Skip to content

Merge branch 'authoring-followups' into feature/v3 #69

Merge branch 'authoring-followups' into feature/v3

Merge branch 'authoring-followups' into feature/v3 #69

Workflow file for this run

name: Test
on: [push, pull_request]
permissions:
contents: read
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
# The floor package.json declares, so a verb reaching for a newer API
# fails here rather than in a consumer's session.
- uses: actions/setup-node@v4
with:
node-version: 20
- name: Build and validate Copilot CLI variant
run: make build && make validate
# `git diff` alone sees modified tracked files only; a newly generated
# variant file would be untracked and pass silently. `git status
# --porcelain` covers both.
- name: Check generated variant is committed
run: |
test -z "$(git status --porcelain -- plugins/maister-copilot/)" \
|| (echo "generated variant is stale — run \`make build\` and commit" \
&& git status --porcelain -- plugins/maister-copilot/ && exit 1)
# Tells the pro repository's CI that a new commit landed here, so it
# can assemble and test against this exact tree. The token is minted
# and stored by the operator (never this repo's tooling); pro
# infrastructure must never fail open CI (PRO-ADR-006), so an absent
# token is a warning and a clean exit, not a failure. sha/ref/repo are
# routed through env: and referenced as quoted shell variables — never
# interpolated directly into the run: body — the same shape used to
# fix an injection defect in the pro repository's own workflows.
- name: Test the engine verbs
run: make test
- name: Dispatch to pro CI
if: github.event_name == 'push'
env:
PRO_DISPATCH_TOKEN: ${{ secrets.PRO_DISPATCH_TOKEN }}
SHA: ${{ github.sha }}
REF: ${{ github.ref }}
REPO: ${{ github.repository }}
run: |
if [ -z "$PRO_DISPATCH_TOKEN" ]; then
echo "::warning::PRO_DISPATCH_TOKEN is not set — skipping dispatch to SkillPanel/maister-pro (pro infrastructure must never fail open CI)"
exit 0
fi
payload="$(jq -n --arg sha "$SHA" --arg ref "$REF" --arg repo "$REPO" \
'{event_type: "open-push", client_payload: {sha: $sha, ref: $ref, repo: $repo}}')"
# A silently-failing dispatch is the exact failure the drift loop exists to prevent —
# unlike the pro-side status write-back, this must fail the step loudly, not warn.
http_code="$(curl -sS -o /dev/null -w '%{http_code}' \
-X POST \
-H "Authorization: token $PRO_DISPATCH_TOKEN" \
-H "Accept: application/vnd.github+json" \
"https://api.github.com/repos/SkillPanel/maister-pro/dispatches" \
-d "$payload")"
echo "dispatch response: $http_code"
case "$http_code" in
2??) ;;
*)
echo "::error::dispatch to SkillPanel/maister-pro returned HTTP $http_code"
exit 1
;;
esac