GitNexus/.github/workflows
Gergo Magyar 1688ef2ab3 fix(review): address all residual ce-code-review findings
Five reviewers (maintainability, reliability, testing, agent-native,
adversarial) flagged that ci-report.yml's sticky PR comment ignores
scope-parity entirely. Add scope_parity_result to the artifact read
step, render it in the Pipeline Status table, and include it in the
OVERALL pass/fail condition. Skipped is now visualised distinctly from
cancelled (skipped → ⏭, cancelled → 🛑).

Add `.github/scripts/check-language-filters.py` and wire it into
ci-quality.yml's workflow-convention job. The script parses
MIGRATED_LANGUAGES from registry-primary-flag.ts and asserts:

  1. ci.yml has a per-language filter block for every migrated slug
  2. ci.yml's FULL_LANG_LIST env var matches
  3. ci-scope-parity.yml's changed-languages default matches

This catches the most common drift mode: adding a language to
MIGRATED_LANGUAGES without updating the two YAML hardcoded lists,
which would silently make scope-parity skip the new language. Negative-
tested with a synthetic flag.ts that adds Kotlin without updating the
filter blocks — script correctly fails with all three location-
specific errors.

Move the resolver test-file existence check from the parity matrix
job into the discover job, iterating the full MIGRATED_LANGUAGES set
rather than just the filtered matrix. A missing test file now fails
the gate even on docs-only PRs that prune the matrix to empty,
holding the invariant regardless of which slugs were filtered.

Dismissed (verified out-of-scope): the performance reviewer's
suggestion to replace setup-gitnexus with a lighter setup in the
discover job. gitnexus-shared/package.json exports only ./dist/, so
`tsx` cannot resolve `import 'gitnexus-shared'` without the build
step. The optimisation would require modifying gitnexus-shared's
exports field to expose ./src/, which is a separate refactor.
2026-05-14 17:34:52 +01:00
..
ci-e2e.yml ci: cascade quality gate, centralize change detection, prune scope-parity matrix 2026-05-14 17:27:16 +01:00
ci-quality.yml fix(review): address all residual ce-code-review findings 2026-05-14 17:34:52 +01:00
ci-report.yml fix(review): address all residual ce-code-review findings 2026-05-14 17:34:52 +01:00
ci-scope-parity.yml fix(review): address all residual ce-code-review findings 2026-05-14 17:34:52 +01:00
ci-tests.yml fix(security): Harden CI permissions (#1454) 2026-05-09 17:58:22 +01:00
ci.yml ci: cascade quality gate, centralize change detection, prune scope-parity matrix 2026-05-14 17:27:16 +01:00
claude.yml ci(claude): allow Bash in code-review job without interactive approval 2026-05-12 09:07:47 +01:00
codeql.yml fix(security): Harden CI permissions (#1454) 2026-05-09 17:58:22 +01:00
dependency-review.yml fix(security): Harden CI permissions (#1454) 2026-05-09 17:58:22 +01:00
docker.yml chore(deps): bump sigstore/cosign-installer from 4.1.1 to 4.1.2 (#1557) 2026-05-14 06:45:14 +01:00
gitleaks.yml fix(security): Harden CI permissions (#1454) 2026-05-09 17:58:22 +01:00
pr-autofix-apply.yml chore(deps): bump actions/checkout from 5.0.0 to 6.0.2 (#1459) 2026-05-09 19:26:53 +01:00
pr-autofix-publish.yml feat(autofix): replace inline reviewdog with /autofix ChatOps button (#1458) 2026-05-09 16:32:38 +01:00
pr-autofix.yml fix(security): Pin Docker Node base images, remove runtime package-manager CVE surface, verify Trivy on PRs, and harden Dependabot policy (#1455) 2026-05-09 16:55:31 +01:00
pr-description-check.yml chore(deps): bump actions/github-script from 7.0.1 to 9.0.0 2026-04-15 20:17:08 +00:00
pr-labeler.yml fix(security): Harden CI permissions (#1454) 2026-05-09 17:58:22 +01:00
publish.yml fix(security): Harden CI permissions (#1454) 2026-05-09 17:58:22 +01:00
release-candidate.yml ci(release): skip rc build on release PRs (#1474) 2026-05-10 09:50:58 +01:00
scorecard.yml chore(deps): bump github/codeql-action from 3.35.3 to 4.35.3 (#1390) 2026-05-07 09:54:17 +01:00
tree-sitter-upgrade-readiness.yml chore(deps): tree-sitter 0.25 upgrade readiness monitor with daily Dependabot (#847) 2026-04-16 09:17:21 +01:00
triage-sweep.yml chore(deps): bump actions/cache from 5.0.4 to 5.0.5 (#840) 2026-04-15 13:36:38 +01:00
trivy.yml fix(security): Harden CI permissions (#1454) 2026-05-09 17:58:22 +01:00
workflow-lint.yml fix(security): Harden CI permissions (#1454) 2026-05-09 17:58:22 +01:00