SRE-1079: Copy shared actions, workflows and Renovate preset from .github - #1
Conversation
…ithub` Copies the composite actions, reusable workflows, `.gitignore` and `renovate-config.json` verbatim from hashintel/.github at 9b55800e7975e3baf17f67a8c3d3dcc54cdd3d56, so `.github` can become a community-health-only repository. - `renovate-config.json`: the digest auto-bump rule also matches `hashintel/actions`. - `lint.yml`: the comment names `hashintel/actions` as the preset host. - `renovate.json` extends `github>hashintel/actions:renovate-config`. - `README.md` describes the repository and how to pin a workflow.
4.3.1 is affected by GHSA-2883-xcg3-v3hh. Every range that pulls `js-yaml` in already admits 4.3.2, so only the lockfile changes.
PR SummaryMedium Risk Overview Adds this repo’s own CI ( Reviewed by Cursor Bugbot for commit 96e2d79. Bugbot is set up for automated code reviews on this repo. Configure here. |
Requested by Tim Diekmann · Slack thread
Before: The org's composite actions, reusable workflows and Renovate preset live in
hashintel/.github. That repository is meant to become community-health-only, so they need a new home.hashintel/actionsholds only aLICENSE.After:
hashintel/actionsholds the same composite actions, reusable workflows and Renovate preset, plus its own CI (lint.yml,preflight-*,housekeeping-dependencies.yml), arenovate.jsonand a README. Nothing calls into this repository yet.How
The files are copied verbatim from
hashintel/.githubat9b55800, with file modes kept (token.shstays executable):.github/actions/{decrypt-secret,encrypt-secret,github-app-token,install-renovate}/**.github/workflows/{housekeeping-dependencies,lint,preflight-actionlint,preflight-dependencies,preflight-pr-title,preflight-todo-comments}.yml.gitignoreandrenovate-config.jsonThree files differ from the source:
renovate-config.json, the digest auto-bump rule matches["hashintel/actions"]instead of["hashintel/.github"], because the actions are being removed fromhashintel/.github.lint.yml, the validator comment namesgithub>hashintel/actions:renovate-configas the preset reference.install-renovate/package-lock.json,js-yamlresolves to 4.3.2 instead of 4.3.1, which is affected by GHSA-2883-xcg3-v3hh. Its three parents (@yarnpkg/parsers^4.3.0,read-yaml-fileandwrite-yaml-file^4.0.0) already admit 4.3.2, sonpm update js-yaml --package-lock-onlyre-resolved it andrenovatestays at 44.34.3.No other literal
hashintel/.githubreference remains. Composite actions are referenced through$/, so they need no change.renovate.jsonextendsgithub>hashintel/actions:renovate-config. Renovate reads repository config from the default branch, so thepull_requestrun ofhousekeeping-dependencies.yml(a dry run inextractmode againstgithub.repository) never reads therenovate.jsonon this branch. Before merge,mainhas no Renovate config and that run treats the repository as not yet onboarded. After merge,mainhas bothrenovate.jsonandrenovate-config.json, so the self-reference resolves. Extending thehashintel/.githubpreset instead would break once that copy is deleted.Callers are repointed in separate PRs. The copies in
hashintel/.githubstay until then.The
housekeeping-dependencies.ymlrun needs two things outside this PR:hashintel/actions/.github/workflows/housekeeping-dependencies.yml@*to the staging Vaultci-renovaterole, applied to staging Vault.RENOVATE_TOKEN_ENC_KEYsecret on this repository.Checks run locally:
actionlintv1.7.12 with the-ignoreflags frompreflight-actionlint.ymlreports no errors. Shellcheck was not installed, so actionlint's embedded shellcheck pass did not run.npm ci --ignore-scriptssucceeds on the updated lockfile, andnpm ls js-yamlshows only 4.3.2.renovate-config-validatorfromrenovate@44.34.3passes onrenovate.jsonand onrenovate-config.json. Onrenovate-config.jsonit warns that config migration is needed (fileMatch→managerFilePatternsin two custom managers). That warning comes from the source file, which this PR leaves unchanged.🤖 Generated with Claude Code
https://claude.ai/code/session_012vhP8cbLCbnWdQP7LLFB5A