diff --git a/patterns/archetypes/responsive-docs-tester.json b/patterns/archetypes/responsive-docs-tester.json index 0322b8e..85f77af 100644 --- a/patterns/archetypes/responsive-docs-tester.json +++ b/patterns/archetypes/responsive-docs-tester.json @@ -31,7 +31,8 @@ "Capture screenshots only on failure and publish them with the upload-asset safe output so evidence is attached without bloating the report", "Always stop the local preview server in a cleanup step even if earlier steps fail", "Call noop when every viewport passes instead of leaving no output", - "Set expires and close-older-issues (or skip-if-match) on create-issue so scheduled runs don't accumulate duplicate reports" + "Set expires and close-older-issues (or skip-if-match) on create-issue so scheduled runs don't accumulate duplicate reports", + "Since this archetype combines schedule with workflow_dispatch, set concurrency.job-discriminator to ${{ github.event_name == 'schedule' && 'scheduled' || github.run_id }} so a manually-triggered run doesn't get cancelled by (or cancel) the next scheduled run" ], "anti_patterns": [] } diff --git a/patterns/archetypes/security-scanner.json b/patterns/archetypes/security-scanner.json index 3645945..52e3ca3 100644 --- a/patterns/archetypes/security-scanner.json +++ b/patterns/archetypes/security-scanner.json @@ -27,7 +27,8 @@ "Scope analysis to a bounded recent window (e.g. last 3 days of commits) rather than the whole history", "Report findings as code-scanning alerts, not issues, so they surface in the Security tab", "Call noop when the scan is clean instead of leaving no output", - "Add skip-if-match to the schedule trigger and expires to create-issue so scheduled runs don't reopen a duplicate finding every day" + "Add skip-if-match to the schedule trigger and expires to create-issue so scheduled runs don't reopen a duplicate finding every day", + "Set threat-detection: false on safe-outputs since the findings necessarily quote suspicious code snippets, which would otherwise trigger false-positive threat-detection warnings on the scanner's own output" ], "anti_patterns": [] }