Repository navigation
Compliance: non-stub-feature-ideation.yml #329
Description
Activity
- addedcompliance-auditAutomated compliance audit findingAutomated compliance audit finding
on May 26, 2026 Dev-Lead Implementation Plan
Issue: #329 — Compliance: non-stub-feature-ideation.yml
Scope
Change
.github/workflows/feature-ideation.ymlso theuses:line references the reusable workflow pinned to@v1(the org-standard tag) instead of the SHA hash@ee22b427cbce9ecadcf2b436acb57c3adf0cb63d # v1.Root Cause
The org compliance check (
check_centralized_workflow_stubsinscripts/compliance-audit.sh) expects an exact match for:uses: petry-projects/.github/.github/workflows/feature-ideation-reusable.yml@v1The current file uses a SHA hash instead of the
v1tag, so the regex does not match and the finding is raised. Thev1tag exists inpetry-projects/.githuband resolves to the same commit as the SHA.Implementation Checklist
-
.github/workflows/feature-ideation.yml— changeuses:from SHA-pinned@ee22b427cbce9ecadcf2b436acb57c3adf0cb63d # v1to tag-pinned@v1
Tests to Write
None — this is a pure CI configuration change with no observable behavioral change. TDD phase is skipped per the exception rule in AGENTS.md.
Test Command
npm test(no JS logic changed; this is a workflow YAML-only fix)-
Dev-Lead: Implementation Complete
Plan Execution
-
.github/workflows/feature-ideation.yml— changeduses:from SHA-pinned@ee22b427cbce9ecadcf2b436acb57c3adf0cb63d # v1to tag-pinned@v1 - TDD exception noted: pure CI configuration change, no observable behavioral difference
- Full test suite passed (301 tests)
- Prettier check passed on changed file
Test Results
Test Suites: 12 passed, 12 total Tests: 301 passed, 301 total Snapshots: 0 total Time: 4.56 s Ran all test suites.Files Changed
.github/workflows/feature-ideation.yml: Changeduses:pin from@ee22b427cbce9ecadcf2b436acb57c3adf0cb63d # v1to@v1on line 91. Thev1tag exists inpetry-projects/.githuband resolves to the same commit as the SHA, so behaviour is unchanged.
Notes
- The compliance check (
check_centralized_workflow_stubsinscripts/compliance-audit.sh) regex-matches for the literal tag@v1; the SHA hash form did not satisfy the pattern even though both reference the same commit. ci-failure-analyst.ymlhas a pre-existing prettier warning unrelated to this change — not introduced by this PR.
-
Weekly Compliance Audit (2026-05-29)
This finding is still open.
Detail: Centralized workflow
feature-ideation.ymlreferences the reusable but is not pinned to@v1(org standard). Replace with the canonical stub fromstandards/workflows/feature-ideation.ymlwhich delegates topetry-projects/.github/.github/workflows/feature-ideation-reusable.yml@v1.- Already working on this: an open PR exists for issue #329.
Weekly Compliance Audit (2026-05-30)
This finding is still open.
Detail: Centralized workflow
feature-ideation.ymlreferences the reusable but is not pinned to@v1(org standard). Replace with the canonical stub fromstandards/workflows/feature-ideation.ymlwhich delegates topetry-projects/.github/.github/workflows/feature-ideation-reusable.yml@v1.@don-petry-dev-lead
- addeddev-leadFor dev-lead agent pickupFor dev-lead agent pickupand removeddev-leadFor dev-lead agent pickupFor dev-lead agent pickup
on Jun 3, 2026 Dev-Lead Implementation Plan
Issue: #329 — Compliance: non-stub-feature-ideation.yml
Scope
Replace the commit-hash ref (
@ee22b427cbce9ecadcf2b436acb57c3adf0cb63d) in.github/workflows/feature-ideation.ymlwith the org-standard@v1tag on theuses:line.Implementation Checklist
-
.github/workflows/feature-ideation.yml: Changeuses:ref from commit hash to@v1
Tests to Write
- N/A — this is a pure CI configuration change with no behavioral impact on the repo's test suite. TDD phase is skipped per the exception clause for behavior-preserving configuration fixes.
Test Command
npm test-
Weekly Compliance Audit (2026-06-05)
This finding is still open.
Detail: Centralized workflow
feature-ideation.ymlreferences the reusable but is not pinned to@v1(org standard). Replace with the canonical stub fromstandards/workflows/feature-ideation.ymlwhich delegates topetry-projects/.github/.github/workflows/feature-ideation-reusable.yml@v1.2 remaining items
- addeddev-leadFor dev-lead agent pickupFor dev-lead agent pickupand removeddev-leadFor dev-lead agent pickupFor dev-lead agent pickup
on Jun 12, 2026 Weekly Compliance Audit (2026-06-19)
This finding is still open.
