Files
houseplan-card/.github/workflows/mutation-gate.yml
T
Claude baf283c50f ci: thin default-branch callers invoke reusable bodies at @dev (#623)
Six workflows run from the default branch (issues, schedule, workflow_run):
process, process-resume, process-reconcile, mutation-gate, nightly,
process-metrics. Their bodies move to _<name>.yml (on: workflow_call); the
original files keep only triggers, run-name, permissions, concurrency and one
job `uses: Matysh/houseplan-card/.github/workflows/_<name>.yml@dev` with
`secrets: inherit`. A pipeline change becomes one commit to dev.

- caller job permissions = union of body job permissions (#556 minimum kept
  per job inside the body); caller `if` repeats the body guard for process and
  process-resume so unrelated events stay skipped;
- dispatch inputs forwarded via workflow_call inputs of the same names;
- _mutation-gate.yml keys evidence/marker on job.workflow_sha (the body SHA):
  in a called workflow github.workflow_sha belongs to the caller in main;
- action-pins: narrow exception for this repo's _*.yml at @dev with a reason;
- preflight workflow_sync compares all six thin callers (was 3 of 6);
  performance.yml excluded: its schedule judges main with main's own body;
- tests read bodies from _*.yml; new test/default-branch-workflows.test.mjs;
  six mutants; PROCESS.md §10.4, AGENTS.md, REVIEWER.md updated.

Issue: #623
User-Visible: no
2026-09-24 10:23:28 +03:00

48 lines
2.6 KiB
YAML

name: Мутационный гейт
# Тонкий вызывающий файл (#623). Для этого события GitHub берёт workflow из
# ветки по умолчанию (`main`), поэтому здесь только то, что обязано жить там:
# триггеры, run-name, права и concurrency. Тело — `_mutation-gate.yml` по ссылке
# `@dev`: правка конвейера — один коммит в `dev`, зеркало в `main` не нужно.
# Этот файл меняется, только когда меняются сами триггеры или потолок прав;
# тогда он зеркалится в `main`, и preflight `workflow_sync` (validate.yml)
# держит копии равными.
on:
workflow_dispatch:
inputs:
ref:
description: Git ref whose mutation guards must be proved
required: false
default: dev
schedule:
# Каждую ночь, 01:00 UTC (04:00 MSK) — после суток правок и до ночного
# полного Validate (nightly.yml, 02:30 UTC), чтобы не делить раннеры (#513).
- cron: '0 1 * * *'
permissions:
contents: read
# Группа зависит от события (#472). Прежде она была одна на всё, и ручной
# запуск (отладка гейта) отменял идущий по расписанию — так 24.08 погиб
# еженедельный прогон, а отменённый в списке выглядит «не красным». Поймать
# отмену изнутри нельзя: вместе с прогоном отменяются и не начавшиеся job,
# включая любой репортёр. Значит отмену надо не ловить, а не допускать.
concurrency:
group: mutation-gate-${{ github.event_name }}
cancel-in-progress: true
jobs:
# Потолок прав тела: объединение job-level прав `_mutation-gate.yml`. Вызываемый
# workflow может права только сузить, поэтому каждая его job по-прежнему
# получает свой прежний минимум (#556), а шире этого набора не получит никто.
dev:
permissions:
contents: read
actions: read
issues: write
uses: Matysh/houseplan-card/.github/workflows/_mutation-gate.yml@dev # #623: тело конвейера из dev
with:
ref: ${{ inputs.ref }}
secrets: inherit