Repository navigation
fix: remove duplicate workflow keys and guard workflow syntax - #696
Conversation
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes across all three workflow files, including the installer contract and whether the new guard detects the original defect.
- Workflow repairs: Removed the duplicate
concurrencyblocks from Dependency Review and SonarCloud while preserving their triggers, permissions, jobs, and remaining concurrency settings. - Syntax guard: Added the
Workflow Syntaxjob with pinned actionlint1.7.12and a narrowly anchored exemption for GitHub's supportedqueuekey.
Validation: the exact full-workflow scan passed locally, and injected duplicate concurrency blocks were rejected in both repaired workflows and guards.yml. The new Workflow Syntax check also passed in CI. The .NET suite was not rerun locally for this workflow-only change.
gpt-6.1-sol | 𝕏
SonarCloud rule githubactions:S6506 flagged the curl download in the workflow syntax guard because a redirect could reach plain HTTP. Restrict the protocol to HTTPS and TLS 1.2 or newer. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes since the previous review at 8bbbc732, with the full PR diff checked for context.
- Hardened installer transport: Added
--proto '=https' --tlsv1.2to the actionlint installer-script download, requiring HTTPS with TLS 1.2 or newer without changing the pinned version or workflow scan.
Validation: the updated download succeeded, actionlint 1.7.12 installed successfully, and the exact full-workflow scan passed locally. The same curl flags rejected an HTTP URL, and Workflow Syntax passed in CI at 2ed1e1dd. The .NET suite was not rerun locally for this workflow-only change.
gpt-6.1-sol | 𝕏
|




Fixes thomasluizon/orbit-tickets#1180.
Remove the two extra top-level
concurrencyblocks from.github/workflows/sonarcloud.ymland.github/workflows/dependency-review.yml. Both files now matchorigin/mainexcept for their existingredesign/mainpull request filters.Add the
Workflow Syntaxjob to.github/workflows/guards.yml. It checks every workflow on pull requests to either base branch, using the official download script and release pinned to actionlint 1.7.12. Keeping installation and execution in the same step avoids consuming installer output fields.Installation was checked against the official installation instructions, the GitHub Actions usage example, and the pinned script source. The script was downloaded, inspected and invoked successfully with version
1.7.12and an existing temporary directory; its downloaded binary reported version 1.7.12. No external response fields are read.The full scan also reported
unexpected key "queue" for "concurrency" section. expected one of "cancel-in-progress", "group"inrelease.yml,staging-postgres-access-reconcile.ymlandstaging-reseed.yml. These findings are not applicable: GitHub documentsqueue: max, and each existing workflow pairs it withcancel-in-progress: false. The guard ignores only that exact diagnostic. Duplicate keys remain errors, including in the guard itself. No other actionlint findings remain.Assumptions
guards.yml; rejected adding a separate harness script because the work order confines this change to workflows.main, so jobs on a directredesign/mainpush are not established by this patch. Pull requests intoredesign/mainretain both checks. Live run verification belongs to the orchestrator after delivery.Test evidence
Before edits, the existing guard commands passed despite the duplicated keys:
node tools/check-timeless.mjs --base origin/redesign/main,node tools/check-dashes.mjs --check-baseline,node tools/check-frontmatter.mjs, andnode tools/check-root-allowlist.mjsall exited 0. There was no existing workflow syntax test to strengthen.Before removing either duplicate,
actionlint .github/workflows/sonarcloud.yml .github/workflows/dependency-review.ymlexited 1. The downloaded 1.7.12 binary then ran the new guard command across all workflows with the defect still present and also exited 1:actionlint -color -ignore '^unexpected key "queue" for "concurrency" section\. expected one of "cancel-in-progress", "group"$'Its four diagnostics were:
After the fix, the identical guard command exited 0 with no output. The exact shell block extracted from
guards.yml, including installation, also exited 0. A stdin mutation of the realguards.ymlappendingname: Duplicate nameexited 1 withkey "name" is duplicated in "workflow" section. A byte comparison confirmed both corrected files equal the main copies with only the pull request branch filter changed, and exactly one concurrency block each.dotnet build Orbit.slnx: passed with 0 errors. Existing dependency and obsolete API warnings remain.dotnet build Orbit.slnx --no-restore: passed with 0 errors before commit.node --test tools/__tests__/check-timeless.test.mjs tools/__tests__/check-suppression-allowlist.test.mjs: 57 passed.git diff --check: passed.dotnet test: 8,637 passed, 0 failed, 0 skipped across Domain (661), Application (4,958), Infrastructure (2,986), and Analyzers (32).