mirror of
https://github.com/NanmiCoder/claude-code-haha.git
synced 2026-10-10 11:53:10 +08:00
20b6e6dc9e
4f9fec876 added this workflow with `cron: '0 18 * * *'`. That was the wrong call
to make unilaterally: the repository had no scheduled workflow at all before it,
so this was not one more cron among several but the introduction of recurring CI
spend — about ninety minutes per run — on a schedule nobody asked for.
The reasoning for the sweep still holds: a per-PR gate only covers what the diff
reaches, so it is blind to checks no recent PR selected and to failures that only
appear when the whole suite runs together. Keeping the workflow on
`workflow_dispatch` keeps that one click away without deciding for the maintainer
when to spend the time.
pr-quality-workflow.test.ts now asserts the absence of `schedule:` and `cron:`
rather than their presence, so a schedule cannot drift back in unnoticed —
verified by adding the cron back and watching the test go red. The docs' four-tier
table renames the tier accordingly; calling it "Nightly" when nothing runs nightly
is exactly the kind of comment that outlives its code.
1.9 KiB
1.9 KiB
CI and Repository Policy
These rules apply to .github/ changes in addition to the root instructions.
- Treat workflow changes as product changes. Run
bun run check:policy; runactionlintwhen available. scripts/pr/change-policy.tsis the source of truth for path-to-check routing. Do not duplicate the routing graph in advisory automation.- Routing is path prefixes plus the import graph from
scripts/pr/module-graph.ts. Prefixes decide areas and every blocking rule; the graph only widens which surface checks run. When the graph cannot be built the run selects every surface rather than silently falling back to prefixes. nightly-quality.ymlruns every deterministic lane unconditionally and re-proves the module graph. It exists because per-PR selection can only ever cover what a diff reaches; do not move its jobs into the required PR gate. It isworkflow_dispatchonly — when to spend ~90 minutes of CI is the maintainer's call, andpr-quality-workflow.test.tsfails if aschedule:is added back.- Keep
pr-quality-gateas the stable required status. Selected jobs must succeed and unselected jobs must be explicitly skipped; never convert failures into success. - Required PR jobs must remain offline and must not receive provider credentials or depend on paid/live services.
- A
pull_request_targetworkflow may inspect PR metadata using trusted base code, but must never execute the PR head, install PR-controlled dependencies, or expose secrets to contributor code. - Keep Bun aligned with
package.json#packageManagerand use frozen lockfile installs in required jobs. - Do not weaken coverage, test routing, CODEOWNERS, or branch protections to make another change pass. Maintainer override labels require an explicit, documented decision.
- Repository settings, rulesets, secrets, and required-check changes require explicit user authorization; editing workflow files alone does not grant it.