From d0aeb3bf1cfc46161ba6a7c8ef825c0d8db5ee02 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Sat, 25 Apr 2026 19:07:42 +0000 Subject: [PATCH] chore: sync workflow templates from Workflows repo Automated sync from stranske/Workflows Template hash: eb19c965e8f4 Changes synced from sync-manifest.yml --- .github/scripts/bot_comment_auth_coverage.js | 50 ++++++++++++++------ .github/workflows/agents-weekly-metrics.yml | 2 + 2 files changed, 37 insertions(+), 15 deletions(-) diff --git a/.github/scripts/bot_comment_auth_coverage.js b/.github/scripts/bot_comment_auth_coverage.js index 481c7f9e..4f88bc80 100644 --- a/.github/scripts/bot_comment_auth_coverage.js +++ b/.github/scripts/bot_comment_auth_coverage.js @@ -163,6 +163,18 @@ function summarizeOrganicEvidence(records = [], options = {}) { const eventCounts = Object.create(null); const latestByComponentEvent = Object.create(null); + if (records.length === 0) { + return { + schema: 'workflows-bot-comment-auth-organic-evidence/v1', + required_events: requiredEvents, + required_components: components, + expected_mode: expectedMode === 'unknown' ? '' : expectedMode, + event_counts: eventCounts, + blockers: [], + status: 'no-data', + }; + } + for (const record of records) { if (!record.component || !record.event_name) continue; eventCounts[record.component] ||= {}; @@ -310,9 +322,19 @@ function artifactFamilyFromSelection(artifact = {}) { return ''; } +function componentCoverageStatus(blockers, policy, latest) { + if (blockers.length === 0) return 'pass'; + if (!latest && policy.missing_record_severity === 'no-data') return 'no-data'; + return 'warning'; +} + +function isComponentMissingBlocker(blocker) { + return Object.keys(COMPONENT_POLICIES).some((component) => blocker === `missing-${component}`); +} + function summarizeBotCommentAuthCoverage(records = [], options = {}) { const policy = normalizePolicy(options); - const parseErrors = Number(options.parse_errors || options.parseErrors || 0); + const parseErrors = Number(options.parse_errors ?? options.parseErrors ?? 0); const artifactSelection = normalizeArtifactSelectionSummary( options.artifact_selection_report ?? options.artifactSelectionReport ); @@ -357,12 +379,6 @@ function summarizeBotCommentAuthCoverage(records = [], options = {}) { blockers.push(`expected-${componentPolicyConfig.expected_mode}-${component}`); } } - let status = 'pass'; - if (blockers.length > 0) { - status = componentPolicyConfig.missing_record_severity === 'no-data' && !latest - ? 'no-data' - : 'warning'; - } return { component, record_count: componentRecords.length, @@ -370,7 +386,7 @@ function summarizeBotCommentAuthCoverage(records = [], options = {}) { expected_mode: componentPolicyConfig.expected_mode, invalid_expected_mode: componentPolicyConfig.invalid_expected_mode, allowed_modes: componentPolicyConfig.allowed_modes, - status, + status: componentCoverageStatus(blockers, componentPolicyConfig, latest), blockers, }; }); @@ -388,9 +404,8 @@ function summarizeBotCommentAuthCoverage(records = [], options = {}) { let coverageStatus = 'pass'; if (authRecords.length === 0) { - coverageStatus = parseErrors > 0 || artifactSelectionWarning || authArtifactInputMismatch - ? 'warning' - : 'no-data'; + const nonMissingBlockers = blockers.filter((blocker) => !isComponentMissingBlocker(blocker)); + coverageStatus = nonMissingBlockers.length > 0 ? 'warning' : 'no-data'; } else if (blockers.length > 0) { coverageStatus = 'warning'; } @@ -494,10 +509,15 @@ function isPotentialAuthCoverageFile(file) { const normalized = cleanString(file).split(path.sep).join('/'); const basename = path.basename(normalized); if (!normalized.endsWith('.json')) return false; - return normalized.includes('/bot-comment-auth-coverage-wrapper-') || - normalized.includes('/bot-comment-auth-coverage-reusable-') || - basename === 'wrapper.json' || - basename === 'reusable.json'; + const segments = normalized.split('/'); + const hasWrapperArtifactDir = segments.some((segment) => + segment.startsWith('bot-comment-auth-coverage-wrapper-') + ); + const hasReusableArtifactDir = segments.some((segment) => + segment.startsWith('bot-comment-auth-coverage-reusable-') + ); + return (basename === 'wrapper.json' && hasWrapperArtifactDir) || + (basename === 'reusable.json' && hasReusableArtifactDir); } function readJsonRecords(files = []) { diff --git a/.github/workflows/agents-weekly-metrics.yml b/.github/workflows/agents-weekly-metrics.yml index 6253fab4..c73ec3e4 100644 --- a/.github/workflows/agents-weekly-metrics.yml +++ b/.github/workflows/agents-weekly-metrics.yml @@ -188,6 +188,8 @@ jobs: ${{ vars.BOT_COMMENT_AUTH_HARD_BLOCK_APPROVED || 'false' }} BOT_COMMENT_WRAPPER_EXPECTED_AUTH_MODE: >- ${{ vars.BOT_COMMENT_WRAPPER_EXPECTED_AUTH_MODE || 'client-id' }} + BOT_COMMENT_WRAPPER_ALLOWED_AUTH_MODES: >- + ${{ vars.BOT_COMMENT_WRAPPER_ALLOWED_AUTH_MODES || 'client-id' }} BOT_COMMENT_REUSABLE_EXPECTED_AUTH_MODE: >- ${{ vars.BOT_COMMENT_REUSABLE_EXPECTED_AUTH_MODE }} BOT_COMMENT_REUSABLE_ALLOWED_AUTH_MODES: >-