Files
houseplan-card/.github/workflows/process.yml
T
Claude baf283c50f ci: thin default-branch callers invoke reusable bodies at @dev (#623)
Six workflows run from the default branch (issues, schedule, workflow_run):
process, process-resume, process-reconcile, mutation-gate, nightly,
process-metrics. Their bodies move to _<name>.yml (on: workflow_call); the
original files keep only triggers, run-name, permissions, concurrency and one
job `uses: Matysh/houseplan-card/.github/workflows/_<name>.yml@dev` with
`secrets: inherit`. A pipeline change becomes one commit to dev.

- caller job permissions = union of body job permissions (#556 minimum kept
  per job inside the body); caller `if` repeats the body guard for process and
  process-resume so unrelated events stay skipped;
- dispatch inputs forwarded via workflow_call inputs of the same names;
- _mutation-gate.yml keys evidence/marker on job.workflow_sha (the body SHA):
  in a called workflow github.workflow_sha belongs to the caller in main;
- action-pins: narrow exception for this repo's _*.yml at @dev with a reason;
- preflight workflow_sync compares all six thin callers (was 3 of 6);
  performance.yml excluded: its schedule judges main with main's own body;
- tests read bodies from _*.yml; new test/default-branch-workflows.test.mjs;
  six mutants; PROCESS.md §10.4, AGENTS.md, REVIEWER.md updated.

Issue: #623
User-Visible: no
2026-09-24 10:23:28 +03:00

32 lines
1.8 KiB
YAML

name: Ревью-конвейер
run-name: "process #${{ github.event.issue.number }} · ${{ github.event.label.name }} · ${{ github.event.issue.title }}"
# Тонкий вызывающий файл (#623). Для этого события GitHub берёт workflow из
# ветки по умолчанию (`main`), поэтому здесь только то, что обязано жить там:
# триггеры, run-name, права и concurrency. Тело — `_process.yml` по ссылке
# `@dev`: правка конвейера — один коммит в `dev`, зеркало в `main` не нужно.
# Этот файл меняется, только когда меняются сами триггеры или потолок прав;
# тогда он зеркалится в `main`, и preflight `workflow_sync` (validate.yml)
# держит копии равными.
on:
issues:
types: [labeled]
permissions:
contents: read
jobs:
# Потолок прав тела: объединение job-level прав `_process.yml`. Вызываемый
# workflow может права только сузить, поэтому каждая его job по-прежнему
# получает свой прежний минимум (#556), а шире этого набора не получит никто.
dev:
# Тот же фильтр, что у job `guard` тела: посторонние события не
# поднимают вызов, а прогон остаётся skipped, как до #623.
if: github.event.label.name == 'S4-spec-review' || github.event.label.name == 'S7-code-review'
permissions:
contents: read
issues: write
uses: Matysh/houseplan-card/.github/workflows/_process.yml@dev # #623: тело конвейера из dev
secrets: inherit