Skip to content

ci: check links and scan pushes in the lane-selection job - #313

Merged
altaywtf merged 2 commits into
nextfrom
fix/scan-in-verify
Oct 5, 2026
Merged

altaywtf merged 2 commits into
nextfrom
fix/scan-in-verify

Conversation

@altaywtf

@altaywtf altaywtf commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Change

Next CI's Linux Select affected lanes job checks Markdown links and scans next pushes with putdotio/.github v1.2.0, replacing the Scan and Links workflows.

Event Before After
Pull request Scan (2–4 jobs) + Links (1) links in Select affected lanes
Push to next Links (1 job) links and scan in Select affected lanes
Weekly Scan (4 jobs) none
workflow_dispatch not available links and a full workflow audit, no macOS lanes
  • Risk: .gitleaksignore goes; Gitleaks scans only private repositories, leaving this public one to GitHub secret scanning and push protection.

Validation

  • Actionlint 1.7.12, Zizmor 1.29.0, pnpm test, and pnpm run markdown:check
  • Seeding a broken link fails the links step
  • Unverified: Xcode lanes; no Swift, project, or toolchain input changed.

Written by an agent (Claude Code, Opus 5.5)

Select affected lanes runs on every Next CI event, so it now runs the shared links and scan actions (v1.2.0) after a checkout. Next CI gains workflow_dispatch for the full workflow audit. The Scan and Links workflows and the unused .gitleaksignore go.
Copilot AI balanced review requested due to automatic review settings October 5, 2026 06:03
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It reshapes the repository's core CI gate and its secret-scanning posture, and coupling link/scan into the lane-selection job changes failure semantics (a link or scan failure now skips all build/test lanes), which warrants human confirmation.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

This PR consolidates the repository's standalone Links and Scan GitHub Actions workflows into the existing Select affected lanes (changes) job of Next CI. Because changes is the lightweight Linux job that already runs on every event, appending a checkout plus the shared links and scan composite actions lets Markdown link checking and workflow scanning run there instead of as separate workflows, reducing the number of jobs per event. It also adds workflow_dispatch so a manual dispatch runs only the lane-selection job (links + a full scan). The .gitleaksignore file is dropped since Gitleaks only runs on private repos and this public repo relies on GitHub secret scanning and push protection.

Changes:

  • Add workflow_dispatch trigger and append actions/checkout + pinned links and scan (v1.2.0) steps to the changes job in ci-next.yml.
  • Delete the Scan and Links workflows and the now-unused .gitleaksignore.
  • Update AGENTS.md verification docs to describe link checking and scanning inside Select affected lanes.
File Description
.github/​workflows/​ci-next.yml Adds workflow_dispatch, a checkout, and the links/scan steps to the changes job; updates concurrency/doc comments.
.github/​workflows/​scan.yml Removed; its secret/workflow scanning moves into the changes job.
.github/​workflows/​links.yml Removed; Markdown link checking moves into the changes job.
.gitleaksignore Removed; Gitleaks does not run on this public repo.
AGENTS.md Verification section rewritten to describe link checks and scan inside Select affected lanes.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/ci-next.yml Outdated
Comment thread .github/workflows/ci-next.yml Outdated
@altaywtf
altaywtf merged commit 036dd0b into next Oct 5, 2026
7 checks passed
@altaywtf
altaywtf deleted the fix/scan-in-verify branch October 5, 2026 06:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants