Skip to content

chore(ci): remove the retired dev lanes and the dormant promotion exception - #286

Merged
freebuff-web[bot] merged 1 commit into
mainfrom
chore/drop-dormant-dev-lanes
Oct 1, 2026
Merged

freebuff-web[bot] merged 1 commit into
mainfrom
chore/drop-dormant-dev-lanes

Conversation

@freebuff-web

@freebuff-web freebuff-web Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

What

Completes the dev branch retirement (branch deleted 2026-10-01, content landed via #181; docs synced in #285) by removing every dormant dev lane from the CI/enforcement surface, and restores the security-audit gate on pull requests.

Why

  • enforce-target carried a leftover dev → main promotion exception for a branch that no longer exists.
  • ci.yml and container.yml still listed dev push triggers, so a recreated dev would silently get CI and image builds against the "do not recreate dev" policy.
  • Gate gap found while auditing the lanes: security-audit.yml triggered only on pull requests targeting dev. Since main became the integration line, the audit never ran on any pull request — only post-merge on push to main. That is a fail-closed gate that has effectively been offline for PRs.

Changes

  • .github/scripts/pr-quality.cjs — remove the promotionBase exception and the now-unused headRef / headFromSameRepo parameters and isSameGithubRepo helper. The exception was dead logic in production: it required base main, which the allow-list already accepts, so it could never change a verdict. Removal is behaviour-neutral by construction.
  • .github/workflows/enforce-pr-target.yml — drop the unused import/arguments, update the policy comment.
  • .github/workflows/ci.yml — push trigger branches: [main, preview, dev] → [main, preview].
  • .github/workflows/container.yml — drop the dev push lane and the refs/heads/dev build-and-load gate term; PRs and off-main dispatches still build-and-load, tags still publish.
  • .github/workflows/security-audit.yml — pull_request: branches: [dev] → [main], push: [dev, main] → [main]. Restores the audit as a pre-merge gate.
  • Comment-only updates in enforce-issue-quality.yml, pr-labeler.yml, stale-needs-info.yml (no more "landing on dev" wording).
  • Tests: .github/scripts/pr-quality.test.cjs now pins that a promotion-shaped PR is an ordinary wrong_base (exception gone); .github/scripts/enforce-pr-target.test.cjs and tests/ci-workflows.test.ts pin the absence of isSameGithubRepo / promotionBase / headRef and the exact wrongBase expression; container/ci trigger pins updated. The wrong-base suites for dev as a base are intentionally kept.
  • Docs: AGENTS.md, MAINTAINERS.md, structure/06_docs-and-release.md ("dormant" → "removed"); CHANGELOG.md records the security-audit gate restoration.

Security analysis (workflow + enforcement boundary)

  • Strictly tightening. No permission, token, action-ref, or trigger-widening change anywhere in the diff. Two enforcement surfaces lose a dormant bypass/trigger (dev promotion exception, dev push lanes); one fail-closed gate (security-audit on PRs) is restored. permissions: blocks, action SHAs, and the pinned allow-list ALLOWED_BASES = ["main"] are untouched.
  • The promotion exception removal cannot change any live verdict: promotionBase required baseRef === "main", and !allowedBases.includes("main") is always false, so wrongBase never depended on it. The rewritten unit tests document this.
  • Restoring security-audit on PRs re-enables a merge-blocking audit on the current tree; the audit already runs on every push to main and is green there, so no latent findings are expected. If a finding appears, the policy is repair-not-suppress.
  • container.yml publishing (packages: write, self-hosted jan) is untouched; only the non-pushing build-and-load lane loses its dev trigger.

Verification

  • node --test .github/scripts/*.test.cjs — 142 pass, 0 fail (before the pin fix; rerun green after).
  • bun test tests/ci-workflows.test.ts tests/review-execution-policy.test.ts — 93 pass, 0 fail (1172 assertions).
  • bun run typecheck — clean.

…eption

The dev branch is gone; its CI lanes (ci/container push triggers), the
dead dev -> main promotion exception in enforce-target, and the stale dev
wording go with it. Also restores security-audit gating on pull requests:
it only triggered for PRs targeting dev, so it had stopped running on PRs
entirely.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: GroepOnline/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 8bb7efd1-358f-4a07-aaa0-20d8e3a5ebaf

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@capy-ai

capy-ai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Capy couldn't review this pull request because OnlineChef's workspace is out of credits, add credits or enable auto-reload to resume automatic reviews.

Open in Capy

@github-actions github-actions Bot added the chore label Oct 1, 2026
@freebuff-web
freebuff-web Bot merged commit 845d29e into main Oct 1, 2026
22 checks passed
@freebuff-web
freebuff-web Bot deleted the chore/drop-dormant-dev-lanes branch October 1, 2026 08:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant