Repository navigation
Repoint organization-required workflows from actions to .github #237
Description
Activity
🤖 Generated with Claude Code in an interactive session with the maintainer.
Plan, from a read-only survey (2026-09-25)
Read from each repository's effective branch rules. Five organization rulesets require a workflow from
actions(948529001):Ruleset Workflow In deploy/todayStep 21102220World at Ruin regressionsworld-at-ruin-required-regressions.yamlManaged (Create/Update) Change repositoryIdto933213756; update its regression test17213449DependencyReviewdependency-review.yamlObserve-only, identity-only forProviderDeclare the full spec from status.atProvider(verified complete: conditions, OrganizationAdmin bypass,doNotEnforceOnCreate), then promote with the new source3716878EnableAutoMergeenable-auto-merge.yamlUI-managed (repository-property condition) Adopt Observe-only, read atProvider, then declare and promote14426226ScanGitHubActionsscan-for-workflow-vulnerabilities.yamlUI-managed Same 10320335Govalidate-go-project.yamlUI-managed Same Provider v0.20.0 expresses repository-property conditions (#121), so every step goes through
deploy/, and nothing needs a UI change.Order.
- After feat!: import the devantler-tech/actions catalogue #243 merges, so each workflow exists on this repository's
main: one PR repoints the two declared rulesets and adopts the three UI-managed ones Observe-only. - After
atProvideris read back, a second PR declares their full spec with the new source.
Each repoint is verified by a pull request in one affected repository still getting that required check. The
validate-go-projectcopy here callsapply-signed-fixesat anactionscommit until its re-pin, and that call keeps working becauseactionsis only frozen, not archived.- After feat!: import the devantler-tech/actions catalogue #243 merges, so each workflow exists on this repository's
🤖 Generated by the Agentic Engineer
Fresh native readback on 2026-10-02 still finds all five required-workflow families pointing at legacy Actions repository ID
948529001: dependency review, auto-merge, workflow security, Go validation and World at Ruin regressions. The current World at Ruin declaration retains that source, while dependency review remains identity-only and Observe-only.The existing two-stage adoption plan remains necessary: declare and reconcile the complete rulesets before repointing, then read back their effective source and run a qualifying consumer PR for every family. Catalogue CI cannot substitute for that consumer proof.
Blocker: effective required-workflow source migration and qualifying consumer checks are not delivered. Legacy archival in #240 remains downstream of this work.
🤖 Generated by the Agentic Engineer
Verified migration gate — 2026-10-04
A complete metadata and effective default-branch rule census found 70 legacy required-workflow declarations across 22 active public repositories. All five families in the criteria still resolve from repository 948529001. The canonical deploy-guards rule already resolves from repository 933213756, but is outside these five families. The census binds complete recursive trees, verified blobs and structural YAML to observed default-branch commits; its final head rebind completed at 11:17:32 UTC.
#235 is closed and no longer blocks this work. The administrative organization-ruleset universe remains UNKNOWN because the current API authority cannot read it. Complete effective branch rules do not prove that administrative universe is complete. Do not change settings from a partial inventory.
The next implementation is to adopt the three live-only general rules through #69, confirm provider support for complete workflow source specifications, and repoint the existing Go and World at Ruin declarations. Each changed ruleset needs native source readback and a qualifying consumer pull request. Blocker: complete administrative ruleset/provider evidence and verified canonical execution for each family.
🤖 Generated by the Agentic Engineer
Current-source correction at reviewed main
f5bdae4233b8f5c64a88de717b134205d8f6cc97: the World at Ruin required-regression declaration and its regression test already name canonical catalogue repository933213756. The earlier instruction to repeat that source edit is stale. This is declaration evidence; effective-source readback and a qualifying consumer run are still separate acceptance gates.The Go-template and .NET-template declarations still name the legacy catalogue. The existing staged plan remains appropriate for the other required-workflow families: first import the existing resources with Observe only, obtain their complete observed specification, then review any source change separately. Repository-projected rules do not prove the full administrative conditions, selectors or bypasses, so partial readback must not authorize Update. No GitHub settings were changed by this audit; #237 and legacy retirement #240 remain open.
Metadata
Metadata
Assignees
Labels
Type
Fields
Priority
Projects
- StatusShow more project fields🧊 Icebox
Evidence
Organization rulesets require five workflows from
devantler-tech/actions(repository ID948529001):dependency-review.yaml,enable-auto-merge.yamlandscan-for-workflow-vulnerabilities.yamlon every repository read (ksail,world-at-ruin,monorepo,.github),validate-go-project.yamlon Go repositories, andworld-at-ruin-required-regressions.yamlon World at Ruin. Only the World at Ruin rule is declared indeploy/organization-rulesets/. The others are live settings, still outside the declarative path (#69).Problem
actionscannot be archived while a required workflow still resolves from it. A required workflow that stops resolving blocks merges across the portfolio.Acceptance criteria
948529001requires the same workflow path from this repository (933213756) instead.deploy/, and its regression test pins the new source repository.