Detail: Centralized workflow
feature-ideation.ymlreferences the reusable but is not pinned to@v1(org standard). Replace with the canonical stub fromstandards/workflows/feature-ideation.ymlwhich delegates topetry-projects/.github/.github/workflows/feature-ideation-reusable.yml@v1.- addeddev-leadFor dev-lead agent pickupFor dev-lead agent pickupand removeddev-leadFor dev-lead agent pickupFor dev-lead agent pickup
on Jun 19, 2026 Weekly Compliance Audit (2026-06-26)
This finding is still open.
Detail: Centralized workflow
feature-ideation.ymlreferences the reusable but is not pinned to@v1(org standard). Replace with the canonical stub fromstandards/workflows/feature-ideation.ymlwhich delegates topetry-projects/.github/.github/workflows/feature-ideation-reusable.yml@v1.- addeddev-leadFor dev-lead agent pickupFor dev-lead agent pickupand removeddev-leadFor dev-lead agent pickupFor dev-lead agent pickup
on Jun 26, 2026 Dev-Lead Implementation Plan
Issue: #329 — Compliance: non-stub-feature-ideation.yml
Scope
Replace
.github/workflows/feature-ideation.ymlwith the canonical thin-caller stub frompetry-projects/.github/standards/workflows/feature-ideation.yml, bringing the reusable pin and trigger shape into compliance.Implementation Checklist
- Replace
.github/workflows/feature-ideation.ymlwith the canonical stub content, which:- Pins the reusable to
feature-ideation-reusable.yml@897e4dede3518cdd7273b9dc63e607d0d05cbdda # v1(repo currently pins the stale@419c90fc…SHA) - Adds the
discussion: types: [created]trigger - Adds the job-level
if:guard for the discussion event - Adds the
target_discussioninput
- Pins the reusable to
- Preserve the per-repo
project_context(currently the unmodified TODO placeholder, so no customization to carry over)
Tests to Write
- TDD exception: this is a CI-config-only change with no observable behavior testable by the repo's Jest suite (which covers GAS JS logic, not workflow YAML). No workflow-stub tests exist in this repo. Validation is via YAML parse + existing lint/test suite passing.
Test Command
npm test(plusnpm run checkandbash .dev-lead/scripts/dev-lead-lint.sh)- Replace
Dev-Lead: Implementation Complete
Plan Execution
- Replaced
.github/workflows/feature-ideation.ymlwith the canonical thin-caller stub frompetry-projects/.github/standards/workflows/feature-ideation.yml(fetched authoritatively viagh api) - Updated the reusable pin from the stale
@419c90fc…SHA to@897e4dede3518cdd7273b9dc63e607d0d05cbdda # v1 - Added the
discussion: types: [created]trigger, the job-levelif:guard, and thetarget_discussioninput that the canonical stub now carries - Preserved the per-repo
project_context(was — and remains — the unmodified TODO placeholder, so no customization lost) - TDD exception applied: CI-config-only change, no behavior testable by the repo's Jest suite (which covers GAS JS logic, not workflow YAML); no workflow-stub tests exist in this repo
Test Results
=== YAML parse === YAML OK === dev-lead-lint === [lint] shellcheck on 4 file(s)... [lint] validating CODEOWNERS... OK: CODEOWNERS [lint] all checks passed === prettier --check .github/workflows/feature-ideation.yml === All matched files use Prettier code style! === npm run check === (exit 0 — 22 pre-existing warnings, 0 errors, all in unrelated gmail-to-drive-by-labels tests) === npm test === Test Suites: 12 passed, 12 total Tests: 301 passed, 301 total Snapshots: 0 total Time: 4.837 sFiles Changed
.github/workflows/feature-ideation.yml: replaced with the canonical org stub — corrects the reusable pin to the# v1SHA and adds the discussion trigger /if:guard /target_discussioninput
Notes
The issue text described the target as
@v1; the authoritative canonical stub in the central repo pins to the v1-tagged commit SHA897e4dede3518cdd7273b9dc63e607d0d05cbdda # v1(org SHA-pinning convention). This repo's file now matches the canonical stub exactly. No follow-up issues needed.- Replaced
- added a commit that references this issue
on Jun 26, 2026 - added a commit that references this issue
on Aug 4, 2026
Compliance Finding
Category:
ci-workflowsSeverity:
errorCheck:
non-stub-feature-ideation.ymlDetail
Centralized workflow
feature-ideation.ymlreferences the reusable but is not pinned to@v1(org standard). Replace with the canonical stub fromstandards/workflows/feature-ideation.ymlwhich delegates topetry-projects/.github/.github/workflows/feature-ideation-reusable.yml@v1.Standard Reference
standards/ci-standards.md#centralization-tiers
Remediation
Please review the linked standard and bring this repository into compliance.
See the full standards documentation for implementation guidance.
This issue was automatically created by the weekly compliance audit.