Repository navigation
ci: sync v4 workflows with CLDMV/.github v4.29.0 templates - #80
Merged
Merged
Conversation
Rebuild every .github/workflows/*.yml and .github/dependabot.yml against the current CLDMV/.github v4.29.0 templates (repo header + template body), and add the standard workflows this repo was missing: dependabot-recreate.yml, member-auto-merge.yml, pr-notify.yml, provenance.yml, release-merge.yml. Notable template-side changes picked up: - Per-job `permissions:` blocks replacing workflow-level grants across branch-retention, ci, cla, codeql, dependabot-auto-merge, feature-pr, hotfixes-release, hotfix-redirector, next-release, next-reset, pr-title-normalizer, publish, scorecard, tag-health, update-major-version-tags. - ci.yml / publish.yml: `max_node_major` now defaults to blank (inherit the reusable's default) instead of a hardcoded "26" pin; LTS-only matrix comment updated to include Node 20. - ci.yml: new lint/format autofix inputs (format_command, lint_fix_command, lint_command, format_check_command). - ci.yml / hotfixes-release.yml / next-release.yml: build_command switched from a hardcoded `echo` to `npm run build:ci` (the repo's build:ci script is itself that same no-op echo, so behavior is unchanged). - master-commit-audit.yml: now a thin caller into reusable-master-commit-audit.yml@v4 instead of inlining the create-app-token + audit-commit-subject steps. - codeql.yml / dependency-review.yml: added the private-repo CLDMV_SKIP_CODE_SCANNING / CLDMV_SKIP_DEPENDENCY_REVIEW documentation. - v4-bootstrap.yml: added the `variables` bootstrap phase + `code_scanning_config` input. - feature-pr.yml: added `deps/**` to the auto-PR branch-prefix set. Repo-specific customizations re-applied on top of the synced templates: - ci.yml: skip_type_check: true (git-embedded's dynamic slothlet-composed API has no meaningful static type surface), with its explanatory comment. - dependabot-auto-merge.yml: merge_method: "squash" (repo's deliberate choice, kept even though next/hotfixes rulesets currently narrow it to merge anyway). - dependabot.yml: the marked >=16 ignore rule for the npm ecosystem (marked-terminal@7.3.0 caps marked at <16; no newer marked-terminal release lifts it). release-merge.yml's workflows: list already matches this repo's ci.yml name (🧪 CI Tests & Build). provenance.yml's package_name is set to @cldmv/git-embedded; extra_packages left empty (no satellite packages).
- fix @project / @filename in workflow headers that still named the CLDMV/.github template (@cldmv/.github, /examples/...) instead of this repository - dependabot-auto-merge: drop the explicit merge_method "squash". The next and hotfixes rulesets allow merge commits only (CLDMV/.github data/rulesets), so squash was stale; the template's default merge method applies.
Shinrai
approved these changes
Sep 28, 2026
cldmv-bot Bot
added a commit
that referenced
this pull request
Oct 2, 2026
…ates ## 🚀 What's Changed ### 💥 Breaking Changes _No breaking changes_ ### ✨ Features _No new features_ ### 🐛 Bug Fixes _No bug fixes_ ### 📦 Dependencies - #82 - deps: bump the patch group across 1 directory with 7 updates (b3d203b) - #76 - deps: bump @cldmv/slothlet from 3.15.3 to 3.17.0 in the minor group (bcdb2be) - #74 - deps: bump prettier from 3.9.6 to 3.9.8 in the prettier group (ebed26f) - #73 - deps: bump eslint from 10.10.0 to 10.11.0 in the eslint group (f0e872d) - #72 - deps: bump vitest from 5.0.0 to 5.0.1 in the vitest group (3783824) ### 🔧 Other Changes - #84 - ci: stop the skipped PR-run mirror from satisfying Required PR Check (7966b20) - #83 - chore: adopt the shared CLDMV fix-headers config and stamp uniform file headers (2339b59) - #80 - ci: add the bundle-size workflow and keep the template release-merge list (78c0072) - ci: bring the v4 workflow sync up to CLDMV/.github v4.29.2 (1f88fa4) - ci: correct workflow header metadata and finish the v4 sync (6ac136f) - ci: sync v4 workflows with CLDMV/.github v4.29.0 templates (54ba059) - #79 - chore: restore the verbatim Apache-2.0 license text (ad1379c) <details> <summary>👥 Contributors</summary> - @Shinrai </details> --- <!-- coverage-start -->  | Metric | Coverage | |--------|----------| | Statements | 100.0% | | Branches | 100.0% | | Functions | 100.0% | | Lines | 100.0% | *Avg: **100.0%** · `cf33241` · Node lts/** <!-- coverage-end --> <!-- co-authors --> Co-authored-by: Shinrai <Shinrai@users.noreply.github.com>
cldmv-bot Bot
added a commit
that referenced
this pull request
Oct 3, 2026
…ates ## 🚀 What's Changed ### 💥 Breaking Changes _No breaking changes_ ### ✨ Features _No new features_ ### 🐛 Bug Fixes _No bug fixes_ ### 📦 Dependencies - #86 - deps: bump the minor group with 3 updates (9f22e03) - #85 - deps: bump the patch group with 2 updates (b1fcf1f) - #82 - deps: bump the patch group across 1 directory with 7 updates (b3d203b) - #76 - deps: bump @cldmv/slothlet from 3.15.3 to 3.17.0 in the minor group (bcdb2be) - #74 - deps: bump prettier from 3.9.6 to 3.9.8 in the prettier group (ebed26f) - #73 - deps: bump eslint from 10.10.0 to 10.11.0 in the eslint group (f0e872d) - #72 - deps: bump vitest from 5.0.0 to 5.0.1 in the vitest group (3783824) ### 🔧 Other Changes - #88 - ci: run the in-repo PR mirror job instead of skipping it (4e917a6) - #84 - ci: stop the skipped PR-run mirror from satisfying Required PR Check (7966b20) - #83 - chore: adopt the shared CLDMV fix-headers config and stamp uniform file headers (2339b59) - #80 - ci: add the bundle-size workflow and keep the template release-merge list (78c0072) - ci: bring the v4 workflow sync up to CLDMV/.github v4.29.2 (1f88fa4) - ci: correct workflow header metadata and finish the v4 sync (6ac136f) - ci: sync v4 workflows with CLDMV/.github v4.29.0 templates (54ba059) - #79 - chore: restore the verbatim Apache-2.0 license text (ad1379c) <details> <summary>👥 Contributors</summary> - @Shinrai </details> --- <!-- coverage-start -->  | Metric | Coverage | |--------|----------| | Statements | 100.0% | | Branches | 100.0% | | Functions | 100.0% | | Lines | 100.0% | *Avg: **100.0%** · `6073ee6` · Node lts/** <!-- coverage-end --> <!-- co-authors --> Co-authored-by: Shinrai <Shinrai@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🚀 What's Changed
💥 Breaking Changes
No breaking changes
✨ Features
No new features
🐛 Bug Fixes
No bug fixes
📦 Dependencies
No dependency updates
🔧 Other Changes
👥 Contributors