Skip to content

chore: sync workflow templates - #136

Merged
stranske merged 1 commit into
mainfrom
sync/workflows-db755a28c753
Jun 23, 2026
Merged

stranske merged 1 commit into
mainfrom
sync/workflows-db755a28c753

Conversation

@stranske

@stranske stranske commented Jun 23, 2026 •

Copy link
Copy Markdown
Owner

Sync Summary

Files Updated

  • agents-guard.yml: Agents guard - enforces agents workflow protections (Health 45)

Files Skipped

  • pr-00-gate.yml: File exists and sync_mode is create_only
  • ci.yml: File exists and sync_mode is create_only
  • renovate.json: File exists and sync_mode is create_only
  • cross-repo-smoke.yml: File exists and sync_mode is create_only
  • llm_slots.json: None

Review Checklist

  • CI passes with updated workflows
  • No repo-specific customizations were overwritten

Source: stranske/Workflows
Source SHA: 56350f8170508a46e484c295404c47a75c9e2db0
Template hash: db755a28c753
Sync branch: sync/workflows-db755a28c753
Consumer repo: stranske/Fine-Art-Archive
Manifest: .github/sync-manifest.yml

Summary by CodeRabbit

  • Chores
    • Updated internal workflow configuration to use a newer version of the API client setup tool.

Automated sync from stranske/Workflows
Template hash: db755a28c753

Changes synced from sync-manifest.yml
@stranske stranske added sync Automated sync from Workflows automated Automated sync from Workflows labels Jun 23, 2026
@coderabbitai

coderabbitai Bot commented Jun 23, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b66adc1f-5453-4886-934e-6d1cc113acf2

📥 Commits

Reviewing files that changed from the base of the PR and between 06f0e4b and 5ff2211.

📒 Files selected for processing (1)
  • .github/workflows/agents-guard.yml
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • stranske/Workflows (auto-detected)
  • stranske/Template (auto-detected)
📜 Recent review details
🧰 Additional context used
📓 Path-based instructions (5)
.github/workflows/*.{yml,yaml}

📄 CodeRabbit inference engine (.github/copilot-instructions.md)

startup_failure in GitHub Actions workflows with zero jobs indicates GitHub couldn't parse the workflow; check for invalid YAML syntax, conflicting permissions: blocks on workflow_call reusable workflows, invalid permission scopes, or circular workflow references

Files:

  • .github/workflows/agents-guard.yml
.github/workflows/*.yml

📄 CodeRabbit inference engine (CLAUDE.md)

Reference reusable workflows with @main by default unless intentionally pinning to an exact commit SHA for a documented reason

Files:

  • .github/workflows/agents-guard.yml
{.github/workflows/agents-*.yml,.github/workflows/autofix.yml,.github/codex/**,docs/**}

📄 CodeRabbit inference engine (CLAUDE.md)

Synced workflows, prompts, scripts, and consumer docs are managed through .github/sync-manifest.yml in Workflows and should not be edited locally

Files:

  • .github/workflows/agents-guard.yml
**/.github/workflows/*.yml

📄 CodeRabbit inference engine (AGENTS.md)

Reference reusable workflows with @main unless intentionally pinning to an exact commit SHA for a controlled reason.

Files:

  • .github/workflows/agents-guard.yml
{**/.github/workflows/agents-*.yml,.github/workflows/autofix.yml,.github/codex/**,docs/ops/CONSUMER_REPO_MAINTENANCE.md,docs/keepalive/Agents.md}

📄 CodeRabbit inference engine (AGENTS.md)

Synced workflows, prompts, scripts, and consumer docs (including agents-*.yml, autofix.yml, .github/codex/ prompts, and synced scripts) are managed through .github/sync-manifest.yml in Workflows and should not be edited locally; fix issues in Workflows instead.

