Sitelet https://github.com/devantler-tech/.github/issues/237
Skip to content

Repoint organization-required workflows from actions to .github #237

Description

@devantler

🤖 Generated by the Agentic Engineer

Evidence

Organization rulesets require five workflows from devantler-tech/actions (repository ID 948529001): dependency-review.yaml, enable-auto-merge.yaml and scan-for-workflow-vulnerabilities.yaml on every repository read (ksail, world-at-ruin, monorepo, .github), validate-go-project.yaml on Go repositories, and world-at-ruin-required-regressions.yaml on World at Ruin. Only the World at Ruin rule is declared in deploy/organization-rulesets/. The others are live settings, still outside the declarative path (#69).

Problem

actions cannot be archived while a required workflow still resolves from it. A required workflow that stops resolving blocks merges across the portfolio.

Acceptance criteria

  • Every organization ruleset that names repository 948529001 requires the same workflow path from this repository (933213756) instead.
  • The declared World at Ruin rule changes through deploy/, and its regression test pins the new source repository.
  • The live-only rulesets change through the reviewed declarative path if the provider supports it by then. Otherwise they change through the documented settings path, with the remaining gap recorded under Adopt supported GitHub rulesets and track remaining provider gaps #69.
  • Each changed ruleset reads back with the new source, and a pull request on one repository per ruleset still gets its required checks.

Activity

  1. added theissue type on Sep 25, 2026
  2. moved this to 📥 Backlog in 🌊 Project Boardon Sep 25, 2026
  3. devantler commented on Sep 25, 2026

    @devantler
    ContributorAuthor

    🤖 Generated with Claude Code in an interactive session with the maintainer.

    Plan, from a read-only survey (2026-09-25)

    Read from each repository's effective branch rules. Five organization rulesets require a workflow from actions (948529001):

    Ruleset Workflow In deploy/ today Step
    21102220 World at Ruin regressions world-at-ruin-required-regressions.yaml Managed (Create/Update) Change repositoryId to 933213756; update its regression test
    17213449 DependencyReview dependency-review.yaml Observe-only, identity-only forProvider Declare the full spec from status.atProvider (verified complete: conditions, OrganizationAdmin bypass, doNotEnforceOnCreate), then promote with the new source
    3716878 EnableAutoMerge enable-auto-merge.yaml UI-managed (repository-property condition) Adopt Observe-only, read atProvider, then declare and promote
    14426226 ScanGitHubActions scan-for-workflow-vulnerabilities.yaml UI-managed Same
    10320335 Go validate-go-project.yaml UI-managed Same

    Provider v0.20.0 expresses repository-property conditions (#121), so every step goes through deploy/, and nothing needs a UI change.

    Order.

    1. After feat!: import the devantler-tech/actions catalogue #243 merges, so each workflow exists on this repository's main: one PR repoints the two declared rulesets and adopts the three UI-managed ones Observe-only.
    2. After atProvider is read back, a second PR declares their full spec with the new source.

    Each repoint is verified by a pull request in one affected repository still getting that required check. The validate-go-project copy here calls apply-signed-fixes at an actions commit until its re-pin, and that call keeps working because actions is only frozen, not archived.

  4. devantler commented on Oct 2, 2026

    @devantler
    ContributorAuthor

    🤖 Generated by the Agentic Engineer

    Fresh native readback on 2026-10-02 still finds all five required-workflow families pointing at legacy Actions repository ID 948529001: dependency review, auto-merge, workflow security, Go validation and World at Ruin regressions. The current World at Ruin declaration retains that source, while dependency review remains identity-only and Observe-only.

    The existing two-stage adoption plan remains necessary: declare and reconcile the complete rulesets before repointing, then read back their effective source and run a qualifying consumer PR for every family. Catalogue CI cannot substitute for that consumer proof.

    Blocker: effective required-workflow source migration and qualifying consumer checks are not delivered. Legacy archival in #240 remains downstream of this work.

  5. devantler commented on Oct 4, 2026

    @devantler
    ContributorAuthor

    🤖 Generated by the Agentic Engineer

    Verified migration gate — 2026-10-04

    A complete metadata and effective default-branch rule census found 70 legacy required-workflow declarations across 22 active public repositories. All five families in the criteria still resolve from repository 948529001. The canonical deploy-guards rule already resolves from repository 933213756, but is outside these five families. The census binds complete recursive trees, verified blobs and structural YAML to observed default-branch commits; its final head rebind completed at 11:17:32 UTC.

    #235 is closed and no longer blocks this work. The administrative organization-ruleset universe remains UNKNOWN because the current API authority cannot read it. Complete effective branch rules do not prove that administrative universe is complete. Do not change settings from a partial inventory.

    The next implementation is to adopt the three live-only general rules through #69, confirm provider support for complete workflow source specifications, and repoint the existing Go and World at Ruin declarations. Each changed ruleset needs native source readback and a qualifying consumer pull request. Blocker: complete administrative ruleset/provider evidence and verified canonical execution for each family.

  6. devantler commented on Oct 8, 2026

    @devantler
    ContributorAuthor

    🤖 Generated by the Agentic Engineer

    Current-source correction at reviewed main f5bdae4233b8f5c64a88de717b134205d8f6cc97: the World at Ruin required-regression declaration and its regression test already name canonical catalogue repository 933213756. The earlier instruction to repeat that source edit is stale. This is declaration evidence; effective-source readback and a qualifying consumer run are still separate acceptance gates.

    The Go-template and .NET-template declarations still name the legacy catalogue. The existing staged plan remains appropriate for the other required-workflow families: first import the existing resources with Observe only, obtain their complete observed specification, then review any source change separately. Repository-projected rules do not prove the full administrative conditions, selectors or bypasses, so partial readback must not authorize Update. No GitHub settings were changed by this audit; #237 and legacy retirement #240 remain open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Fields

    Priority

    None yet

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions