Skip to content

ci: release and scan through the shared putdotio/.github workflows - #74

Merged
altaywtf merged 2 commits into
mainfrom
ci/shared-workflows
Sep 22, 2026
Merged

altaywtf merged 2 commits into
mainfrom
ci/shared-workflows

Conversation

@altaywtf

Copy link
Copy Markdown
Member

Summary

The release job now calls the shared frontend-release-npm.yml workflow from putdotio/.github, pinned to v1.0.1, and a new scan.yml calls the shared Gitleaks, TruffleHog, Actionlint, and Zizmor scan. The local setup-vp composite is gone; voidzero-dev/setup-vp resolves the Vite+ version from package.json. Dependabot gets the same one-day cooldown on actions as on npm, and .github/zizmor.yml records that cooldown and the hash-pin policy. Contract: https://github.com/putdotio/.github/blob/main/frontend/README.md

Verification

actionlint and zizmor clean locally; the scan workflow runs on this pull request. Gitleaks and TruffleHog full-history scans ran clean locally before adoption. The release path is proven on the next main push that carries a releasable commit.

Notes

npm trusted publishing still sees workflow ci.yml and Environment release, so no npm-side change.

Copilot AI lite review requested due to automatic review settings September 22, 2026 12:02
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-22T12:10:07.904429Z 649e625 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The CI migration to the pinned shared workflows is consistent with the referenced contract, with only a minor documentation link clarity nit noted.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

This PR migrates rokit’s CI release and security scanning to the shared putdotio/.github reusable workflows (pinned to v1.0.1), centralizing release/scan implementation and pinning policy while keeping rokit’s workflow entrypoints stable for npm Trusted Publishing.

Changes:

  • Switch ci.yml release to call putdotio/.github’s frontend-release-npm.yml reusable workflow and use voidzero-dev/setup-vp directly (removing the local composite).
  • Add a new scan.yml workflow that calls the shared frontend-scan.yml (Gitleaks, TruffleHog, Actionlint, Zizmor).
  • Add Dependabot action update cooldown and introduce .github/zizmor.yml to record zizmor policy/config; update distribution docs accordingly.
File Description
docs/​DISTRIBUTION.md Documents the new shared-workflow-based release flow and related release credential behavior.
.github/​zizmor.yml Adds zizmor rule configuration (dependabot cooldown + hash-pin policy).
.github/​workflows/​scan.yml Adds a Scan workflow that reuses the shared frontend scan workflow pinned to v1.0.1.
.github/​workflows/​ci.yml Updates verify setup to use voidzero-dev/setup-vp directly and switches release to the shared reusable release workflow.
.github/​dependabot.yml Adds a 1-day cooldown to Dependabot updates (actions + npm).
.github/​actions/​setup-vp/​action.yml Removes the local setup-vp composite action now replaced by the upstream action.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/DISTRIBUTION.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 649e625920

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/ci.yml
@altaywtf
altaywtf merged commit 793e810 into main Sep 22, 2026
6 checks passed
@altaywtf
altaywtf deleted the ci/shared-workflows branch September 22, 2026 12:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants