From 633e3d1074990808bd16683fee19c19aa58c5171 Mon Sep 17 00:00:00 2001 From: Nikolai Emil Damm Date: Mon, 5 Oct 2026 11:48:50 +0200 Subject: [PATCH 1/3] ci: reject retired repository links in active documentation --- .github/retired-repo-links.json | 1 + .github/workflows/ci.yaml | 54 ++++++++++++++++++++++++++++++++- 2 files changed, 54 insertions(+), 1 deletion(-) create mode 100644 .github/retired-repo-links.json diff --git a/.github/retired-repo-links.json b/.github/retired-repo-links.json new file mode 100644 index 00000000..49be5cd9 --- /dev/null +++ b/.github/retired-repo-links.json @@ -0,0 +1 @@ +{"version":1,"repositories":["devantler-tech/reusable-workflows"],"paths":["README.md","AGENTS.md"],"exceptions":[]} diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 9419a88f..5685d998 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -452,6 +452,57 @@ jobs: SKILL: ${{ matrix.skill }} run: skills-ref validate "$SKILL" + retired-repo-links: + name: Retired repository links + runs-on: ubuntu-latest + permissions: + contents: read + timeout-minutes: 10 + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6.0.2 + with: + persist-credentials: false + - name: Check active documentation + id: links + uses: devantler-tech/.github/actions/validate-retired-repo-links@bd0035dd8f41fcf1459b878882b8897443f8dc59 # v4.9.4 + with: + enabled: "true" + - name: Require a completed scan + env: + VALIDATED: ${{ steps.links.outputs.validated }} + run: test "$VALIDATED" = true + - name: Check out the exact validator for refusal controls + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6.0.2 + with: + repository: devantler-tech/.github + ref: bd0035dd8f41fcf1459b878882b8897443f8dc59 # v4.9.4 + path: .retired-link-validator-source + persist-credentials: false + - name: Prove retired links and incomplete scans fail + env: + GOWORK: off + GOFLAGS: "" + GOTOOLCHAIN: local + run: | + set -euo pipefail + control=$(mktemp -d "$RUNNER_TEMP/retired-links.XXXXXX") + trap 'rm -rf "$control"' EXIT + mkdir "$control/.github" + cp .github/retired-repo-links.json "$control/.github/" + cp README.md AGENTS.md "$control/" + go -C .retired-link-validator-source/actions/validate-retired-repo-links build -mod=readonly -trimpath -o "$control/validator" . + printf '\nhttps://github.com/devantler-tech/reusable-workflows\n' >>"$control/README.md" + status=0 + "$control/validator" --root "$control" >"$control/negative.log" 2>&1 || status=$? + test "$status" = 1 || { cat "$control/negative.log"; exit 1; } + grep -Eq '^README.md:[0-9]+: link targets retired repository devantler-tech/reusable-workflows$' "$control/negative.log" + rm "$control/.github/retired-repo-links.json" + status=0 + "$control/validator" --root "$control" >"$control/missing.log" 2>&1 || status=$? + test "$status" = 2 || { cat "$control/missing.log"; exit 1; } + grep -q '^Invalid configuration:' "$control/missing.log" + echo 'PASS: clean scan, seeded retired link rejection, and missing configuration refusal' + ci-required-checks: name: CI - Required Checks runs-on: ubuntu-latest @@ -460,12 +511,13 @@ jobs: statuses: read pull-requests: read timeout-minutes: 5 - needs: [validate-manifests, lint-scripts, check-version-bump, check-bundled-skill-edits, discover-skills, validate-spec] + needs: [retired-repo-links, validate-manifests, lint-scripts, check-version-bump, check-bundled-skill-edits, discover-skills, validate-spec] if: ${{ always() }} steps: - uses: devantler-tech/.github/actions/aggregate-job-checks@4b00bd6698af033dc472b39a7e609173fe38dfb1 # v6.0.6 with: job-results: >- + ${{ needs.retired-repo-links.result }} ${{ needs.validate-manifests.result }} ${{ needs.lint-scripts.result }} ${{ needs.check-version-bump.result }} From 4d2ac719bead5d7847c45ac4fa6212c5c0b68270 Mon Sep 17 00:00:00 2001 From: Nikolai Emil Damm Date: Mon, 5 Oct 2026 11:59:49 +0200 Subject: [PATCH 2/3] chore(ci): label the pinned checkout release accurately --- .github/workflows/ci.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 5685d998..05a7fec1 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -459,7 +459,7 @@ jobs: contents: read timeout-minutes: 10 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6.0.2 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Check active documentation @@ -472,7 +472,7 @@ jobs: VALIDATED: ${{ steps.links.outputs.validated }} run: test "$VALIDATED" = true - name: Check out the exact validator for refusal controls - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6.0.2 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: repository: devantler-tech/.github ref: bd0035dd8f41fcf1459b878882b8897443f8dc59 # v4.9.4 From 3205d34c18b78ea44ce7bf9fde7d9a1c9313755b Mon Sep 17 00:00:00 2001 From: Nikolai Emil Damm Date: Mon, 5 Oct 2026 12:22:51 +0200 Subject: [PATCH 3/3] fix(ci): quote the retired link guard workspace setting --- .github/workflows/ci.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index 05a7fec1..ad388449 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -480,7 +480,7 @@ jobs: persist-credentials: false - name: Prove retired links and incomplete scans fail env: - GOWORK: off + GOWORK: "off" GOFLAGS: "" GOTOOLCHAIN: local run: |