Skip to content

ci: call the shared workflows from git-your-ship-together - #12

Merged
ChiefGyk3D merged 5 commits into
masterfrom
ci/git-your-ship-together
Oct 3, 2026
Merged

ChiefGyk3D merged 5 commits into
masterfrom
ci/git-your-ship-together

Conversation

@ChiefGyk3D

@ChiefGyk3D ChiefGyk3D commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Written by scripts/new-repo.sh in ChiefGyk3D/git-your-ship-together, pinned to v1.6.3.

What it found and wrote:

  • Languages: shell
  • Container release: none
  • Package release: no
  • Required checks: ci / CI green
  • Replaced: ci.yml

Default branch is master; the callers trigger on it, and branch protection now requires ci / CI green there (it replaces whatever was required before).

Hand edits (second commit), caller file only:

  • bash-ci.yml test-command carries the old ci.yml's non-shell jobs, with the same commands and image tags: docker compose config --quiet, promtool check config and rules (prom/prometheus:v2.53.0, example file_sd targets staged), amtool check-config (prom/alertmanager:v0.27.0), logstash --config.test_and_exit (opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.0, throwaway CA), a well-formedness check of the Wazuh XML fragments (Python standard library; xmllint is not on the runner and apt would need mirrors in the allow-list), scripts/check-wazuh-rule-ids.py, and pytest over tests/python (68 tests; test-install-command installs pytest, requests, pyyaml).
  • runners: '["ubuntu-24.04"]' only: the test pulls Docker Hub images and the logstash image is not published for arm64. No distros: the checks are about this stack's config files, not an operating system.
  • extra-allowed-endpoints: Docker Hub (auth.docker.io, registry-1.docker.io, production.cloudfront.docker.com, the list python-ci.yml measured) for the test, and ghcr.io, pkg-containers.githubusercontent.com, raw.githubusercontent.com, registry.npmjs.org for the workflow-lint job (bash-ci.yml's default list lacks them).
  • dependabot.yml is github-actions only. The compose file pins most images through ${VAR:-version} defaults, so a docker-compose ecosystem would mostly be noise; add one if you want image bumps.

Pre-existing, now visible (shellcheck-continue-on-error: true, shfmt-continue-on-error: true). The old gate was shellcheck at --severity=error, which is clean; the shared default is warning. Counts come from the same shellcheck 0.11.0 and shfmt 3.14.1 the workflow pins.

shellcheck warnings, 7 in 6 files: scripts/05-verify.sh 2, one each in scripts/10-snapshot-setup.sh, scripts/09-test-crowdsec-pfsense-ingest.sh, scripts/08-crowdsec-smoketest.sh, scripts/04-apply-ism-policy.sh, change-passwords.sh.

shfmt -i 4 -ci (four spaces is what most of the scripts write; scripts 08, 09 and deploy-n8n-soar.sh use two), hunks per file, 60 in 13 of 14 scripts: scripts/deploy-n8n-soar.sh 16, change-passwords.sh 8, scripts/10-snapshot-setup.sh 6, scripts/02-bootstrap.sh 5, scripts/08-crowdsec-smoketest.sh 4, scripts/01-disk-setup.sh 4, scripts/09-test-crowdsec-pfsense-ingest.sh 3, scripts/08b-init-opensearch-security.sh 3, scripts/07-generate-opensearch-certs.sh 3, scripts/05-verify.sh 3, scripts/04-apply-ism-policy.sh 3, scripts/render-alertmanager-config.sh 1, scripts/03-deploy.sh 1.

Before merging: read the caller files once; every command in them came from what the repository already ran. A domain not allowed: <host> line in a job log names a host to add to extra-allowed-endpoints. Branch protection now requires the checks above.

🤖 Generated with Claude Code

ChiefGyk3D and others added 3 commits October 3, 2026 11:22
Written by scripts/new-repo.sh from what the repository already contains.
The workflows it replaces are listed in the pull request.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…indings

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

ChiefGyk3D and others added 2 commits October 3, 2026 11:32
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…the runner

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@ChiefGyk3D
ChiefGyk3D merged commit 0e2d702 into master Oct 3, 2026
17 checks passed
@ChiefGyk3D
ChiefGyk3D deleted the ci/git-your-ship-together branch October 3, 2026 15:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants