mirror of
https://github.com/Matysh/houseplan-card
synced 2026-10-01 12:18:51 +00:00
`workflow_dispatch` runs the file from the chosen ref, but GitHub lists a workflow and accepts a dispatch (button, `gh workflow run`, API) only when its file exists on the default branch. `ship-review.yml` (#696) and `beta-derived.yml` (#697) lived only in `dev`, so neither could be started at all, and the comment "the file runs from `--ref dev`, no mirror in `main` needed" was wrong. Both beta steps are needed before the next promotion would bring them to `main`. They now follow the #623 layout instead of a full copy in `main`: a thin caller (trigger, dispatch inputs, run-name, permission ceiling, concurrency) calls `_ship-review.yml` / `_beta-derived.yml` at `@dev` with `secrets: inherit`. A full copy would either need a mirror on every edit or drift silently, and a dispatch from `main` (the button's default) would run the stale copy; the thin caller runs the dev body from any ref. The caller ceiling is the union of the body jobs' permissions (#556): ship-review `contents: read` + `issues: read`, beta-derived `contents: read` + `actions: read`; writes to `dev` stay with HP_PROCESS_TOKEN as before. `workflow_sync` in validate.yml now compares eight files, and test/default-branch-workflows.test.mjs lists the two dispatch-only files explicitly with the reason checked (only `workflow_dispatch`). Workflow tests and the #697 provenance mutant read the bodies. PROCESS.md §10.4, §8 and §11.7 say how these are run and that a new thin file is mirrored into `main` before it is merged into `dev`. Issue: #716 User-Visible: no Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018qZfe7YS4rqEMKoVeS3GKd
54 lines
2.4 KiB
YAML
54 lines
2.4 KiB
YAML
name: "Бета: пакетное ревью ship"
|
|
run-name: "Ship review ${{ inputs.tag }}"
|
|
|
|
# Тонкий вызывающий файл (#716, устройство #623). `workflow_dispatch` GitHub
|
|
# исполняет с выбранной ветки, но кнопку и сам запуск (`gh workflow run`)
|
|
# даёт только workflow, чей файл лежит в ветке по умолчанию (`main`). Поэтому
|
|
# здесь только то, что обязано жить там: триггер, входы ручного запуска,
|
|
# run-name, права и concurrency. Тело — `_ship-review.yml` по ссылке `@dev`:
|
|
# правка ревью — один коммит в `dev`, а запуск с любой ветки (в кнопке по
|
|
# умолчанию выбрана `main`) исполняет тело из `dev`.
|
|
# Этот файл меняется, только когда меняются входы или потолок прав; тогда он
|
|
# зеркалится в `main`, и preflight `workflow_sync` (validate.yml) держит копии
|
|
# равными.
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
tag:
|
|
description: "Beta tag the review is for, for example v1.79.0-beta.1"
|
|
required: true
|
|
type: string
|
|
candidate:
|
|
description: "Exact candidate SHA; empty = the dev tip"
|
|
required: false
|
|
type: string
|
|
default: ""
|
|
force:
|
|
description: "Review again even when the document already exists in dev"
|
|
required: false
|
|
type: boolean
|
|
default: false
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: ship-review-${{ inputs.tag }}
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
# Потолок прав тела: объединение job-level прав `_ship-review.yml`. Вызываемый
|
|
# workflow может права только сузить, поэтому каждая его job по-прежнему
|
|
# получает свой прежний минимум (#556), а шире этого набора не получит никто.
|
|
dev:
|
|
permissions:
|
|
contents: read
|
|
issues: read
|
|
uses: Matysh/houseplan-card/.github/workflows/_ship-review.yml@dev # #716: тело ревью из dev
|
|
with:
|
|
tag: ${{ inputs.tag }}
|
|
candidate: ${{ inputs.candidate }}
|
|
force: ${{ inputs.force }}
|
|
secrets: inherit
|