Skip to content

ci: repair publisher access and Dependabot required statuses - #5

Merged
coisa merged 4 commits into
mainfrom
codex/ci-publisher-actions-read
Oct 8, 2026
Merged

coisa merged 4 commits into
mainfrom
codex/ci-publisher-actions-read

Conversation

@coisa

@coisa coisa commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

The isolated per-version publisher introduced by DevTools #362 needs actions: read in the caller's permission ceiling. GitHub validates this ceiling even when publication is disabled, so the current caller would fail before starting its jobs after adopting that workflow.

This grants read access to workflow job metadata. The shared workflow keeps test execution jobs at contents: read, actions: none and statuses: none; it reserves status writes for the separate publisher.

Validation: actionlint .github/workflows/tests.yml and git diff --check passed. A controlled GitHub caller with the old ceiling failed before creating jobs (negative case); changing only Actions read permission made the same pinned reusable workflow succeed (control). Library code, Dash artwork and README content are untouched. Merge this caller compatibility update before DevTools #362.

The optional .github/workflows/test-statuses.yml bridge handles Dependabot push lifecycle events from the default branch, using verified GitHub Run/Jobs metadata without checkout, caches, artifacts or caller code. Active attempts reset pending; completed attempts publish actual terminal results. The final code prevents old successes after full-rerun prerequisite failures, closes missing matrix jobs in failed/canceled runs as failures, preserves legitimate partial retries, rejects additional observed versions, and rechecks source metadata before every POST. The complete PHP 8.3/8.4/8.5 contract is explicitly configured for this repository; normal dev-tools:sync does not auto-install the optional source template. PHP 8.4 and 8.5 each passed 130 scenarios / 1,130 assertions (2,260 total). Real lifecycle activation awaits default-branch installation. The test caller's existing Statuses-write ceiling is retained; Actions-read is added for the isolated shared publisher. Deploy this compatibility PR before dev-tools#362, then deploy the ten newly enabled library callers.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T17:36:30.793403Z 61f16bf New commits
🔒 Security Review ✅ Completed 2026-10-08T17:36:05.733801Z 61f16bf New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: bf8a1c3b-307e-458b-8f4f-03652ee41053
📥 Commits

Reviewing files that changed from the base of the PR and between facde75 and 2404cd3.

📒 Files selected for processing (2)
  • .github/workflows/test-statuses.yml
  • CHANGELOG.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Summary

Summary by CodeRabbit

  • Bug Fixes
    • Automated status reporting now reflects completed test results for each configured PHP version on eligible Dependabot push runs, including failures.
    • Statuses are published only after the workflow validates the run and its latest test results, helping prevent outdated or incomplete results from being reported.
    • The status publisher can read workflow outcomes, while test jobs remain without write permissions.

Walkthrough

A completion workflow validates completed Dependabot push runs for the Fast Forward Test Suite. It checks the latest run and PHP-version job results before publishing per-version commit statuses. The test workflow also gains Actions read permission.

Changes

Dependabot test status publishing

Layer / File(s) Summary
Workflow trigger and permissions
.github/workflows/test-statuses.yml, .github/workflows/tests.yml, CHANGELOG.md
The completion workflow handles qualifying Dependabot push runs and receives the source run identity and configured PHP versions. The test workflow gains actions: read. The changelog describes the status-publishing changes.
Run identity and latest-run checks
.github/workflows/test-statuses.yml
The script validates its inputs and API responses, verifies the source run identity and completion state, and skips publishing when a newer run supersedes it.
Job results and commit statuses
.github/workflows/test-statuses.yml
For each configured PHP version, the script validates the latest completed job result. It then publishes a success status only for a successful result and a failure status otherwise.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant CompletionWorkflow
  participant GitHubActionsAPI
  participant GitHubCommitStatuses
  CompletionWorkflow->>GitHubActionsAPI: Fetch source run, latest runs, and job results
  GitHubActionsAPI-->>CompletionWorkflow: Return validated run and job data
  CompletionWorkflow->>GitHubCommitStatuses: Publish per-version success or failure statuses
Loading

Merge Risk: ⚪ Minimal · up to 2404c

No actionable merge-blocking issue is established for this change. The permission update is mergeable after normal checks.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the two main changes: repairing publisher access and adding Dependabot required statuses.
Description check ✅ Passed The description directly explains the Actions permission change, isolated status publisher, Dependabot status workflow, validation, and deployment sequence.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks each run with care
PHP results line up in rows
Newer runs wait; old ones pause
Green or red, the statuses show
Then off the rabbit hops below

Comment @coderabbitai help to get the list of available commands.

@coisa coisa changed the title ci: grant job-metadata read access to the isolated status publisher ci: repair publisher access and Dependabot required statuses Oct 8, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2404cd3eea

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/test-statuses.yml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3661566919

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/test-statuses.yml
@coisa
coisa merged commit ed624ed into main Oct 8, 2026
13 checks passed
@coisa
coisa deleted the codex/ci-publisher-actions-read branch October 8, 2026 19:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant