Skip to content

ci: release and scan through the shared putdotio/.github workflows - #51

Merged
altaywtf merged 2 commits into
mainfrom
ci/shared-workflows
Sep 22, 2026
Merged

altaywtf merged 2 commits into
mainfrom
ci/shared-workflows

Conversation

@altaywtf

Copy link
Copy Markdown
Member

The release job now calls the shared frontend-release-npm.yml workflow from putdotio/.github, pinned to v1.0.1, and a new scan.yml calls the shared Gitleaks, TruffleHog, Actionlint, and Zizmor scan. The local setup-vp composite is gone; voidzero-dev/setup-vp resolves the Vite+ version from package.json. Dependabot gets the same one-day cooldown on actions as on npm, and .github/zizmor.yml records that cooldown and the hash-pin policy. Contract: https://github.com/putdotio/.github/blob/main/frontend/README.md

actionlint and zizmor clean locally; the scan workflow runs on this pull request. Gitleaks and TruffleHog full-history scans ran clean locally before adoption. npm trusted publishing still sees workflow ci.yml and Environment release, so no npm-side change.

Copilot AI lite review requested due to automatic review settings September 22, 2026 12:01
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-22T12:07:01.837491Z 4aa00f5 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The CI/workflow changes align with the shared workflow contract and appear operationally sound, with only a minor documentation link correction suggested.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

This PR updates the repository’s CI configuration to consume the shared putdotio/.github reusable workflows for releases and security/scanning, keeping workflow pins centralized while preserving npm Trusted Publishing requirements.

Changes:

  • Switch the release job to call putdotio/.github’s frontend-release-npm.yml reusable workflow pinned to v1.0.1.
  • Add a new scan.yml workflow that calls the shared frontend-scan.yml workflow (Gitleaks, TruffleHog, Actionlint, Zizmor), also pinned to v1.0.1.
  • Replace the local setup-vp composite action with voidzero-dev/setup-vp, and align Dependabot/actionlint/zizmor policy configuration.
File Description
docs/​DISTRIBUTION.md Documents the move to shared release workflow (one link target needs correction).
.github/​zizmor.yml Adds zizmor policy configuration (dependabot cooldown + hash-pin policy).
.github/​workflows/​scan.yml Introduces reusable scan workflow invocation pinned to v1.0.1.
.github/​workflows/​ci.yml Migrates release to shared workflow and uses upstream setup-vp.
.github/​dependabot.yml Adds a 1-day cooldown for Dependabot updates (actions + npm).
.github/​actions/​setup-vp/​action.yml Removes the now-unneeded local composite action.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/DISTRIBUTION.md Outdated
@altaywtf
altaywtf merged commit 8e894f5 into main Sep 22, 2026
6 checks passed
@altaywtf
altaywtf deleted the ci/shared-workflows branch September 22, 2026 12:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants