Skip to content

fix(workflow-audit): find the previous successful run without the stale status filter - #920

Merged
nedtwigg merged 1 commit into
mainfrom
fix/workflow-audit-since-37017894064
Oct 2, 2026
Merged

nedtwigg merged 1 commit into
mainfrom
fix/workflow-audit-since-37017894064

Conversation

@dormouse-bot

Copy link
Copy Markdown
Collaborator

workflow-audit has opened three issues (#811 on 09-28, #880 on 10-01, #915 today) that each re-list 23–24 commits earlier audits had already covered. All three report the same lower bound, 2026-09-03T12:03:48Z. The bound comes from runs?status=success&per_page=1, and that filtered listing is stale: right now it reports total_count: 31 with 2026-09-03 as the newest success. The unfiltered listing for the same workflow has a success every day through today (2026-10-02T13:48:12Z).

This PR selects the newest conclusion == "success" run from the unfiltered listing, which is newest first, so the --since bound becomes the previous successful run's server-set created_at again. That is the contract docs/specs/security-ci.md → "Automated Maintainer (tend)" audits ("must stay the previous successful run's server-set created_at"). The in-progress run has no conclusion yet, so it can't select itself. If no success exists, the empty-string fallback to 25 hours still applies.

Verification: I ran the new snippet under set -euo pipefail against this repo, and it returned 2026-10-02T13:48:12Z. The empty-input case yields an empty SINCE, and the YAML parses. The first scheduled run after merge should report a bound of about one day.

Refs #915. Once this merges, the 24 commits #915 lists still need accounting for, or the issue can be closed as a stale-bound duplicate of #880.

…us filter

The runs listing filtered by status=success returned 2026-09-03 as the newest
success on three nights while the unfiltered listing showed daily successes, so
#811, #880, and #915 each re-listed about 24 commits earlier audits had already
covered. Select the newest success from the unfiltered listing instead; the
bound is still that run's server-set created_at.
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying mouseterm with  Cloudflare Pages  Cloudflare Pages

Latest commit: c66fa14
Status: ✅  Deploy successful!
Preview URL: https://821d7836.mouseterm.pages.dev
Branch Preview URL: https://fix-workflow-audit-since-370.mouseterm.pages.dev

View logs

@nedtwigg
nedtwigg merged commit fe624ac into main Oct 2, 2026
11 checks passed
@nedtwigg
nedtwigg deleted the fix/workflow-audit-since-37017894064 branch October 2, 2026 15:37

This branch is waiting to be deployed

1 waiting deployment
hosted-preview — c66fa146 Waiting Oct 2, 2026 by nedtwigg via cleanup #770
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants