Skip to content

ci: sync v4 workflows with CLDMV/.github v4.29.0 templates - #80

Merged
Shinrai merged 4 commits into
nextfrom
ci/sync-v4-workflows
Sep 28, 2026
Merged

Shinrai merged 4 commits into
nextfrom
ci/sync-v4-workflows

Conversation

@cldmv-bot

@cldmv-bot cldmv-bot Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

🚀 What's Changed

💥 Breaking Changes

No breaking changes

✨ Features

No new features

🐛 Bug Fixes

No bug fixes

📦 Dependencies

No dependency updates

🔧 Other Changes

👥 Contributors

Rebuild every .github/workflows/*.yml and .github/dependabot.yml against
the current CLDMV/.github v4.29.0 templates (repo header + template body),
and add the standard workflows this repo was missing:
dependabot-recreate.yml, member-auto-merge.yml, pr-notify.yml,
provenance.yml, release-merge.yml.

Notable template-side changes picked up:
- Per-job `permissions:` blocks replacing workflow-level grants across
  branch-retention, ci, cla, codeql, dependabot-auto-merge, feature-pr,
  hotfixes-release, hotfix-redirector, next-release, next-reset,
  pr-title-normalizer, publish, scorecard, tag-health,
  update-major-version-tags.
- ci.yml / publish.yml: `max_node_major` now defaults to blank (inherit
  the reusable's default) instead of a hardcoded "26" pin; LTS-only matrix
  comment updated to include Node 20.
- ci.yml: new lint/format autofix inputs (format_command, lint_fix_command,
  lint_command, format_check_command).
- ci.yml / hotfixes-release.yml / next-release.yml: build_command switched
  from a hardcoded `echo` to `npm run build:ci` (the repo's build:ci script
  is itself that same no-op echo, so behavior is unchanged).
- master-commit-audit.yml: now a thin caller into
  reusable-master-commit-audit.yml@v4 instead of inlining the
  create-app-token + audit-commit-subject steps.
- codeql.yml / dependency-review.yml: added the private-repo
  CLDMV_SKIP_CODE_SCANNING / CLDMV_SKIP_DEPENDENCY_REVIEW documentation.
- v4-bootstrap.yml: added the `variables` bootstrap phase +
  `code_scanning_config` input.
- feature-pr.yml: added `deps/**` to the auto-PR branch-prefix set.

Repo-specific customizations re-applied on top of the synced templates:
- ci.yml: skip_type_check: true (git-embedded's dynamic slothlet-composed
  API has no meaningful static type surface), with its explanatory comment.
- dependabot-auto-merge.yml: merge_method: "squash" (repo's deliberate
  choice, kept even though next/hotfixes rulesets currently narrow it to
  merge anyway).
- dependabot.yml: the marked >=16 ignore rule for the npm ecosystem
  (marked-terminal@7.3.0 caps marked at <16; no newer marked-terminal
  release lifts it).

release-merge.yml's workflows: list already matches this repo's ci.yml
name (🧪 CI Tests & Build). provenance.yml's package_name is set to
@cldmv/git-embedded; extra_packages left empty (no satellite packages).
@cldmv-bot cldmv-bot Bot added ! ci → next v4 flow: ci contributor PR targeting the next integration branch type: ci Changes to CI workflows, actions, or build pipelines type: config Changes to repository or project configuration files labels Sep 27, 2026
- fix @project / @filename in workflow headers that still named the
  CLDMV/.github template (@cldmv/.github, /examples/...) instead of this
  repository
- dependabot-auto-merge: drop the explicit merge_method "squash". The
  next and hotfixes rulesets allow merge commits only
  (CLDMV/.github data/rulesets), so squash was stale; the template's
  default merge method applies.
@Shinrai
Shinrai merged commit ea22cda into next Sep 28, 2026
26 checks passed
@cldmv-bot
cldmv-bot Bot deleted the ci/sync-v4-workflows branch September 28, 2026 07:14
cldmv-bot Bot added a commit that referenced this pull request Oct 2, 2026
…ates

## 🚀 What's Changed

### 💥 Breaking Changes
_No breaking changes_

### ✨ Features
_No new features_

### 🐛 Bug Fixes
_No bug fixes_

### 📦 Dependencies
- #82
  - deps: bump the patch group across 1 directory with 7 updates (b3d203b)

- #76
  - deps: bump @cldmv/slothlet from 3.15.3 to 3.17.0 in the minor group (bcdb2be)

