Found by dnswatcher while re-vendoring for #78 (sneak/dnswatcher#259). dnswatcher added two things to its .gitea/workflows/check.yml under sneak/dnswatcher#216 that the canonical workflow lacks, so a byte-identical re-vendor removes them:
No concurrency block. Every push runs to the end, even after a newer push to the same branch has replaced it. On 2026-10-02 45 stale runs queued on the one shared runner, holding up every repository's checks. dnswatcher uses concurrency: {group: ${{ github.workflow }}-${{ github.ref }}, cancel-in-progress: true}: a new push cancels only the older run on the same branch.
The checkout leaves the CI token in .git/config.actions/checkout persists its token there unless persist-credentials: false is set. script/cibuild needs no token. The canonical .dockerignore keeps .git/config out of the image, but the token still sits in the job's checkout for every later step.
Fix
Add both to the canonical .gitea/workflows/check.yml, each with a one-line comment saying why, and update the workflow bullet of prompts/REPO_POLICIES.md, which says the workflow "checks out the repo as its only other step", so it describes the file as it now is. Check both checklists for the same description.
Definition of done
The canonical workflow has both, and the policy and checklists describe it accurately.
Verified on this repository: a second push to a feature branch cancels the first run on that branch, and the checkout step's .git/config has no extraheader with a token. Gitea's shared runner is broken until sneak/project-management#27 is fixed; until then, state that this is not yet verified and verify once it is.
make check passes.
Model: opus-5-5
Found by `dnswatcher` while re-vendoring for https://git.eeqj.de/sneak/prompts/issues/78 (https://git.eeqj.de/sneak/dnswatcher/pulls/259). `dnswatcher` added two things to its `.gitea/workflows/check.yml` under https://git.eeqj.de/sneak/dnswatcher/issues/216 that the canonical workflow lacks, so a byte-identical re-vendor removes them:
1. **No `concurrency` block.** Every push runs to the end, even after a newer push to the same branch has replaced it. On 2026-10-02 45 stale runs queued on the one shared runner, holding up every repository's checks. `dnswatcher` uses `concurrency: {group: ${{ github.workflow }}-${{ github.ref }}, cancel-in-progress: true}`: a new push cancels only the older run on the same branch.
2. **The checkout leaves the CI token in `.git/config`.** `actions/checkout` persists its token there unless `persist-credentials: false` is set. `script/cibuild` needs no token. The canonical `.dockerignore` keeps `.git/config` out of the image, but the token still sits in the job's checkout for every later step.
## Fix
Add both to the canonical `.gitea/workflows/check.yml`, each with a one-line comment saying why, and update the workflow bullet of `prompts/REPO_POLICIES.md`, which says the workflow "checks out the repo as its only other step", so it describes the file as it now is. Check both checklists for the same description.
## Definition of done
- The canonical workflow has both, and the policy and checklists describe it accurately.
- Verified on this repository: a second push to a feature branch cancels the first run on that branch, and the checkout step's `.git/config` has no `extraheader` with a token. Gitea's shared runner is broken until https://git.eeqj.de/sneak/project-management/issues/27 is fixed; until then, state that this is not yet verified and verify once it is.
- `make check` passes.
Model: opus-5-5
clawbot
self-assigned this 2026-10-06 02:48:06 +02:00
Done in #109: the canonical workflow now has the concurrency block and persist-credentials: false on its checkout step, each with a one-line comment saying why, and the policy and both checklists describe it. Not yet verified live: Gitea's shared runner is out of disk space (sneak/project-management#28); the two live checks are still to do once it runs again.
Model: opus-5-5
Done in https://git.eeqj.de/sneak/prompts/pulls/109: the canonical workflow now has the `concurrency` block and `persist-credentials: false` on its checkout step, each with a one-line comment saying why, and the policy and both checklists describe it. Not yet verified live: Gitea's shared runner is out of disk space (https://git.eeqj.de/sneak/project-management/issues/28); the two live checks are still to do once it runs again.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found by
dnswatcherwhile re-vendoring for #78 (sneak/dnswatcher#259).dnswatcheradded two things to its.gitea/workflows/check.ymlunder sneak/dnswatcher#216 that the canonical workflow lacks, so a byte-identical re-vendor removes them:concurrencyblock. Every push runs to the end, even after a newer push to the same branch has replaced it. On 2026-10-02 45 stale runs queued on the one shared runner, holding up every repository's checks.dnswatcherusesconcurrency: {group: ${{ github.workflow }}-${{ github.ref }}, cancel-in-progress: true}: a new push cancels only the older run on the same branch..git/config.actions/checkoutpersists its token there unlesspersist-credentials: falseis set.script/cibuildneeds no token. The canonical.dockerignorekeeps.git/configout of the image, but the token still sits in the job's checkout for every later step.Fix
Add both to the canonical
.gitea/workflows/check.yml, each with a one-line comment saying why, and update the workflow bullet ofprompts/REPO_POLICIES.md, which says the workflow "checks out the repo as its only other step", so it describes the file as it now is. Check both checklists for the same description.Definition of done
.git/confighas noextraheaderwith a token. Gitea's shared runner is broken until sneak/project-management#27 is fixed; until then, state that this is not yet verified and verify once it is.make checkpasses.Model: opus-5-5
Done in #109: the canonical workflow now has the
concurrencyblock andpersist-credentials: falseon its checkout step, each with a one-line comment saying why, and the policy and both checklists describe it. Not yet verified live: Gitea's shared runner is out of disk space (sneak/project-management#28); the two live checks are still to do once it runs again.Model: opus-5-5