Canonical workflow lacks a concurrency block and leaves the CI token in .git/config #107

Open
opened 2026-10-06 02:48:06 +02:00 by clawbot · 1 comment
Collaborator

Found by dnswatcher while re-vendoring for #78 (sneak/dnswatcher#259). dnswatcher added two things to its .gitea/workflows/check.yml under sneak/dnswatcher#216 that the canonical workflow lacks, so a byte-identical re-vendor removes them:

  1. No concurrency block. Every push runs to the end, even after a newer push to the same branch has replaced it. On 2026-10-02 45 stale runs queued on the one shared runner, holding up every repository's checks. dnswatcher uses concurrency: {group: ${{ github.workflow }}-${{ github.ref }}, cancel-in-progress: true}: a new push cancels only the older run on the same branch.
  2. The checkout leaves the CI token in .git/config. actions/checkout persists its token there unless persist-credentials: false is set. script/cibuild needs no token. The canonical .dockerignore keeps .git/config out of the image, but the token still sits in the job's checkout for every later step.

Fix

Add both to the canonical .gitea/workflows/check.yml, each with a one-line comment saying why, and update the workflow bullet of prompts/REPO_POLICIES.md, which says the workflow "checks out the repo as its only other step", so it describes the file as it now is. Check both checklists for the same description.

Definition of done

  • The canonical workflow has both, and the policy and checklists describe it accurately.
  • Verified on this repository: a second push to a feature branch cancels the first run on that branch, and the checkout step's .git/config has no extraheader with a token. Gitea's shared runner is broken until sneak/project-management#27 is fixed; until then, state that this is not yet verified and verify once it is.
  • make check passes.

Model: opus-5-5

Found by `dnswatcher` while re-vendoring for https://git.eeqj.de/sneak/prompts/issues/78 (https://git.eeqj.de/sneak/dnswatcher/pulls/259). `dnswatcher` added two things to its `.gitea/workflows/check.yml` under https://git.eeqj.de/sneak/dnswatcher/issues/216 that the canonical workflow lacks, so a byte-identical re-vendor removes them: 1. **No `concurrency` block.** Every push runs to the end, even after a newer push to the same branch has replaced it. On 2026-10-02 45 stale runs queued on the one shared runner, holding up every repository's checks. `dnswatcher` uses `concurrency: {group: ${{ github.workflow }}-${{ github.ref }}, cancel-in-progress: true}`: a new push cancels only the older run on the same branch. 2. **The checkout leaves the CI token in `.git/config`.** `actions/checkout` persists its token there unless `persist-credentials: false` is set. `script/cibuild` needs no token. The canonical `.dockerignore` keeps `.git/config` out of the image, but the token still sits in the job's checkout for every later step. ## Fix Add both to the canonical `.gitea/workflows/check.yml`, each with a one-line comment saying why, and update the workflow bullet of `prompts/REPO_POLICIES.md`, which says the workflow "checks out the repo as its only other step", so it describes the file as it now is. Check both checklists for the same description. ## Definition of done - The canonical workflow has both, and the policy and checklists describe it accurately. - Verified on this repository: a second push to a feature branch cancels the first run on that branch, and the checkout step's `.git/config` has no `extraheader` with a token. Gitea's shared runner is broken until https://git.eeqj.de/sneak/project-management/issues/27 is fixed; until then, state that this is not yet verified and verify once it is. - `make check` passes. Model: opus-5-5
clawbot self-assigned this 2026-10-06 02:48:06 +02:00
Author
Collaborator

Done in #109: the canonical workflow now has the concurrency block and persist-credentials: false on its checkout step, each with a one-line comment saying why, and the policy and both checklists describe it. Not yet verified live: Gitea's shared runner is out of disk space (sneak/project-management#28); the two live checks are still to do once it runs again.

Model: opus-5-5

Done in https://git.eeqj.de/sneak/prompts/pulls/109: the canonical workflow now has the `concurrency` block and `persist-credentials: false` on its checkout step, each with a one-line comment saying why, and the policy and both checklists describe it. Not yet verified live: Gitea's shared runner is out of disk space (https://git.eeqj.de/sneak/project-management/issues/28); the two live checks are still to do once it runs again. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/prompts#107