Conversation
adds image-freshness/decide.py, the pure decision function for the scheduled image freshness check (ANG-3523). it takes a facts json doc (repo visibility, HEAD, registry image, running digests, xray scan, last rebuild dispatch, previous run state) and returns ok / fail / rebuild with the rule number and reason. rules are evaluated in order, first match wins, and anything unknown or malformed fails closed instead of mapping to ok. stdlib only, no I/O beyond reading the facts file and printing, so every rule is unit tested (45 tests in image-freshness/tests). the adapters that actually gather the facts come later. adds a Makefile with `make test` (actionlint over .github/workflows plus the unit tests), so local hooks and CI can't drift, they both call this one target. new .github/workflows/ci.yaml runs it on push to main and on PRs, actions SHA-pinned, read-only token, no persisted credentials. ports the actionlint harness (tests/lint_workflows.sh, tests/actionlint-legacy.txt, tools/actionlint go tool module) from the closed ang-2720-deploy-gate-watchdog branch. legacy workflows that already had findings stay exempted by name, and that list can only shrink from here. also adds a dependabot gomod entry for /tools/actionlint so the actionlint pin gets updated same as the actions already are, and a one-liner in the README: run make test before pushing, CI runs the same target. Claude-Session: https://claude.ai/code/session_01FKzBJ35DrcARUiQCh9iTKM
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I noticed this repo has no CI of its own, nothing lints the reusable workflows or tests the code living inside them.
The fix is
image-freshness/decide.py, the pure decision function for the scheduled freshness check, plus amake testtarget (actionlint and unit tests) that a new CI workflow runs as is. Five workflows with existing actionlint findings are exempted by name, and that list can only shrink.The adapters and reusable workflow that call this function, and fixing those five workflows, are left for later PRs.