Skip to content

SRE-1079: Copy shared actions, workflows and Renovate preset from .github - #1

Merged
TimDiekmann merged 4 commits into
mainfrom
claude/sre-1079-copy-shared-actions-from-dotgithub
Sep 26, 2026
Merged

TimDiekmann merged 4 commits into
mainfrom
claude/sre-1079-copy-shared-actions-from-dotgithub

Conversation

@claude

@claude claude Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Requested by Tim Diekmann · Slack thread

Before: The org's composite actions, reusable workflows and Renovate preset live in hashintel/.github. That repository is meant to become community-health-only, so they need a new home. hashintel/actions holds only a LICENSE.

After: hashintel/actions holds the same composite actions, reusable workflows and Renovate preset, plus its own CI (lint.yml, preflight-*, housekeeping-dependencies.yml), a renovate.json and a README. Nothing calls into this repository yet.

How

The files are copied verbatim from hashintel/.github at 9b55800, with file modes kept (token.sh stays executable):

  • .github/actions/{decrypt-secret,encrypt-secret,github-app-token,install-renovate}/**
  • .github/workflows/{housekeeping-dependencies,lint,preflight-actionlint,preflight-dependencies,preflight-pr-title,preflight-todo-comments}.yml
  • .gitignore and renovate-config.json

Three files differ from the source:

  • In renovate-config.json, the digest auto-bump rule matches ["hashintel/actions"] instead of ["hashintel/.github"], because the actions are being removed from hashintel/.github.
  • In lint.yml, the validator comment names github>hashintel/actions:renovate-config as the preset reference.
  • In install-renovate/package-lock.json, js-yaml resolves to 4.3.2 instead of 4.3.1, which is affected by GHSA-2883-xcg3-v3hh. Its three parents (@yarnpkg/parsers ^4.3.0, read-yaml-file and write-yaml-file ^4.0.0) already admit 4.3.2, so npm update js-yaml --package-lock-only re-resolved it and renovate stays at 44.34.3.

No other literal hashintel/.github reference remains. Composite actions are referenced through $/, so they need no change.

renovate.json extends github>hashintel/actions:renovate-config. Renovate reads repository config from the default branch, so the pull_request run of housekeeping-dependencies.yml (a dry run in extract mode against github.repository) never reads the renovate.json on this branch. Before merge, main has no Renovate config and that run treats the repository as not yet onboarded. After merge, main has both renovate.json and renovate-config.json, so the self-reference resolves. Extending the hashintel/.github preset instead would break once that copy is deleted.

Callers are repointed in separate PRs. The copies in hashintel/.github stay until then.

The housekeeping-dependencies.yml run needs two things outside this PR:

  • hashintel/internal-infra#373, which adds hashintel/actions/.github/workflows/housekeeping-dependencies.yml@* to the staging Vault ci-renovate role, applied to staging Vault.
  • The RENOVATE_TOKEN_ENC_KEY secret on this repository.

Checks run locally:

  • actionlint v1.7.12 with the -ignore flags from preflight-actionlint.yml reports no errors. Shellcheck was not installed, so actionlint's embedded shellcheck pass did not run.
  • npm ci --ignore-scripts succeeds on the updated lockfile, and npm ls js-yaml shows only 4.3.2.
  • renovate-config-validator from renovate@44.34.3 passes on renovate.json and on renovate-config.json. On renovate-config.json it warns that config migration is needed (fileMatch → managerFilePatterns in two custom managers). That warning comes from the source file, which this PR leaves unchanged.

🤖 Generated with Claude Code

https://claude.ai/code/session_012vhP8cbLCbnWdQP7LLFB5A

…ithub`

Copies the composite actions, reusable workflows, `.gitignore` and
`renovate-config.json` verbatim from hashintel/.github at
9b55800e7975e3baf17f67a8c3d3dcc54cdd3d56, so `.github` can become a
community-health-only repository.

- `renovate-config.json`: the digest auto-bump rule also matches
  `hashintel/actions`.
- `lint.yml`: the comment names `hashintel/actions` as the preset host.
- `renovate.json` extends `github>hashintel/actions:renovate-config`.
- `README.md` describes the repository and how to pin a workflow.
Comment thread .github/actions/install-renovate/package-lock.json
4.3.1 is affected by GHSA-2883-xcg3-v3hh. Every range that pulls
`js-yaml` in already admits 4.3.2, so only the lockfile changes.
Comment thread renovate-config.json Outdated
@claude
claude Bot requested a review from TimDiekmann September 26, 2026 14:20
@claude
claude Bot marked this pull request as ready for review September 26, 2026 14:23
@cursor

cursor Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Relocates Vault JWT signing and encrypted cross-job token handling into a new repo; misconfiguration of secrets or Vault policy could break dependency automation org-wide once callers switch.

Overview
Moves the org’s shared GitHub Actions building blocks from hashintel/.github into hashintel/actions: composite actions (encrypt-secret / decrypt-secret, Vault-backed github-app-token, pinned install-renovate), reusable preflight-* and housekeeping-dependencies workflows, and the shared renovate-config.json preset plus local renovate.json and README.

Adds this repo’s own CI (lint.yml with shellcheck and Renovate config validation). Targeted edits vs the copy: the Renovate preset’s digest auto-bump rule and lint.yml docs now point at hashintel/actions; renovate.json self-extends github>hashintel/actions:renovate-config. Callers are not repointed in this PR; copies in .github stay until follow-ups. Renovate housekeeping still needs RENOVATE_TOKEN_ENC_KEY and Vault role updates outside this change.

Reviewed by Cursor Bugbot for commit 96e2d79. Bugbot is set up for automated code reviews on this repo. Configure here.

TimDiekmann
TimDiekmann previously approved these changes Sep 26, 2026
@claude
claude Bot requested a review from TimDiekmann September 26, 2026 14:33
@TimDiekmann
TimDiekmann added this pull request to the merge queue Sep 26, 2026
Merged via the queue into main with commit 66c8121 Sep 26, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants