ci: required-check workflows now fire on every PR (no paths filter)
Branch protection on `main` + `stable` lists `upgrade-from-bootstrap` and `fresh-install` as REQUIRED checks. The producing workflows had `paths:` filters in their `pull_request` triggers, so they correctly skipped on PRs that didn't touch migrations / package.json. But a skipped workflow doesn't satisfy a required check — it leaves the status "missing", which blocks merge on every unrelated PR. Concretely surfaced on PR #692 (security bumps): all 12 visible checks were green, but the merge button was blocked because the two path-filtered workflows skipped and their required-check names never reported. This PR drops the `paths:` filter from both workflows so they always fire on PRs against `main` + `stable`. Costs: - `schema-drift` (`upgrade-from-bootstrap`): ~75 s per PR (Postgres service boot + migrate:safe run + schema assertion). - `install-smoke` (`fresh-install`): ~2 min per PR (full Docker Compose boot + login). Both are buying unconditional safety nets on the install + migration paths, which is what the required-check gate is supposed to model. Also fixes the trigger branch list while in the file: `[main, beta]` → `[main, stable]`, completing the post-#669 rename for these two workflows that were missed in PR #686. ## What this does NOT fix `GitGuardian Security Checks` is the third required check that's currently missing on PRs — but that's a separate problem. The GitGuardian GitHub App was installed at the user-account level (`the-luap`) before the org transfer and didn't move with the repo. Re-installing it on the org via the GitHub Marketplace is a UI step the maintainer needs to do; can't be done via API.
This commit is contained in:
@@ -16,24 +16,17 @@ name: Fresh-install smoke
|
||||
# don't pay the build cost.
|
||||
|
||||
on:
|
||||
# No `paths:` filter — branch protection on `main` + `stable` lists
|
||||
# `fresh-install` as a REQUIRED check, and a path-filtered trigger
|
||||
# that skipped on unrelated PRs (e.g. frontend-only) would leave the
|
||||
# required check "missing" forever and block the merge. Better to
|
||||
# pay the boot cost on every PR than maintain a per-path allowlist
|
||||
# that drifts as the install surface evolves. (Branches also updated
|
||||
# post-#669 rename: beta → main, old main → stable.)
|
||||
push:
|
||||
branches: [main, beta]
|
||||
paths:
|
||||
- 'backend/Dockerfile'
|
||||
- 'backend/wait-for-db.sh'
|
||||
- 'backend/migrations/**'
|
||||
- 'backend/package*.json'
|
||||
- 'docker-compose.production.yml'
|
||||
- '.github/workflows/install-smoke.yml'
|
||||
branches: [main, stable]
|
||||
pull_request:
|
||||
branches: [main, beta]
|
||||
paths:
|
||||
- 'backend/Dockerfile'
|
||||
- 'backend/wait-for-db.sh'
|
||||
- 'backend/migrations/**'
|
||||
- 'backend/package*.json'
|
||||
- 'docker-compose.production.yml'
|
||||
- '.github/workflows/install-smoke.yml'
|
||||
branches: [main, stable]
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
|
||||
@@ -30,20 +30,17 @@ name: Schema drift (#530)
|
||||
# the same shape is caught before merge.
|
||||
|
||||
on:
|
||||
# No `paths:` filter — branch protection on `main` + `stable` lists
|
||||
# `upgrade-from-bootstrap` as a REQUIRED check. A path-filtered
|
||||
# trigger that skipped on unrelated PRs would leave the required
|
||||
# check "missing" forever, blocking every PR that doesn't touch
|
||||
# migrations. The ~75-second cost on every PR buys an unconditional
|
||||
# safety net. (Branches also updated post-#669 rename: beta → main,
|
||||
# old main → stable.)
|
||||
push:
|
||||
branches: [main, beta]
|
||||
paths:
|
||||
- 'backend/migrations/**'
|
||||
- 'backend/src/database/db.js'
|
||||
- 'backend/knexfile.js'
|
||||
- '.github/workflows/schema-drift.yml'
|
||||
branches: [main, stable]
|
||||
pull_request:
|
||||
branches: [main, beta]
|
||||
paths:
|
||||
- 'backend/migrations/**'
|
||||
- 'backend/src/database/db.js'
|
||||
- 'backend/knexfile.js'
|
||||
- '.github/workflows/schema-drift.yml'
|
||||
branches: [main, stable]
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
|
||||
Reference in New Issue
Block a user