Configurable Laravel and Node CI, self-check CI, workflow guide - #1
Merged
Merged
Conversation
Nobody uses the licence check. For PHP and npm, OWASP Dependency-Check adds little over composer audit and npm audit, and its Composer analyzer is experimental and was not enabled.
- Split into parallel lint, test, build and optional browser test jobs, with one aggregate CI check for branch protection - Auto-detect tools, or run lint-command, types-command, test-command - Optional Codecov upload with coverage-file - working-directory for applications in a subfolder - Share setup steps between jobs with YAML anchors - Document accepted values in every input description - Add the Node CI template; list every input in both templates
- scan-dev-configs: fail on any script file (extension, executable bit or shebang) unless allowed-scripts lists it - Fix both actions failing under bash -e when grep finds no match - security.yml: the org requires SHA-pinned actions, so check out scify/.github at job.workflow_sha and run the actions from a local path - security.yml: add allowed-dev-scripts
The guide explains how to call each workflow, lists every input with example values, and gives recipes and troubleshooting. The README states that deployment workflows belong in a private repository.
- actionlint and shellcheck on workflows, templates and composite actions - The workflow guide must document every input - Internal references must use one release tag - Composite actions must pass on good fixtures and fail on bad ones - security.yml, laravel-ci.yml and node-ci.yml run against this repository and the fixtures in tests/fixtures
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
First releasable state of the shared workflows, to be tagged as v0.1.
CI workflows
laravel-ci.ymlandnode-ci.ymlrun parallel jobs (static checks, tests, build, optional Playwright tests) and report one aggregateci / CIcheck.lint-command,types-commandortest-command.coverage-fileturns on the Codecov upload.working-directorysupports an application in a subfolder.Security
scan-dev-configsfails on any script in.vscode,.claude,.cursoror.ideaunlessallowed-scriptslists it.bash -ewhengrepfound no match.security.ymlnow checks outscify/.githubatjob.workflow_shaand runs its actions from a local path..github/actions/*.Removed
license-check.ymlandowasp-dependency-check.yml.Documentation
.github/workflows/README.md: how a call works, every input with example values, recipes, troubleshooting.Self-check
security.yml,laravel-ci.ymlandnode-ci.ymlrun against this repository and the fixture projects intests/fixtures/.