ci: release and scan through the shared putdotio/.github workflows - #51
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The CI/workflow changes align with the shared workflow contract and appear operationally sound, with only a minor documentation link correction suggested.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
This PR updates the repository’s CI configuration to consume the shared putdotio/.github reusable workflows for releases and security/scanning, keeping workflow pins centralized while preserving npm Trusted Publishing requirements.
Changes:
- Switch the
releasejob to callputdotio/.github’sfrontend-release-npm.ymlreusable workflow pinned tov1.0.1. - Add a new
scan.ymlworkflow that calls the sharedfrontend-scan.ymlworkflow (Gitleaks, TruffleHog, Actionlint, Zizmor), also pinned tov1.0.1. - Replace the local
setup-vpcomposite action withvoidzero-dev/setup-vp, and align Dependabot/actionlint/zizmor policy configuration.
| File | Description |
|---|---|
| docs/DISTRIBUTION.md | Documents the move to shared release workflow (one link target needs correction). |
| .github/zizmor.yml | Adds zizmor policy configuration (dependabot cooldown + hash-pin policy). |
| .github/workflows/scan.yml | Introduces reusable scan workflow invocation pinned to v1.0.1. |
| .github/workflows/ci.yml | Migrates release to shared workflow and uses upstream setup-vp. |
| .github/dependabot.yml | Adds a 1-day cooldown for Dependabot updates (actions + npm). |
| .github/actions/setup-vp/action.yml | Removes the now-unneeded local composite action. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

The release job now calls the shared
frontend-release-npm.ymlworkflow from putdotio/.github, pinned to v1.0.1, and a newscan.ymlcalls the shared Gitleaks, TruffleHog, Actionlint, and Zizmor scan. The localsetup-vpcomposite is gone;voidzero-dev/setup-vpresolves the Vite+ version frompackage.json. Dependabot gets the same one-day cooldown on actions as on npm, and.github/zizmor.ymlrecords that cooldown and the hash-pin policy. Contract: https://github.com/putdotio/.github/blob/main/frontend/README.mdactionlint and zizmor clean locally; the scan workflow runs on this pull request. Gitleaks and TruffleHog full-history scans ran clean locally before adoption. npm trusted publishing still sees workflow
ci.ymland Environmentrelease, so no npm-side change.