Skip to content

fix(ci): drop invalid timeout-minutes from 4 reusable-workflow calls (were parse-rejected/dead) - #374

Closed
hyperpolymath wants to merge 1 commit into
mainfrom
fix/ci-timeout-minutes-reusable
Closed

hyperpolymath wants to merge 1 commit into
mainfrom
fix/ci-timeout-minutes-reusable

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

What

governance.yml, hypatia-scan.yml, mirror.yml, and secret-scanner.yml each set a job-level timeout-minutes: on a job that calls a reusable workflow via uses:. GitHub does not permit that key on a workflow_call job, so it rejected all four files at parse time — they failed instantly (0s, run titled by raw filename) on every push and never executed a single job.

Net effect on the hub: governance enforcement, hypatia scanning, GitLab mirroring, and secret scanning were all silently disabled.

Evidence

  • gh run view on a recent run: "This run likely failed because of a workflow file issue."
  • actionlint (real tool): when a reusable workflow is called with "uses", "timeout-minutes" is not available on all four.

Fix

Remove the invalid caller-side timeout-minutes:. The standards *-reusable.yml workflows already declare timeout-minutes on every internal job, so the caller key was redundant as well as invalid. This matches the already-correct rsr-template-repo pattern, and the upstream hypatia rule missing_timeout_minutes (lib/rules/workflow_audit.ex) already exempts reusable-call jobs — so these will not be re-flagged.

Verification

actionlint on the four files: exit 0, zero timeout-minutes is not available findings remain on the hub.

Wider context

This is the reference fix for an estate-wide shared-fate defect: 84 repos carry the same dead pattern. A scripted, verified sweep of the remaining 83 is proposed separately.

🤖 Generated with Claude Code

…w calls

governance.yml, hypatia-scan.yml, mirror.yml and secret-scanner.yml each set
`timeout-minutes:` on a job that calls a reusable workflow via `uses:`. GitHub
does not permit that key on a workflow_call job, so it rejected all four files
at parse time: each failed instantly (0s, titled by raw filename) on every
push and never ran a single job. That silently disabled governance, hypatia
scanning, GitLab mirroring and secret scanning on the hub.

The standards `*-reusable.yml` workflows already declare `timeout-minutes` on
every internal job, so the caller-side key was redundant as well as invalid.
Removing it restores the four workflows and matches the already-correct
rsr-template-repo pattern. The upstream hypatia rule `missing_timeout_minutes`
(lib/rules/workflow_audit.ex) already exempts reusable-call jobs, so these
will not be re-flagged.

Verified with actionlint (real tool): all four files parse clean, exit 0; zero
`timeout-minutes is not available` findings remain on the hub.

Part of the estate-wide CI cleanup: 84 repos carry this same dead pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath marked this pull request as ready for review July 17, 2026 19:59
@hyperpolymath
hyperpolymath enabled auto-merge (squash) July 17, 2026 19:59
This was referenced Jul 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant