Skip to content

fix(validate): fetch scripts from molecule-ci instead of vendored copy - #24

Merged
HongmingWang-Rabbit merged 1 commit into
mainfrom
fix/validate-fetch-scripts-from-ci
Apr 29, 2026
Merged

HongmingWang-Rabbit merged 1 commit into
mainfrom
fix/validate-fetch-scripts-from-ci

Conversation

@HongmingWang-Rabbit

Copy link
Copy Markdown
Contributor

Summary

`validate-org-template.yml` and `validate-plugin.yml` expected `.molecule-ci/scripts/` to be vendored into the calling repo. That broke when callers didn't have the directory.

This PR: mirror the fix already in `validate-workspace-template.yml` — a second `actions/checkout@v4` of molecule-ci into `.molecule-ci-canonical/`, re-point script paths.

Currently broken (will be fixed by this PR)

  • `molecule-ai-org-template-medo-smoke#2`
  • `molecule-ai-org-template-molecule-worker-gemini#2`
  • `molecule-ai-org-template-reno-stars#2`
  • `molecule-ai-plugin-molecule-compliance#2`
  • `molecule-ai-plugin-molecule-freeze-scope#2`
  • `molecule-ai-plugin-molecule-prompt-watchdog#2`

All 6 are stuck on `validate / Org template validation` (or `/ Plugin validation`) failing with: `No file in [...] matched to [.molecule-ci/scripts/requirements.txt or **/pyproject.toml]`.

Changes

  • Add a second checkout of molecule-ci into `.molecule-ci-canonical/` in both workflows.
  • Re-point `cache-dependency-path` and `python3 ...` invocations.
  • Add `.molecule-ci-canonical` to secret-scan `SKIP_DIRS` so the side-tree isn't walked.
  • Backwards compatible: callers that still have a vendored `.molecule-ci/scripts/` copy are unaffected — the workflow no longer reads from there, so the vendored copy becomes harmless dead weight (cleanup deferred to a separate PR).

Verification

  • `yaml.safe_load` parses both workflows
  • After merge: re-trigger CI on the 6 stuck PRs and confirm validate passes

🤖 Generated with Claude Code

…pecting them in caller

The validate-org-template.yml and validate-plugin.yml workflows
expected `.molecule-ci/scripts/` to be vendored INTO each calling
repo. That worked for the repos that copied the directory in, but
broke on the ones that didn't:

- molecule-ai-org-template-medo-smoke
- molecule-ai-org-template-molecule-worker-gemini
- molecule-ai-org-template-reno-stars
- molecule-ai-plugin-molecule-compliance
- molecule-ai-plugin-molecule-freeze-scope
- molecule-ai-plugin-molecule-prompt-watchdog

Surfaced when the secret-scan rollout PRs hit those repos and the
required validate check failed on missing
`.molecule-ci/scripts/requirements.txt`.

Mirror the same fix already in validate-workspace-template.yml: a
second `actions/checkout@v4` of molecule-ci into
`.molecule-ci-canonical/`, with script paths re-pointed accordingly.
Single source of truth — callers never need to vendor or sync.

Also adds `.molecule-ci-canonical` to the secret-scan SKIP_DIRS so
the side-checked-out tree doesn't get walked.

Callers can drop their vendored `.molecule-ci/scripts/` copies in a
follow-up cleanup. Both shapes work after this PR — the vendored
copy is harmless dead weight, not a conflict.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant