Repository navigation
ci: check links and scan pushes in the lane-selection job - #313
Conversation
Select affected lanes runs on every Next CI event, so it now runs the shared links and scan actions (v1.2.0) after a checkout. Next CI gains workflow_dispatch for the full workflow audit. The Scan and Links workflows and the unused .gitleaksignore go.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It reshapes the repository's core CI gate and its secret-scanning posture, and coupling link/scan into the lane-selection job changes failure semantics (a link or scan failure now skips all build/test lanes), which warrants human confirmation.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
This PR consolidates the repository's standalone Links and Scan GitHub Actions workflows into the existing Select affected lanes (changes) job of Next CI. Because changes is the lightweight Linux job that already runs on every event, appending a checkout plus the shared links and scan composite actions lets Markdown link checking and workflow scanning run there instead of as separate workflows, reducing the number of jobs per event. It also adds workflow_dispatch so a manual dispatch runs only the lane-selection job (links + a full scan). The .gitleaksignore file is dropped since Gitleaks only runs on private repos and this public repo relies on GitHub secret scanning and push protection.
Changes:
- Add
workflow_dispatchtrigger and appendactions/checkout+ pinnedlinksandscan(v1.2.0) steps to thechangesjob inci-next.yml. - Delete the
ScanandLinksworkflows and the now-unused.gitleaksignore. - Update
AGENTS.mdverification docs to describe link checking and scanning insideSelect affected lanes.
| File | Description |
|---|---|
.github/workflows/ci-next.yml |
Adds workflow_dispatch, a checkout, and the links/scan steps to the changes job; updates concurrency/doc comments. |
.github/workflows/scan.yml |
Removed; its secret/workflow scanning moves into the changes job. |
.github/workflows/links.yml |
Removed; Markdown link checking moves into the changes job. |
.gitleaksignore |
Removed; Gitleaks does not run on this public repo. |
AGENTS.md |
Verification section rewritten to describe link checks and scan inside Select affected lanes. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.


Change
Next CI's Linux
Select affected lanesjob checks Markdown links and scansnextpushes withputdotio/.githubv1.2.0, replacing the Scan and Links workflows.Select affected lanesnextSelect affected lanesworkflow_dispatch.gitleaksignoregoes; Gitleaks scans only private repositories, leaving this public one to GitHub secret scanning and push protection.Validation
pnpm test, andpnpm run markdown:checkWritten by an agent (Claude Code, Opus 5.5)