chore(ci): remove the retired dev lanes and the dormant promotion exception - #286
Conversation
…eption The dev branch is gone; its CI lanes (ci/container push triggers), the dead dev -> main promotion exception in enforce-target, and the stale dev wording go with it. Also restores security-audit gating on pull requests: it only triggered for PRs targeting dev, so it had stopped running on PRs entirely. 🤖 Generated with Codebuff Co-Authored-By: Codebuff <noreply@codebuff.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Repository: GroepOnline/opencodex/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Capy couldn't review this pull request because OnlineChef's workspace is out of credits, add credits or enable auto-reload to resume automatic reviews. |
What
Completes the
devbranch retirement (branch deleted 2026-10-01, content landed via #181; docs synced in #285) by removing every dormantdevlane from the CI/enforcement surface, and restores the security-audit gate on pull requests.Why
enforce-targetcarried a leftoverdev→mainpromotion exception for a branch that no longer exists.ci.ymlandcontainer.ymlstill listeddevpush triggers, so a recreateddevwould silently get CI and image builds against the "do not recreatedev" policy.security-audit.ymltriggered only on pull requests targetingdev. Sincemainbecame the integration line, the audit never ran on any pull request — only post-merge on push tomain. That is a fail-closed gate that has effectively been offline for PRs.Changes
.github/scripts/pr-quality.cjs— remove thepromotionBaseexception and the now-unusedheadRef/headFromSameRepoparameters andisSameGithubRepohelper. The exception was dead logic in production: it required basemain, which the allow-list already accepts, so it could never change a verdict. Removal is behaviour-neutral by construction..github/workflows/enforce-pr-target.yml— drop the unused import/arguments, update the policy comment..github/workflows/ci.yml— push triggerbranches: [main, preview, dev]→[main, preview]..github/workflows/container.yml— drop thedevpush lane and therefs/heads/devbuild-and-load gate term; PRs and off-main dispatches still build-and-load, tags still publish..github/workflows/security-audit.yml—pull_request: branches: [dev]→[main],push: [dev, main]→[main]. Restores the audit as a pre-merge gate.enforce-issue-quality.yml,pr-labeler.yml,stale-needs-info.yml(no more "landing ondev" wording)..github/scripts/pr-quality.test.cjsnow pins that a promotion-shaped PR is an ordinarywrong_base(exception gone);.github/scripts/enforce-pr-target.test.cjsandtests/ci-workflows.test.tspin the absence ofisSameGithubRepo/promotionBase/headRefand the exactwrongBaseexpression; container/ci trigger pins updated. The wrong-base suites fordevas a base are intentionally kept.AGENTS.md,MAINTAINERS.md,structure/06_docs-and-release.md("dormant" → "removed");CHANGELOG.mdrecords the security-audit gate restoration.Security analysis (workflow + enforcement boundary)
devpromotion exception,devpush lanes); one fail-closed gate (security-audit on PRs) is restored.permissions:blocks, action SHAs, and the pinned allow-listALLOWED_BASES = ["main"]are untouched.promotionBaserequiredbaseRef === "main", and!allowedBases.includes("main")is always false, sowrongBasenever depended on it. The rewritten unit tests document this.mainand is green there, so no latent findings are expected. If a finding appears, the policy is repair-not-suppress.container.ymlpublishing (packages: write, self-hostedjan) is untouched; only the non-pushing build-and-load lane loses itsdevtrigger.Verification
node --test .github/scripts/*.test.cjs— 142 pass, 0 fail (before the pin fix; rerun green after).bun test tests/ci-workflows.test.ts tests/review-execution-policy.test.ts— 93 pass, 0 fail (1172 assertions).bun run typecheck— clean.