Cancel replaced CI runs and drop the checkout token (closes #107)
check / check (push) Canceled after 0s

The canonical `.gitea/workflows/check.yml` gains a `concurrency` block grouped
by workflow and branch with `cancel-in-progress: true`, so a new push cancels
the older run on the same branch and no other, and its checkout step sets
`persist-credentials: false`, so the job's token is not left in `.git/config`;
`script/cibuild` needs none. Both come from `dnswatcher`, where a byte-identical
re-vendor would have removed them. The workflow bullet of
`prompts/REPO_POLICIES.md` and both checklists now describe the file as it is.

Model: opus-5-5
This commit is contained in:
2026-10-06 01:35:43 +00:00
parent b09fff488b
commit 22e6bda2bb
5 changed files with 31 additions and 8 deletions
+6
View File
@@ -21,6 +21,12 @@ fmt-check, and commit.
# Completed Steps
- 2026-10-06: The canonical `.gitea/workflows/check.yml` now has a `concurrency`
block, so a new push cancels the older run on the same branch and no other,
and its checkout step sets `persist-credentials: false`, so the job's token is
not left in `.git/config` (issue 107). `REPO_POLICIES.md` and both checklists
describe the workflow as it now is. Not yet tried on the shared runner, which
is out of disk space. Repositories pick this up on their next re-vendor.
- 2026-10-05: `script/cibuild`, `script/docker`, `script/lint` and `script/test`
now assign the image tag from `script/projectname` on its own line before the
`docker build` (issue 101), so `set -e` stops the script where