Skip to content

ci: unify workflow names, triggers and release permissions #patch - #52

Merged
nmichlo merged 1 commit into
mainfrom
chore/standardise-workflows
Sep 9, 2026
Merged

nmichlo merged 1 commit into
mainfrom
chore/standardise-workflows

Conversation

@nmichlo

@nmichlo nmichlo commented Sep 9, 2026

Copy link
Copy Markdown
Owner

Why

Follow-up to the shared-workflow adoption. Three gaps were left: file names and triggers
still differed per repo, and the release caller did not grant its own permissions.

Naming and triggers

Every repo now has the same three files with the same names, extensions and job names:

before after
lint lint.yml / python-lint.yml / ci.yml lint.yaml
test python-test.yml / python-tests.yml / ci.yml test.yaml
release release.yaml / release.yml release.yaml

Lint and test now both run on the same events everywhere -- every PR, plus every push to
main so a merge is verified even if no PR check covered it:

on:
  pull_request:
  push:
    branches: [main]

Previously lint was PR-only in three repos but push+PR in norfair-rs, and tests were
PR-only in disent but tags-plus-branch-filtered in mtg-dataset.

The release caller now grants its own permissions

mtg-vision's release run failed at startup when PR #1 merged:

X This run likely failed because of a workflow file issue.

Cause: a reusable workflow cannot hold more permission than its caller. The shared
release.yaml pushes tags and creates releases, so it needs contents: write -- but
mtg-vision's default workflow token is read-only, while mtg-dataset and disent default
to write. Same caller, three different outcomes:

repo default_workflow_permissions result
mtg-vision read startup_failure
mtg-dataset write success, tagged v0.4.0
disent write success, tagged v0.9.0

Fixed on the caller rather than by changing a repo setting, so the workflow behaves the
same everywhere regardless of how a repo is configured:

jobs:
  release:
    permissions:
      contents: write
    uses: nmichlo/.github/.github/workflows/release.yaml@main

@codecov

codecov Bot commented Sep 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 68.37%. Comparing base (be80c08) to head (876aa2b).
⚠️ Report is 4 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main      #52      +/-   ##
==========================================
- Coverage   69.01%   68.37%   -0.64%     
==========================================
  Files         136      136              
  Lines        7613     7466     -147     
==========================================
- Hits         5254     5105     -149     
- Misses       2359     2361       +2     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@nmichlo
nmichlo merged commit 785c89d into main Sep 9, 2026
5 checks passed
@nmichlo
nmichlo deleted the chore/standardise-workflows branch September 9, 2026 06:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant