Repository navigation
Merge branch 'authoring-followups' into feature/v3 #69
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Test | |
| on: [push, pull_request] | |
| permissions: | |
| contents: read | |
| jobs: | |
| test: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| # The floor package.json declares, so a verb reaching for a newer API | |
| # fails here rather than in a consumer's session. | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 20 | |
| - name: Build and validate Copilot CLI variant | |
| run: make build && make validate | |
| # `git diff` alone sees modified tracked files only; a newly generated | |
| # variant file would be untracked and pass silently. `git status | |
| # --porcelain` covers both. | |
| - name: Check generated variant is committed | |
| run: | | |
| test -z "$(git status --porcelain -- plugins/maister-copilot/)" \ | |
| || (echo "generated variant is stale — run \`make build\` and commit" \ | |
| && git status --porcelain -- plugins/maister-copilot/ && exit 1) | |
| # Tells the pro repository's CI that a new commit landed here, so it | |
| # can assemble and test against this exact tree. The token is minted | |
| # and stored by the operator (never this repo's tooling); pro | |
| # infrastructure must never fail open CI (PRO-ADR-006), so an absent | |
| # token is a warning and a clean exit, not a failure. sha/ref/repo are | |
| # routed through env: and referenced as quoted shell variables — never | |
| # interpolated directly into the run: body — the same shape used to | |
| # fix an injection defect in the pro repository's own workflows. | |
| - name: Test the engine verbs | |
| run: make test | |
| - name: Dispatch to pro CI | |
| if: github.event_name == 'push' | |
| env: | |
| PRO_DISPATCH_TOKEN: ${{ secrets.PRO_DISPATCH_TOKEN }} | |
| SHA: ${{ github.sha }} | |
| REF: ${{ github.ref }} | |
| REPO: ${{ github.repository }} | |
| run: | | |
| if [ -z "$PRO_DISPATCH_TOKEN" ]; then | |
| echo "::warning::PRO_DISPATCH_TOKEN is not set — skipping dispatch to SkillPanel/maister-pro (pro infrastructure must never fail open CI)" | |
| exit 0 | |
| fi | |
| payload="$(jq -n --arg sha "$SHA" --arg ref "$REF" --arg repo "$REPO" \ | |
| '{event_type: "open-push", client_payload: {sha: $sha, ref: $ref, repo: $repo}}')" | |
| # A silently-failing dispatch is the exact failure the drift loop exists to prevent — | |
| # unlike the pro-side status write-back, this must fail the step loudly, not warn. | |
| http_code="$(curl -sS -o /dev/null -w '%{http_code}' \ | |
| -X POST \ | |
| -H "Authorization: token $PRO_DISPATCH_TOKEN" \ | |
| -H "Accept: application/vnd.github+json" \ | |
| "https://api.github.com/repos/SkillPanel/maister-pro/dispatches" \ | |
| -d "$payload")" | |
| echo "dispatch response: $http_code" | |
| case "$http_code" in | |
| 2??) ;; | |
| *) | |
| echo "::error::dispatch to SkillPanel/maister-pro returned HTTP $http_code" | |
| exit 1 | |
| ;; | |
| esac |