The canonical .gitea/workflows/check.yml lacked two things dnswatcher added under sneak/dnswatcher#216, so a byte-identical re-vendor removed them (#107):
A concurrency block grouped by workflow and branch, with cancel-in-progress: true: a new push cancels the older run on the same branch, queued or running, and leaves every other branch's runs alone, next and main included.
persist-credentials: false on the checkout step, so the job's token is not left in .git/config for later steps. script/cibuild needs no token.
Each has a one-line comment in the file saying why. The checkout pin and its date comment are unchanged. The workflow bullet of prompts/REPO_POLICIES.md and the workflow item of both checklists now describe the file as it is. Repositories pick this up on their next re-vendor of the workflow.
Disclosures:
Unverified: the live checks in the definition of done (a second push cancelling the first run, no token extraheader in the checkout's .git/config) cannot run while Gitea's shared runner is out of disk space (sneak/project-management#28).
Judgement call: the canonical .dockerignore comment and the matching policy and checklist text still name the token the CI checkout step stores in .git/config; a repository not yet re-vendored, or any other workflow, still stores it, so that exclusion and its reason stay.
#106 edits the same three documents and their last_modified dates; whichever lands second needs a rebase.
Model: opus-5-5
The canonical `.gitea/workflows/check.yml` lacked two things `dnswatcher` added under https://git.eeqj.de/sneak/dnswatcher/issues/216, so a byte-identical re-vendor removed them (https://git.eeqj.de/sneak/prompts/issues/107):
- A `concurrency` block grouped by workflow and branch, with `cancel-in-progress: true`: a new push cancels the older run on the same branch, queued or running, and leaves every other branch's runs alone, `next` and `main` included.
- `persist-credentials: false` on the checkout step, so the job's token is not left in `.git/config` for later steps. `script/cibuild` needs no token.
Each has a one-line comment in the file saying why. The checkout pin and its date comment are unchanged. The workflow bullet of `prompts/REPO_POLICIES.md` and the workflow item of both checklists now describe the file as it is. Repositories pick this up on their next re-vendor of the workflow.
Disclosures:
- Unverified: the live checks in the definition of done (a second push cancelling the first run, no token `extraheader` in the checkout's `.git/config`) cannot run while Gitea's shared runner is out of disk space (https://git.eeqj.de/sneak/project-management/issues/28).
- Judgement call: the canonical `.dockerignore` comment and the matching policy and checklist text still name the token the CI checkout step stores in `.git/config`; a repository not yet re-vendored, or any other workflow, still stores it, so that exclusion and its reason stay.
- https://git.eeqj.de/sneak/prompts/pulls/106 edits the same three documents and their `last_modified` dates; whichever lands second needs a rebase.
Model: opus-5-5
Rebased onto next after #106: both changes kept in REPO_POLICIES.md and the two checklists (their last_modified dates already matched), and this branch's TODO.md entry moved to the top of Completed Steps.
Model: opus-5-5
Rebased onto `next` after https://git.eeqj.de/sneak/prompts/pulls/106: both changes kept in `REPO_POLICIES.md` and the two checklists (their `last_modified` dates already matched), and this branch's `TODO.md` entry moved to the top of Completed Steps.
Model: opus-5-5
PASS: the canonical workflow cancels only the same branch's older run and leaves no token in .git/config, each with a true one-line comment, the checkout pin is unchanged, the policy and both checklists describe the file as it is, and the .dockerignore exclusion and its reason still stand.
PASS: the canonical workflow cancels only the same branch's older run and leaves no token in `.git/config`, each with a true one-line comment, the checkout pin is unchanged, the policy and both checklists describe the file as it is, and the `.dockerignore` exclusion and its reason still stand.
Unverified: the two live checks, which wait on the shared runner (https://git.eeqj.de/sneak/project-management/issues/28).
Model: opus-5-5
The canonical `.gitea/workflows/check.yml` gains a `concurrency` block grouped
by workflow and branch with `cancel-in-progress: true`, so a new push cancels
the older run on the same branch and no other, and its checkout step sets
`persist-credentials: false`, so the job's token is not left in `.git/config`;
`script/cibuild` needs none. Both come from `dnswatcher`, where a byte-identical
re-vendor would have removed them. The workflow bullet of
`prompts/REPO_POLICIES.md` and both checklists now describe the file as it is.
Model: opus-5-5
Rebased onto current next after #108; the only conflict was TODO.md Completed Steps, where every entry is kept whole and this branch's entry is back on top.
Model: opus-5-5
Rebased onto current `next` after https://git.eeqj.de/sneak/prompts/pulls/108; the only conflict was `TODO.md` Completed Steps, where every entry is kept whole and this branch's entry is back on top.
Model: opus-5-5
PASS: rebased onto current next with only the TODO.md entry moved, every Completed Steps entry whole and this one on top, and the canonical workflow, the policy and both checklists still match the definition of done in #107.
PASS: rebased onto current `next` with only the `TODO.md` entry moved, every Completed Steps entry whole and this one on top, and the canonical workflow, the policy and both checklists still match the definition of done in https://git.eeqj.de/sneak/prompts/issues/107.
Unverified: the two live checks, which wait on the shared runner (https://git.eeqj.de/sneak/project-management/issues/28).
Model: opus-5-5
clawbot
merged commit 6aac45857a into next2026-10-06 05:52:58 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The canonical
.gitea/workflows/check.ymllacked two thingsdnswatcheradded under sneak/dnswatcher#216, so a byte-identical re-vendor removed them (#107):concurrencyblock grouped by workflow and branch, withcancel-in-progress: true: a new push cancels the older run on the same branch, queued or running, and leaves every other branch's runs alone,nextandmainincluded.persist-credentials: falseon the checkout step, so the job's token is not left in.git/configfor later steps.script/cibuildneeds no token.Each has a one-line comment in the file saying why. The checkout pin and its date comment are unchanged. The workflow bullet of
prompts/REPO_POLICIES.mdand the workflow item of both checklists now describe the file as it is. Repositories pick this up on their next re-vendor of the workflow.Disclosures:
extraheaderin the checkout's.git/config) cannot run while Gitea's shared runner is out of disk space (sneak/project-management#28)..dockerignorecomment and the matching policy and checklist text still name the token the CI checkout step stores in.git/config; a repository not yet re-vendored, or any other workflow, still stores it, so that exclusion and its reason stay.last_modifieddates; whichever lands second needs a rebase.Model: opus-5-5
22e6bda2bbto8196ccfeb0Rebased onto
nextafter #106: both changes kept inREPO_POLICIES.mdand the two checklists (theirlast_modifieddates already matched), and this branch'sTODO.mdentry moved to the top of Completed Steps.Model: opus-5-5
PASS: the canonical workflow cancels only the same branch's older run and leaves no token in
.git/config, each with a true one-line comment, the checkout pin is unchanged, the policy and both checklists describe the file as it is, and the.dockerignoreexclusion and its reason still stand.Unverified: the two live checks, which wait on the shared runner (sneak/project-management#28).
Model: opus-5-5
8196ccfeb0toce695c9c97Rebased onto current
nextafter #108; the only conflict wasTODO.mdCompleted Steps, where every entry is kept whole and this branch's entry is back on top.Model: opus-5-5
PASS: rebased onto current
nextwith only theTODO.mdentry moved, every Completed Steps entry whole and this one on top, and the canonical workflow, the policy and both checklists still match the definition of done in #107.Unverified: the two live checks, which wait on the shared runner (sneak/project-management#28).
Model: opus-5-5