- #74
  - deps: bump prettier from 3.9.6 to 3.9.8 in the prettier group (ebed26f)

- #73
  - deps: bump eslint from 10.10.0 to 10.11.0 in the eslint group (f0e872d)

- #72
  - deps: bump vitest from 5.0.0 to 5.0.1 in the vitest group (3783824)

### 🔧 Other Changes
- #84
  - ci: stop the skipped PR-run mirror from satisfying Required PR Check (7966b20)

- #83
  - chore: adopt the shared CLDMV fix-headers config and stamp uniform file headers (2339b59)

- #80
  - ci: add the bundle-size workflow and keep the template release-merge list (78c0072)
  - ci: bring the v4 workflow sync up to CLDMV/.github v4.29.2 (1f88fa4)
  - ci: correct workflow header metadata and finish the v4 sync (6ac136f)
  - ci: sync v4 workflows with CLDMV/.github v4.29.0 templates (54ba059)

- #79
  - chore: restore the verbatim Apache-2.0 license text (ad1379c)



<details>
<summary>👥 Contributors</summary>

- @Shinrai

</details>

---

<!-- coverage-start -->

![coverage](https://img.shields.io/badge/coverage-100.0%25-brightgreen?style=for-the-badge&logo=vitest&logoColor=white)

| Metric | Coverage |
|--------|----------|
| Statements | 100.0% |
| Branches   | 100.0% |
| Functions  | 100.0% |
| Lines      | 100.0% |

*Avg: **100.0%** · `cf33241` · Node lts/**

<!-- coverage-end -->

<!-- co-authors -->

Co-authored-by: Shinrai <Shinrai@users.noreply.github.com>
cldmv-bot Bot added a commit that referenced this pull request Oct 3, 2026
…ates

## 🚀 What's Changed

### 💥 Breaking Changes
_No breaking changes_

### ✨ Features
_No new features_

### 🐛 Bug Fixes
_No bug fixes_

### 📦 Dependencies
- #86
  - deps: bump the minor group with 3 updates (9f22e03)

- #85
  - deps: bump the patch group with 2 updates (b1fcf1f)

- #82
  - deps: bump the patch group across 1 directory with 7 updates (b3d203b)

- #76
  - deps: bump @cldmv/slothlet from 3.15.3 to 3.17.0 in the minor group (bcdb2be)

- #74
  - deps: bump prettier from 3.9.6 to 3.9.8 in the prettier group (ebed26f)

- #73
  - deps: bump eslint from 10.10.0 to 10.11.0 in the eslint group (f0e872d)

- #72
  - deps: bump vitest from 5.0.0 to 5.0.1 in the vitest group (3783824)

### 🔧 Other Changes
- #88
  - ci: run the in-repo PR mirror job instead of skipping it (4e917a6)

- #84
  - ci: stop the skipped PR-run mirror from satisfying Required PR Check (7966b20)

- #83
  - chore: adopt the shared CLDMV fix-headers config and stamp uniform file headers (2339b59)

- #80
  - ci: add the bundle-size workflow and keep the template release-merge list (78c0072)
  - ci: bring the v4 workflow sync up to CLDMV/.github v4.29.2 (1f88fa4)
  - ci: correct workflow header metadata and finish the v4 sync (6ac136f)
  - ci: sync v4 workflows with CLDMV/.github v4.29.0 templates (54ba059)

- #79
  - chore: restore the verbatim Apache-2.0 license text (ad1379c)



<details>
<summary>👥 Contributors</summary>

- @Shinrai

</details>

---

<!-- coverage-start -->

![coverage](https://img.shields.io/badge/coverage-100.0%25-brightgreen?style=for-the-badge&logo=vitest&logoColor=white)

| Metric | Coverage |
|--------|----------|
| Statements | 100.0% |
| Branches   | 100.0% |
| Functions  | 100.0% |
| Lines      | 100.0% |

*Avg: **100.0%** · `6073ee6` · Node lts/**

<!-- coverage-end -->

<!-- co-authors -->

Co-authored-by: Shinrai <Shinrai@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

! ci → next v4 flow: ci contributor PR targeting the next integration branch type: ci Changes to CI workflows, actions, or build pipelines type: config Changes to repository or project configuration files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant