mirror of
https://github.com/Matysh/houseplan-card
synced 2026-09-29 03:09:36 +00:00
Six workflows run from the default branch (issues, schedule, workflow_run): process, process-resume, process-reconcile, mutation-gate, nightly, process-metrics. Their bodies move to _<name>.yml (on: workflow_call); the original files keep only triggers, run-name, permissions, concurrency and one job `uses: Matysh/houseplan-card/.github/workflows/_<name>.yml@dev` with `secrets: inherit`. A pipeline change becomes one commit to dev. - caller job permissions = union of body job permissions (#556 minimum kept per job inside the body); caller `if` repeats the body guard for process and process-resume so unrelated events stay skipped; - dispatch inputs forwarded via workflow_call inputs of the same names; - _mutation-gate.yml keys evidence/marker on job.workflow_sha (the body SHA): in a called workflow github.workflow_sha belongs to the caller in main; - action-pins: narrow exception for this repo's _*.yml at @dev with a reason; - preflight workflow_sync compares all six thin callers (was 3 of 6); performance.yml excluded: its schedule judges main with main's own body; - tests read bodies from _*.yml; new test/default-branch-workflows.test.mjs; six mutants; PROCESS.md §10.4, AGENTS.md, REVIEWER.md updated. Issue: #623 User-Visible: no
48 lines
2.6 KiB
YAML
48 lines
2.6 KiB
YAML
name: Мутационный гейт
|
|
|
|
# Тонкий вызывающий файл (#623). Для этого события GitHub берёт workflow из
|
|
# ветки по умолчанию (`main`), поэтому здесь только то, что обязано жить там:
|
|
# триггеры, run-name, права и concurrency. Тело — `_mutation-gate.yml` по ссылке
|
|
# `@dev`: правка конвейера — один коммит в `dev`, зеркало в `main` не нужно.
|
|
# Этот файл меняется, только когда меняются сами триггеры или потолок прав;
|
|
# тогда он зеркалится в `main`, и preflight `workflow_sync` (validate.yml)
|
|
# держит копии равными.
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
ref:
|
|
description: Git ref whose mutation guards must be proved
|
|
required: false
|
|
default: dev
|
|
schedule:
|
|
# Каждую ночь, 01:00 UTC (04:00 MSK) — после суток правок и до ночного
|
|
# полного Validate (nightly.yml, 02:30 UTC), чтобы не делить раннеры (#513).
|
|
- cron: '0 1 * * *'
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
# Группа зависит от события (#472). Прежде она была одна на всё, и ручной
|
|
# запуск (отладка гейта) отменял идущий по расписанию — так 24.08 погиб
|
|
# еженедельный прогон, а отменённый в списке выглядит «не красным». Поймать
|
|
# отмену изнутри нельзя: вместе с прогоном отменяются и не начавшиеся job,
|
|
# включая любой репортёр. Значит отмену надо не ловить, а не допускать.
|
|
concurrency:
|
|
group: mutation-gate-${{ github.event_name }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
# Потолок прав тела: объединение job-level прав `_mutation-gate.yml`. Вызываемый
|
|
# workflow может права только сузить, поэтому каждая его job по-прежнему
|
|
# получает свой прежний минимум (#556), а шире этого набора не получит никто.
|
|
dev:
|
|
permissions:
|
|
contents: read
|
|
actions: read
|
|
issues: write
|
|
uses: Matysh/houseplan-card/.github/workflows/_mutation-gate.yml@dev # #623: тело конвейера из dev
|
|
with:
|
|
ref: ${{ inputs.ref }}
|
|
secrets: inherit
|