ci: release and scan through the shared putdotio/.github workflows - #74
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The CI migration to the pinned shared workflows is consistent with the referenced contract, with only a minor documentation link clarity nit noted.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
This PR migrates rokit’s CI release and security scanning to the shared putdotio/.github reusable workflows (pinned to v1.0.1), centralizing release/scan implementation and pinning policy while keeping rokit’s workflow entrypoints stable for npm Trusted Publishing.
Changes:
- Switch
ci.ymlrelease to callputdotio/.github’sfrontend-release-npm.ymlreusable workflow and usevoidzero-dev/setup-vpdirectly (removing the local composite). - Add a new
scan.ymlworkflow that calls the sharedfrontend-scan.yml(Gitleaks, TruffleHog, Actionlint, Zizmor). - Add Dependabot action update cooldown and introduce
.github/zizmor.ymlto record zizmor policy/config; update distribution docs accordingly.
| File | Description |
|---|---|
| docs/DISTRIBUTION.md | Documents the new shared-workflow-based release flow and related release credential behavior. |
| .github/zizmor.yml | Adds zizmor rule configuration (dependabot cooldown + hash-pin policy). |
| .github/workflows/scan.yml | Adds a Scan workflow that reuses the shared frontend scan workflow pinned to v1.0.1. |
| .github/workflows/ci.yml | Updates verify setup to use voidzero-dev/setup-vp directly and switches release to the shared reusable release workflow. |
| .github/dependabot.yml | Adds a 1-day cooldown to Dependabot updates (actions + npm). |
| .github/actions/setup-vp/action.yml | Removes the local setup-vp composite action now replaced by the upstream action. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 649e625920
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Summary
The release job now calls the shared
frontend-release-npm.ymlworkflow from putdotio/.github, pinned to v1.0.1, and a newscan.ymlcalls the shared Gitleaks, TruffleHog, Actionlint, and Zizmor scan. The localsetup-vpcomposite is gone;voidzero-dev/setup-vpresolves the Vite+ version frompackage.json. Dependabot gets the same one-day cooldown on actions as on npm, and.github/zizmor.ymlrecords that cooldown and the hash-pin policy. Contract: https://github.com/putdotio/.github/blob/main/frontend/README.mdVerification
actionlint and zizmor clean locally; the scan workflow runs on this pull request. Gitleaks and TruffleHog full-history scans ran clean locally before adoption. The release path is proven on the next
mainpush that carries a releasable commit.Notes
npm trusted publishing still sees workflow
ci.ymland Environmentrelease, so no npm-side change.