Files:

  • .github/workflows/agents-guard.yml
🔀 Multi-repo context stranske/Workflows, stranske/Template

Perfect! I now have comprehensive cross-repo context. Let me document my findings:

Linked repositories findings

stranske/Workflows

Template setup-api-client action (source of truth):
The source template at ./templates/consumer-repo/.github/workflows/agents-guard.yml [::stranske/Workflows::] pins the setup-api-client action to commit 6c3391d38bbc20a4577ac42b9aa6c9dc4e462c09 (lines 114 and 183). This is the newer pinned revision being rolled out to consumer repos.

Action definition:
The setup-api-client action (located at ./.github/actions/setup-api-client/action.yml) [::stranske/Workflows::] is a composite action that:

  • Installs @octokit dependencies at pinned versions
  • Exports all available tokens to environment variables
  • Ensures consistent API client setup across workflow jobs

The action accepts inputs like secrets, github_token, individual PATs, and app credentials, and outputs token_count, available_tokens, and setup_contract (lines 16-74 of action.yml).

stranske/Template

Consumers of the external setup-api-client reference:
Only the agents-guard.yml workflow [::stranske/Template::] references the external stranske/Workflows/.github/actions/setup-api-client action. This occurs in two fallback paths:

  • Line 114: "Setup API client (Workflows fallback)" step for pull_request_target events
  • Line 183: "Setup API client (Workflows fallback)" step for pull_request events

These fallback steps execute when the local ./.github/actions/setup-api-client action is not available (checked by the preceding "Check API client action" steps at lines 86-97 and 155-166).

Usage pattern:
The fallback provides defensive coverage - it ensures the workflow can proceed even if the consumer repo hasn't yet synced their local setup-api-client action. The other 24 workflows in the repo [::stranske/Template::] use the local ./.github/actions/setup-api-client reference and are not affected by the external action pin update.

Scope of change:
The update changes only two lines (114 and 183) in agents-guard.yml to update the pinned SHA. The action interface (inputs/outputs) remains stable, so consuming workflows don't need modifications.

🔇 Additional comments (1)
.github/workflows/agents-guard.yml (1)

114-114: 🔒 Security & Privacy

The pinned SHA 6c3391d38bbc20a4577ac42b9aa6c9dc4e462c09 is resolvable in stranske/Workflows (commit message: "chore(main): release 1.17.3") and the # v1 annotation is accurate—the v1 tag points to this exact commit. The sync matches the source template.

Note: This file is synced through .github/sync-manifest.yml in Workflows; any updates should be made upstream rather than edited locally.


📝 Walkthrough

Walkthrough

Two lines in .github/workflows/agents-guard.yml are updated to pin a new commit SHA for the stranske/Workflows/.github/actions/setup-api-client action, one in the pull_request_target fallback step and one in the pull_request fallback step.

Changes

SHA pin update in agents-guard workflow

Layer / File(s) Summary
Update pinned SHA in both fallback steps
.github/workflows/agents-guard.yml
The uses: reference for stranske/Workflows/.github/actions/setup-api-client is updated to a new commit SHA in both the pull_request_target fallback step (line 114) and the pull_request fallback step (line 183).

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Possibly related PRs

  • stranske/Fine-Art-Archive#130: Performs the same pattern of updating the pinned commit SHA for stranske/Workflows/.github/actions/setup-api-client in both fallback steps of agents-guard.yml.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'chore: sync workflow templates' directly matches the PR's objective of synchronizing workflow templates from the source repository, clearly summarizing the primary change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch sync/workflows-db755a28c753

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Keepalive Loop Reporter. Do not edit.

@github-actions

github-actions Bot commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Agents Gate Followups. Do not edit.

@stranske
stranske merged commit e3fd951 into main Jun 23, 2026
55 of 61 checks passed
@stranske
stranske deleted the sync/workflows-db755a28c753 branch June 23, 2026 18:39

This branch had an error being deployed

1 failed deployment
agent-standard — 5ff22119 Deployed Jun 23, 2026 by stranske via Record autofix metrics #685
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated sync from Workflows sync Automated sync from Workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant