Sitelet https://github.com/lightspeedwp/.github/issues/3488
Skip to content

epic: central, tested workflow layer for all org repos (GitHub Free) #3488

Description

@eleshar

Context

The workflow layer was modelled on github/awesome-copilot workflows/, but it was not implemented correctly. Most workflows either do not run or do not perform the check they claim to. As a result, AI-generated changes are merging unchecked. The goal (Ash, 2026-09-23) is GitHub Actions that every org repo can use. For example, the PR template and changelog checks are needed by all repos.

Constraint: the org stays on GitHub Free (decided 2026-09-23). The verified constraints are in the comment below:

  • no org rulesets
  • private repos (202) cannot use rulesets or branch protection
  • public repos (102) can use per-repo rulesets
  • reusable workflows in this public repo can be called from every repo
  • callers pay the run minutes

Target architecture (GitHub Free)

  1. One shared reusable workflow, "PR checks" (on: workflow_call) in this repo. It covers changelog validation, PR-template section checks, actionlint and markdown lint, each switchable by inputs. It is pinned by commit SHA or release tag, and Dependabot (github-actions) bumps callers.
  2. Every repo carries one short caller file. It is added from an org workflow template (workflow-templates/) and kept in sync across repos by a script. There are no copies of the check logic.
  3. Enforcement depends on visibility:
    • Public repos: a per-repo ruleset requires the "PR checks" status on the default branch. It is created and kept in sync by a script, since there are no org rulesets.
    • Private repos: nothing can block a merge on Free. Checks are advisory at merge time, backed by detect and report after merge. A scheduled workflow in this repo lists PRs merged in the last day where "PR checks" failed or never ran, and opens or updates one tracking issue (or sends an alert) so they are fixed immediately.
  4. Templates are central. PR and issue templates live only in this public .github repo as org defaults. Per-repo template folders that only duplicate them are removed, because any local template disables the org default for that repo.
  5. Watch the minutes budget. Private-repo runs use the Free plan's included minutes. The shared checks must stay light: sparse checkout, no full install unless needed, concurrency with cancel-in-progress, and path-aware steps. Heavy checks (the full test gate from fix: ci - run Jest on every PR and fail only on new failures #3487) are opt-in per repo. Measure usage in Settings → Billing before and after rollout.
  6. Agentic workflows (GitHub Agentic Workflows) only for judgement tasks such as summaries, changelog drafts and triage. They are compiled, read-only by default and tested. They are never a gate.
  7. Nothing counts as working until it is tested. Each shared workflow needs unit tests for its scripts (as in feat: ci - activate organisation reusable workflows #3486), a recorded passing and failing caller run, and a documented caller snippet.

Work

  • Inventory all workflows (active and archived) and every org repo's .github/workflows: does each run, does it do what it claims, and is it org-wide or local? Decide keep-local, reusable, template-only or delete for each.
  • Build the "PR checks" reusable workflow from changelog-unified.yml and pr-template-routing.yml. Scripts are checked out at job.workflow_repository@job.workflow_sha (pattern proven in feat: ci - activate organisation reusable workflows #3486). Remove this repo's paths and config from them so they work in plugin, theme and scaffold repos. No PR code runs under pull_request_target.
  • Org workflow template for the caller, plus a sync script (dry-run first) that opens a PR in each active repo to add or update the caller and reports coverage.
  • Ruleset sync script for public repos: require "PR checks", evaluate mode first, admin bypass only.
  • Post-merge audit workflow for private repos: daily scan, one tracking issue per repo or one digest, with no false positives on docs-only PRs.
  • Remove duplicate per-repo PR and issue templates (30 PR-template and 113 issue-template files found); keep only genuine per-repo variants.
  • Measure the Actions minutes baseline, set per-check budgets, and review after the pilot.
  • Pilot on block-plugin-scaffold and block-theme-scaffold (with block-plugin-scaffold#35 and block-theme-scaffold#7), then roll out to the active repos.
  • Agentic workflows: choose the judgement tasks, compile, restrict permissions, test.
  • Release the shared workflows with tags so callers are bumped by Dependabot.

Acceptance

  • Every active repo runs "PR checks", with a recorded passing and failing run.
  • Public repos block merges on a failing check.
  • Private repos get a post-merge report of any PR merged without a passing check, within a day.
  • Actions minutes stay within the Free allowance.

Builds on #3480 / #3486 (first reusable workflows) and #3479 / #3487 (test gate). Relates to #3464, #2896, #3476.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions