Skip to content

fix: remove duplicate workflow keys and guard workflow syntax - #696

Merged
thomasluizon merged 2 commits into
redesign/mainfrom
fix/ticket-1180-workflow-duplicate-keys
Oct 3, 2026
Merged

thomasluizon merged 2 commits into
redesign/mainfrom
fix/ticket-1180-workflow-duplicate-keys

Conversation

@thomasluizon

Copy link
Copy Markdown
Owner

Fixes thomasluizon/orbit-tickets#1180.

Remove the two extra top-level concurrency blocks from .github/workflows/sonarcloud.yml and .github/workflows/dependency-review.yml. Both files now match origin/main except for their existing redesign/main pull request filters.

Add the Workflow Syntax job to .github/workflows/guards.yml. It checks every workflow on pull requests to either base branch, using the official download script and release pinned to actionlint 1.7.12. Keeping installation and execution in the same step avoids consuming installer output fields.

Installation was checked against the official installation instructions, the GitHub Actions usage example, and the pinned script source. The script was downloaded, inspected and invoked successfully with version 1.7.12 and an existing temporary directory; its downloaded binary reported version 1.7.12. No external response fields are read.

The full scan also reported unexpected key "queue" for "concurrency" section. expected one of "cancel-in-progress", "group" in release.yml, staging-postgres-access-reconcile.yml and staging-reseed.yml. These findings are not applicable: GitHub documents queue: max, and each existing workflow pairs it with cancel-in-progress: false. The guard ignores only that exact diagnostic. Duplicate keys remain errors, including in the guard itself. No other actionlint findings remain.

Assumptions

  • Implement the guard inline in guards.yml; rejected adding a separate harness script because the work order confines this change to workflows.
  • Preserve existing event triggers as required by Scope; rejected introducing push events. Dependency Review is pull-request-only and SonarCloud pushes target main, so jobs on a direct redesign/main push are not established by this patch. Pull requests into redesign/main retain both checks. Live run verification belongs to the orchestrator after delivery.

Test evidence

Before edits, the existing guard commands passed despite the duplicated keys: node tools/check-timeless.mjs --base origin/redesign/main, node tools/check-dashes.mjs --check-baseline, node tools/check-frontmatter.mjs, and node tools/check-root-allowlist.mjs all exited 0. There was no existing workflow syntax test to strengthen.

Before removing either duplicate, actionlint .github/workflows/sonarcloud.yml .github/workflows/dependency-review.yml exited 1. The downloaded 1.7.12 binary then ran the new guard command across all workflows with the defect still present and also exited 1:

actionlint -color -ignore '^unexpected key "queue" for "concurrency" section\. expected one of "cancel-in-progress", "group"$'

Its four diagnostics were:

.github/workflows/dependency-review.yml:11:1: key "concurrency" is duplicated in "workflow" section. previously defined at line:7,col:1 [syntax-check]
.github/workflows/dependency-review.yml:15:1: key "concurrency" is duplicated in "workflow" section. previously defined at line:7,col:1 [syntax-check]
.github/workflows/sonarcloud.yml:13:1: key "concurrency" is duplicated in "workflow" section. previously defined at line:9,col:1 [syntax-check]
.github/workflows/sonarcloud.yml:17:1: key "concurrency" is duplicated in "workflow" section. previously defined at line:9,col:1 [syntax-check]

After the fix, the identical guard command exited 0 with no output. The exact shell block extracted from guards.yml, including installation, also exited 0. A stdin mutation of the real guards.yml appending name: Duplicate name exited 1 with key "name" is duplicated in "workflow" section. A byte comparison confirmed both corrected files equal the main copies with only the pull request branch filter changed, and exactly one concurrency block each.

  • dotnet build Orbit.slnx: passed with 0 errors. Existing dependency and obsolete API warnings remain.
  • dotnet build Orbit.slnx --no-restore: passed with 0 errors before commit.
  • node --test tools/__tests__/check-timeless.test.mjs tools/__tests__/check-suppression-allowlist.test.mjs: 57 passed.
  • Lefthook pre-commit checks, changed-file timeless and dash checks, and git diff --check: passed.
  • dotnet test: 8,637 passed, 0 failed, 0 skipped across Domain (661), Application (4,958), Infrastructure (2,986), and Analyzers (32).

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes across all three workflow files, including the installer contract and whether the new guard detects the original defect.

  • Workflow repairs: Removed the duplicate concurrency blocks from Dependency Review and SonarCloud while preserving their triggers, permissions, jobs, and remaining concurrency settings.
  • Syntax guard: Added the Workflow Syntax job with pinned actionlint 1.7.12 and a narrowly anchored exemption for GitHub's supported queue key.

Validation: the exact full-workflow scan passed locally, and injected duplicate concurrency blocks were rejected in both repaired workflows and guards.yml. The new Workflow Syntax check also passed in CI. The .NET suite was not rerun locally for this workflow-only change.

Pullfrog  | View workflow run | Using gpt-6.1-sol | 𝕏

SonarCloud rule githubactions:S6506 flagged the curl download in the workflow
syntax guard because a redirect could reach plain HTTP. Restrict the protocol
to HTTPS and TLS 1.2 or newer.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes since the previous review at 8bbbc732, with the full PR diff checked for context.

  • Hardened installer transport: Added --proto '=https' --tlsv1.2 to the actionlint installer-script download, requiring HTTPS with TLS 1.2 or newer without changing the pinned version or workflow scan.

Validation: the updated download succeeded, actionlint 1.7.12 installed successfully, and the exact full-workflow scan passed locally. The same curl flags rejected an HTTP URL, and Workflow Syntax passed in CI at 2ed1e1dd. The .NET suite was not rerun locally for this workflow-only change.

Pullfrog  | View workflow run | Using gpt-6.1-sol | 𝕏

@sonarqubecloud

sonarqubecloud Bot commented Oct 3, 2026

Copy link
Copy Markdown

@thomasluizon
thomasluizon merged commit a306721 into redesign/main Oct 3, 2026
26 checks passed
@thomasluizon
thomasluizon deleted the fix/ticket-1180-workflow-duplicate-keys branch October 3, 2026 19:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant