Skip to content

Onboard slang-rhi to slang PR board-sync workflow - #804

Merged
jhelferty-nv merged 5 commits into
mainfrom
onboard-pr-board-sync
Jul 31, 2026
Merged

jhelferty-nv merged 5 commits into
mainfrom
onboard-pr-board-sync

Conversation

@jhelferty-nv

@jhelferty-nv jhelferty-nv commented Jul 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Replace the open-only add-pr-to-project.yml workflow with thin callers for slang's reusable pr-board-sync.yml (Status, Source, assignment, fork-review relay).
  • Wire pr-checks-complete.yml to slang-rhi's gating Actions workflows (ci, pre-commit).
  • Add pr-sweep-nightly.yml so this repo gets its own nightly mode: sweep backstop (enumerates this caller's open PRs via context.repo).
  • Callers use org secret SLANG_PR_BOT_TOKEN and permissions: {} per the slang onboarding templates.

Companions: shader-slang/slangpy#1084, shader-slang/slangpy-samples#57

Test plan

  • Confirm org secret SLANG_PR_BOT_TOKEN is available to shader-slang/slang-rhi
  • After merge to main, open a test PR (or use an existing one) and verify it appears on the Slang PR Tracking board with Source/Status
  • Push a commit that fails ci or pre-commit and confirm Status moves to Snagged (and recovers on green)
  • Submit a review on an origin PR and a fork PR; confirm Status updates (fork path uses bridge → apply)
  • Manually run PR Board Sweep (nightly) via workflow_dispatch and confirm open PRs reconcile
  • Confirm the old Add PR to Project Board workflow no longer runs

Replace the open-only add-pr-to-project workflow with thin callers for
slang's reusable pr-board-sync, wired to this repo's ci and pre-commit
gating workflows.
@jhelferty-nv
jhelferty-nv requested a review from a team as a code owner July 30, 2026 23:31
@jhelferty-nv
jhelferty-nv requested review from bmillsNV and removed request for a team July 30, 2026 23:31
@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Changes

The PR removes the project-classification workflow and adds event-specific workflows for pull-request board synchronization. It handles pull-request events, workflow completion, commit statuses, fork-originated reviews, and scheduled sweeps.

Pull-request board synchronization

Layer / File(s) Summary
Direct pull-request event synchronization
.github/workflows/pr-maintenance.yml, .github/zizmor.yml
Routes pull-request, review, and completed check-suite events to the shared board-sync workflow. Excludes fork pull-request reviews and configures reference-pinning policies.
Status and workflow completion synchronization
.github/workflows/pr-checks-complete.yml, .github/workflows/pr-commit-status.yml
Synchronizes completed CI or pre-commit workflows and settled commit statuses with the shared board-sync workflow.
Fork review bridge and privileged apply
.github/workflows/pr-review-fork-bridge.yml, .github/workflows/pr-review-fork-apply.yml
Captures fork review changes in an unprivileged workflow and applies synchronization after successful bridge completion.
Scheduled board synchronization
.github/workflows/pr-sweep-nightly.yml
Runs the shared board-sync workflow on a schedule or manual dispatch in sweep mode.

Suggested reviewers: bmillsnv

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes the onboarding of slang-rhi to the reusable Slang PR board-sync workflow.
Description check ✅ Passed The description accurately explains the workflow replacement, board-sync integration, secret usage, and test plan.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2


ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ae5cd31f-66d7-4156-9e27-c3291fd28ae8

📥 Commits

Reviewing files that changed from the base of the PR and between 1afb838 and ae2361b.

📒 Files selected for processing (6)
  • .github/workflows/add-pr-to-project.yml
  • .github/workflows/pr-checks-complete.yml
  • .github/workflows/pr-commit-status.yml
  • .github/workflows/pr-maintenance.yml
  • .github/workflows/pr-review-fork-apply.yml
  • .github/workflows/pr-review-fork-bridge.yml
💤 Files with no reviewable changes (1)
  • .github/workflows/add-pr-to-project.yml

Comment thread .github/workflows/pr-maintenance.yml
Comment thread .github/workflows/pr-review-fork-apply.yml
@jhelferty-nv jhelferty-nv self-assigned this Jul 30, 2026
@jhelferty-nv
jhelferty-nv removed the request for review from bmillsNV July 30, 2026 23:34
Keep @master callers intentional so board-sync updates propagate without
SHA pin-bump PRs; silence CodeRabbit/zizmor unpinned-uses on those refs.
@coderabbitai
coderabbitai Bot requested a review from bmillsNV July 31, 2026 14:08

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 6a270cf2-f0ab-49d2-b7a9-3af0dd0e6094

📥 Commits

Reviewing files that changed from the base of the PR and between ae2361b and f88d104.

