Problem
Three GitHub Actions workflow files sit in the root workflows/ folder, which workflows/README.md defines as the home for agentic markdown runbooks. GitHub only loads workflows from .github/workflows/, so these never run:
None declares on: workflow_call, and no active workflow in .github/workflows/ does either. Organisation repos therefore have no reusable workflows to consume. The consumption examples described some anyway, with invalid uses: syntax (fixed in #3478).
Decision
Activate them as organisation reusable workflows (chosen 2026-09-23).
Change
- Move each into
.github/workflows/ and add on: workflow_call with typed inputs and secrets. Drop GITHUB_TOKEN as a passed secret; callers grant permissions instead.
- Fix stale paths: pr-creation-agent →
agents/pr-agent.
- Rework
pull_request_target use: a called workflow runs with the event of the calling workflow, so decide per workflow whether it needs pull_request_target and document why. Never check out PR head code under it.
- Harden: SHA-pinned actions, inputs via
env, least-privilege permissions, concurrency and timeouts.
- Add them to the actionlint file list in
workflow-lint.yml.
- Update
.github/examples/workflow-consumption-wordpress-{plugin,theme}.yml to call them as lightspeedwp/.github/.github/workflows/<file>.yml@<sha>.
- Verify each with a real caller run (a
workflow_call caller in this repo or a test repo) before marking done.
Relates to #3478, #2896, #3479
Problem
Three GitHub Actions workflow files sit in the root
workflows/folder, whichworkflows/README.mddefines as the home for agentic markdown runbooks. GitHub only loads workflows from.github/workflows/, so these never run:workflows/ai-feedback-validation.yml(pull_request_target, comments and check runs)workflows/orchestrate-phase-progression.yml(issues, pull_request, pull_request_target)workflows/pr-creation-agent-integration-tests.yml(push/pull_request on.github/agents/pr-creation-agent/**, a path that no longer exists since the aiops: pr-agent - plan consolidation spec, fix initial identity and lint config bugs #3400/refactor: pr-agent - restructure 6 skills into Agent Skills specification shape #3401 consolidation intoagents/pr-agent/)None declares
on: workflow_call, and no active workflow in.github/workflows/does either. Organisation repos therefore have no reusable workflows to consume. The consumption examples described some anyway, with invaliduses:syntax (fixed in #3478).Decision
Activate them as organisation reusable workflows (chosen 2026-09-23).
Change
.github/workflows/and addon: workflow_callwith typedinputsandsecrets. DropGITHUB_TOKENas a passed secret; callers grantpermissionsinstead.agents/pr-agent.pull_request_targetuse: a called workflow runs with the event of the calling workflow, so decide per workflow whether it needspull_request_targetand document why. Never check out PR head code under it.env, least-privilegepermissions, concurrency and timeouts.workflow-lint.yml..github/examples/workflow-consumption-wordpress-{plugin,theme}.ymlto call them aslightspeedwp/.github/.github/workflows/<file>.yml@<sha>.workflow_callcaller in this repo or a test repo) before marking done.Relates to #3478, #2896, #3479