From 8b52bdac62cd81ee3e6a2cf98f64cad189598694 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?M=C4=81ris=20Pop=C4=93ns?= Date: Thu, 24 Sep 2026 10:59:45 +0000 Subject: [PATCH] chore(ci): trim workflow comments Keep only the non-obvious why; drop change history, restated code and long explanations. --- .github/dependabot.yml | 5 ----- .github/workflows/auto-merge.yml | 13 +++---------- .github/workflows/ci.yml | 12 +++--------- .github/workflows/security.yml | 11 +---------- .github/zizmor.yml | 9 ++------- 5 files changed, 9 insertions(+), 41 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index f152405..21fafee 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -1,8 +1,3 @@ -# To get started with Dependabot version updates, you'll need to specify which -# package ecosystems to update and where the package manifests are located. -# Please see the documentation for all configuration options: -# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file - version: 2 updates: - package-ecosystem: "github-actions" diff --git a/.github/workflows/auto-merge.yml b/.github/workflows/auto-merge.yml index 9d0d9cc..93fd92e 100644 --- a/.github/workflows/auto-merge.yml +++ b/.github/workflows/auto-merge.yml @@ -7,19 +7,12 @@ on: jobs: auto-merge: - # The reusable workflow cannot grant itself more than the caller has, and - # the org default for GITHUB_TOKEN is read-only — so declare it here. + # The org default token is read-only. permissions: contents: write pull-requests: write - # Only the conclusion is checked, not workflow_run.event: a same-repo - # branch (which is how Dependabot pushes) triggers CI as 'push', not - # 'pull_request', so gating on the event silently skipped every run. The - # reusable workflow looks up the PR and enforces the author allow-list, - # which is the actual safety gate; a run with no open PR just no-ops. - # Every other actor's CI completion used to match this too, spinning up - # the reusable workflow (and its PR lookup) just to no-op - narrowing the - # trigger itself to the only actor that can ever be eligible below. + # Not gated on workflow_run.event: Dependabot branches run CI as 'push'. + # The reusable workflow's author check is the real gate. if: >- github.event.workflow_run.conclusion == 'success' && github.event.workflow_run.actor.login == 'dependabot[bot]' diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b5588d6..03aff36 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -12,11 +12,8 @@ concurrency: cancel-in-progress: true jobs: - # Per-job path filtering, not a workflow-level paths-ignore: the jobs - # below care about disjoint file sets (shell scripts vs .tmpl templates - # vs markdown), and a blanket ignore would wrongly skip markdownlint on - # a shell-only change or vice versa. Each filter also matches this - # workflow file itself, so editing the pipeline always re-runs everything. + # Per-job path filters: the jobs cover disjoint files. Each filter + # includes this file, so pipeline edits rerun everything. changes: name: detect changes runs-on: ubuntu-latest @@ -234,13 +231,10 @@ jobs: with: globs: "**/*.md" - # Audit of this repo's own workflows; accepted findings are in - # .github/zizmor.yml. zizmor: uses: drumandbytes/reusable-actions/.github/workflows/zizmor.yml@v1 - # Single stable name for the org's required-status-check ruleset to point - # at, regardless of how the real jobs above are split or renamed. + # The one name the ruleset requires, however the jobs above change. required-checks-passed: name: Required checks passed runs-on: ubuntu-latest diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 6758248..704d955 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -1,14 +1,6 @@ name: Security -# Split out of the CI workflow deliberately. Auto-merge gates on the CI -# workflow's conclusion, so keeping the scan in CI meant a vulnerability in -# one package blocked merging a Dependabot PR that fixed a different one — -# the gate held its own fixes hostage. Findings still fail this workflow. -# -# No push:branches:[main] leg: pull_request already scanned this before -# merge, so a post-merge rerun scanned nothing new. No npm/pip manifest here -# to path-filter on (only dependency is github-actions), so every PR still -# gets scanned; the weekly run catches advisories against what's on main. +# Separate from CI so a finding can't block auto-merge of an unrelated Dependabot fix. on: pull_request: schedule: @@ -19,7 +11,6 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true -# Read-only token; no job here writes to the repo or reads other scopes. permissions: contents: read diff --git a/.github/zizmor.yml b/.github/zizmor.yml index c9f6ee2..e540ae0 100644 --- a/.github/zizmor.yml +++ b/.github/zizmor.yml @@ -1,18 +1,13 @@ -# zizmor configuration, read by the zizmor job in ci.yml. Anything accepted -# here is accepted on purpose -- each entry says why. - rules: unpinned-uses: config: policies: - # GitHub's own and the org's actions stay on tags (Dependabot moves - # them); third-party actions are SHA-pinned. + # GitHub's and our own actions on tags; third-party SHA-pinned. "actions/*": ref-pin "drumandbytes/*": ref-pin "*": hash-pin dangerous-triggers: ignore: - # workflow_run so Dependabot PRs get a token that can merge; never - # checks out PR code. + # Needed for Dependabot merges; never checks out PR code. - auto-merge.yml