Skip to content

Adopt the Hub Reusable Workflows and Retire repo-config - #129

Merged
ptr727 merged 9 commits into
developfrom
resync/reusable-workflows
Sep 26, 2026
Merged

ptr727 merged 9 commits into
developfrom
resync/reusable-workflows

Conversation

@ptr727

@ptr727 ptr727 commented Sep 26, 2026

Copy link
Copy Markdown
Owner

Replaces this repository's carried workflow task bodies with thin callers of the hub's reusable workflows, and retires repo-config/. This is the third PR of the hub resync (audit run 2026-09-26T02:19:51Z, hub 45669468).

What changes

  • test-pull-request.yml calls the hub's validate-task.yml for the lint gate and build-release-task.yml with smoke: true for the amd64 smoke build. The trigger shape is unchanged: push to every branch, no paths filter, branch deletions skipped. The aggregator keeps its ruleset-bound name, Check pull request workflow status job.
  • publish-release.yml has the plan, validate, and publish jobs the release interface requires, plus publish-docker-readme. The triggers are unchanged: a weekly main schedule and manual dispatch, so merges still do not publish. publish-plan-task.yml decides the gate, and the hub validate gate runs on the branch tip before the build.
  • merge-bot-pull-request.yml is the hub catalog stub, which calls merge-bot-task.yml. Dependabot auto-merge on every tier and disabling auto-merge on a maintainer push both carry over.
  • Every hub reference is pinned to 45669468 # 2.0.685, the current hub release, and Dependabot bumps it.
  • Deleted, per the retire dispositions in the hub's spec/divergences.json: build-docker-task.yml, build-release-task.yml, get-version-task.yml, publish-docker-readme-task.yml, and validate-task.yml. Also deleted: repo-config/, whose settings.json, configure.sh, and README.md are hub-owned. ruleset-develop.json and ruleset-main.json are pre-rename copies of the hub's rulesets, and the live rulesets are applied from the hub.
  • GOVERNANCE.md "Repository Layout" and OPERATIONS.md describe the thin callers, and drop the repo-config/ entry.

Behavior

  • The image, its tags, the platforms (multi-arch on main, amd64 on develop and smoke), and the LABEL_VERSION build argument are all unchanged. The hub Docker core has the same shape as the deleted copy.
  • A release now runs the full hub validate gate before building. The Docker Hub overview still comes from Docker/README.md, and only a main publish pushes it.
  • The Docker Hub short description is the GitHub About text, so it changes to match on the next main publish.

Verified

actionlint, markdownlint, editorconfig-checker, and the hub repo gate (eol, eol-coverage, sha-pin) are clean. This PR's CI runs the new stubs.

🤖 Generated with Claude Code

ptr727 and others added 8 commits September 25, 2026 19:25
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rkflows

# Conflicts:
#	GOVERNANCE.md
#	OPERATIONS.md
#	repo-config/README.md
#	repo-config/ruleset-develop.json
#	repo-config/ruleset-main.json
#	repo-config/settings.json
Copilot AI lite review requested due to automatic review settings September 26, 2026 03:11
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 15 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 137e35e3-7919-465e-9828-abf5525fe01f

📥 Commits

Reviewing files that changed from the base of the PR and between a62f082 and 34a90e6.

📒 Files selected for processing (17)
  • .github/workflows/build-docker-task.yml
  • .github/workflows/build-release-task.yml
  • .github/workflows/get-version-task.yml
  • .github/workflows/merge-bot-pull-request.yml
  • .github/workflows/publish-docker-readme-task.yml
  • .github/workflows/publish-release.yml
  • .github/workflows/test-pull-request.yml
  • .github/workflows/validate-task.yml
  • AGENTS.md
  • Docker/Dockerfile
  • GOVERNANCE.md
  • OPERATIONS.md
  • repo-config/README.md
  • repo-config/configure.sh
  • repo-config/ruleset-develop.json
  • repo-config/ruleset-main.json
  • repo-config/settings.json

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The workflow callers and documentation updates are consistent with the pinned hub reusable workflow interfaces, and no functional or contract regressions were found in the changed files.

Review effort: Lite
Findings: None

What changed in this PR

This PR converts this repository’s GitHub Actions workflows into thin callers of the hub (ptr727/ProjectTemplate) reusable workflows, and removes the now-redundant, hub-owned repo-config/ and locally-carried workflow task bodies. This aligns the repo with the fleet model where logic lives in the hub and downstream repos pin to a hub commit.

Changes:

  • Replaced locally-implemented CI/release/merge-bot task workflows with pinned calls to hub reusable workflows.
  • Added a release “plan → validate → publish (+ publish Docker README)” structure to match the hub release interface and gate behavior.
  • Deleted repo-config/ and the local reusable workflow task bodies that are now provided by the hub.
File Description
repo-config/​settings.json Deleted (repo settings now hub-applied).
repo-config/​ruleset-main.json Deleted (rulesets now hub-applied).
repo-config/​ruleset-develop.json Deleted (rulesets now hub-applied).
repo-config/​README.md Deleted (repo-config retired in favor of hub ownership).
repo-config/​configure.sh Deleted (hub owns configuration tooling).
OPERATIONS.md Updated operational docs to describe hub-pinned thin workflow callers.
GOVERNANCE.md Updated repository layout to reflect hub workflow/task ownership and retired repo-config.
.github/​workflows/​validate-task.yml Deleted (validation now called from hub reusable workflow).
.github/​workflows/​test-pull-request.yml Updated to call hub validate-task.yml and build-release-task.yml (smoke mode) with explicit permissions/secrets.
.github/​workflows/​publish-release.yml Updated to call hub publish-plan-task.yml, validate-task.yml, build-release-task.yml, and publish-docker-readme-task.yml.
.github/​workflows/​publish-docker-readme-task.yml Deleted (Docker Hub README publishing now called from hub reusable workflow).
.github/​workflows/​merge-bot-pull-request.yml Updated to call hub merge-bot-task.yml with app secrets.
.github/​workflows/​get-version-task.yml Deleted (versioning now handled by hub release chain).
.github/​workflows/​build-release-task.yml Deleted (release chain now handled by hub reusable workflow).
.github/​workflows/​build-docker-task.yml Deleted (docker build now handled by hub reusable workflow).

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

The hub's default Docker prepare step builds ./Docker/Dockerfile, beside Docker/README.md.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 26, 2026 03:18

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The publish workflow can validate a different commit than it releases because validate does not pass the same ${{ github.sha }} ref that publish builds.

Review effort: Lite
Findings: 1 Medium severity

Open (1)

Comment thread .github/workflows/publish-release.yml

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The new Docker/Dockerfile contains internally inconsistent local-build guidance and base-OS/dependency assumptions that could mislead contributors and potentially break builds.

Review effort: Lite
Findings: None

Resolved since last review (1)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants