Files
Claudeandclaude[bot] d11ad9c1c2 ci: register ship-review and beta-derived as thin callers in main (#716)
`workflow_dispatch` runs the file from the chosen ref, but GitHub lists a
workflow and accepts a dispatch (button, `gh workflow run`, API) only when
its file exists on the default branch. `ship-review.yml` (#696) and
`beta-derived.yml` (#697) lived only in `dev`, so neither could be started
at all, and the comment "the file runs from `--ref dev`, no mirror in
`main` needed" was wrong. Both beta steps are needed before the next
promotion would bring them to `main`.

They now follow the #623 layout instead of a full copy in `main`: a thin
caller (trigger, dispatch inputs, run-name, permission ceiling, concurrency)
calls `_ship-review.yml` / `_beta-derived.yml` at `@dev` with
`secrets: inherit`. A full copy would either need a mirror on every edit or
drift silently, and a dispatch from `main` (the button's default) would run
the stale copy; the thin caller runs the dev body from any ref. The caller
ceiling is the union of the body jobs' permissions (#556): ship-review
`contents: read` + `issues: read`, beta-derived `contents: read` +
`actions: read`; writes to `dev` stay with HP_PROCESS_TOKEN as before.

`workflow_sync` in validate.yml now compares eight files, and
test/default-branch-workflows.test.mjs lists the two dispatch-only files
explicitly with the reason checked (only `workflow_dispatch`). Workflow
tests and the #697 provenance mutant read the bodies. PROCESS.md §10.4,
§8 and §11.7 say how these are run and that a new thin file is mirrored
into `main` before it is merged into `dev`.

Issue: #716
User-Visible: no
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018qZfe7YS4rqEMKoVeS3GKd
2026-09-30 21:01:10 +00:00

54 lines
2.4 KiB
YAML

name: "Бета: пакетное ревью ship"
run-name: "Ship review ${{ inputs.tag }}"
# Тонкий вызывающий файл (#716, устройство #623). `workflow_dispatch` GitHub
# исполняет с выбранной ветки, но кнопку и сам запуск (`gh workflow run`)
# даёт только workflow, чей файл лежит в ветке по умолчанию (`main`). Поэтому
# здесь только то, что обязано жить там: триггер, входы ручного запуска,
# run-name, права и concurrency. Тело — `_ship-review.yml` по ссылке `@dev`:
# правка ревью — один коммит в `dev`, а запуск с любой ветки (в кнопке по
# умолчанию выбрана `main`) исполняет тело из `dev`.
# Этот файл меняется, только когда меняются входы или потолок прав; тогда он
# зеркалится в `main`, и preflight `workflow_sync` (validate.yml) держит копии
# равными.
on:
workflow_dispatch:
inputs:
tag:
description: "Beta tag the review is for, for example v1.79.0-beta.1"
required: true
type: string
candidate:
description: "Exact candidate SHA; empty = the dev tip"
required: false
type: string
default: ""
force:
description: "Review again even when the document already exists in dev"
required: false
type: boolean
default: false
permissions:
contents: read
concurrency:
group: ship-review-${{ inputs.tag }}
cancel-in-progress: false
jobs:
# Потолок прав тела: объединение job-level прав `_ship-review.yml`. Вызываемый
# workflow может права только сузить, поэтому каждая его job по-прежнему
# получает свой прежний минимум (#556), а шире этого набора не получит никто.
dev:
permissions:
contents: read
issues: read
uses: Matysh/houseplan-card/.github/workflows/_ship-review.yml@dev # #716: тело ревью из dev
with:
tag: ${{ inputs.tag }}
candidate: ${{ inputs.candidate }}
force: ${{ inputs.force }}
secrets: inherit