📒 Files selected for processing (1)
  • .github/zizmor.yml

Comment thread .github/zizmor.yml
owner/repo alone does not match uses with a subpath; use
shader-slang/slang/* so @master board-sync callers are ref-pin allowed.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d4c62940-fabf-4d27-9d86-9fbfca910d04

📥 Commits

Reviewing files that changed from the base of the PR and between f88d104 and 8271617.

📒 Files selected for processing (1)
  • .github/zizmor.yml

Comment thread .github/zizmor.yml
Comment on lines +14 to +16
actions/*: ref-pin
github/*: ref-pin
dependabot/*: ref-pin

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

rg -n \
  --glob '.github/workflows/*.yml' \
  --glob '.github/workflows/*.yaml' \
  '^[[:space:]]*uses:[[:space:]]*(actions|github|dependabot)/' .

Repository: shader-slang/slang-rhi

Length of output: 160


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

printf 'Tracked files under .github:\n'
git ls-files .github | sed -n '1,160p'

printf '\n.zizmor.yml contents:\n'
if [ -f .github/zizmor.yml ]; then
  cat -n .github/zizmor.yml
fi

printf '\nWorkflow uses directives (all matching owner prefixes):\n'
rg -n --glob '.github/workflows/*.yml' --glob '.github/workflows/*.yaml' '^[[:space:]]*uses:' .github/workflows || true

printf '\nAll workflow files:\n'
find .github/workflows -maxdepth 1 -type f 2>/dev/null | sort || true

Repository: shader-slang/slang-rhi

Length of output: 3092


🌐 Web query:

zizmor unpinned-uses ref-pin github-actions owner/repo/* pattern reusable workflows

💡 Result:

In zizmor, the unpinned-uses audit is a security check that detects actions or reusable workflows referenced by tag, branch, or other mutable references rather than immutable commit SHA hashes [1][2]. To configure specific patterns for reusable workflows or actions, you use the rules.unpinned-uses.config.policies configuration in your zizmor configuration file [1]. This allows you to apply different pinning policies (such as ref-pin or hash-pin) based on repository patterns [1]. Configuration Details: - The configuration uses a pattern: policy mapping [1]. - Repository patterns allow you to target specific scopes, such as owner/repo/, to apply custom rules [1]. - Valid policies include: - hash-pin: Requires pinning to an immutable commit SHA (the modern default) [1]. - ref-pin: Allows pinning by branch or tag [1]. - any: Requires no specific pinning [1]. Example Configuration: If you wish to allow ref-pinning (branch or tag) for your own organization's reusable workflows (e.g., github/), you can define the following in your configuration [2]: rules: unpinned-uses: config: policies: github/: ref-pin Important Notes: - Scope: The unpinned-uses audit applies to both standard actions and reusable workflows [3][2]. - Default Behavior: As of zizmor v1.20.0, the default policy for all actions and reusable workflows is to require hash-pinning [1][4]. - Pattern Matching: You can use patterns like owner/repo/ to match entire repositories or namespaces [1]. The zizmor documentation provides specific repository pattern formats to ensure precise matching [1][5].

Citations:


Remove the broad ref-pin exceptions.

The workflow references do not require actions/*, github/*, or dependabot/* ref-pinning: only github/* is needed for the board-sync reusable workflow, and that pattern is already covered by shader-slang/slang/*. Keep hash-pin as the default for all unlisted uses.

Schedule mode:sweep via slang's reusable pr-board-sync so this repo's open
PRs get the same nightly backstop as slang.
@jhelferty-nv
jhelferty-nv requested review from jkiviluoto-nv, jkwak-work and skallweitNV and removed request for bmillsNV July 31, 2026 17:31
Comment thread .github/zizmor.yml
@jhelferty-nv
jhelferty-nv merged commit 455d3bd into main Jul 31, 2026
30 checks passed
@jhelferty-nv
jhelferty-nv deleted the onboard-pr-board-sync branch July 31, 2026 22:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants