Skip to content

ci: gate deploy on link check, add pytest workflow, and harden permissions - #374

Merged
shunk031 merged 4 commits into
mainfrom
ci/harden-workflows
Jul 12, 2026
Merged

shunk031 merged 4 commits into
mainfrom
ci/harden-workflows

Conversation

@shunk031

@shunk031 shunk031 commented Jul 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Gate deploy on link check: deploy now needs: [build, check-broken-links] in gh-pages.yml, so a broken-link failure blocks the gh-pages publish instead of racing it (previously check-broken-links and deploy both only depended on build and ran in parallel with no ordering guarantee).
  • Harden permissions: added top-level permissions: contents: read to gh-pages.yml. Deploy uses the ACTIONS_DEPLOY_KEY deploy_key secret, not GITHUB_TOKEN, so no write scope is required.
  • Job-level skip for PRs: moved the (github.event_name == 'push' || github.event_name == 'workflow_dispatch') && github.ref == 'refs/heads/main' condition from the Deploy step's if: up to the deploy job's if:. Previously PR runs still executed the whole deploy job (downloading the artifact) only to skip the final step as a no-op; now the entire job is skipped on PRs.
  • Bump lychee and single-source its version: v0.21.0 → v0.24.2 (latest stable, per gh api repos/lycheeverse/lychee/releases/latest). The version is pinned once in mise.toml (lychee = "0.24.2", was "latest"), and both gh-pages.yml and lychee-prune.yml read it from mise.toml at runtime (tomllib one-liner → step output → lycheeVersion:) instead of hardcoding it per workflow, so there is no duplicate version management. In lychee-prune.yml the version is read right after checkout, before the prune-branch step switches branches.
  • Add test workflow: new .github/workflows/test.yml (workflow name Test, job test) runs tests/ via uv run --with pytest --with ruamel.yaml pytest tests/ -q using astral-sh/setup-uv@v8.3.2 (latest release), triggered on pull_request and push to main, scoped with paths: to tests/**, scripts/**, .agents/skills/**, and the workflow file itself (.github/workflows/test.yml) so changes to the workflow are also CI-verified before merge. permissions: contents: read only.
  • Fix Hugo timeout: config/_default/hugo.yaml's bare timeout: 600000 changed to timeout: "600s". This is a behavioral change, not just a notation cleanup: Hugo v0.136.5 interprets the bare number 600000 as seconds, so the effective timeout was ~166 hours. The original 600000 appears to be a leftover from Hugo's old milliseconds interpretation (600000 ms = 10 min), so "600s" restores the originally intended 10-minute timeout unambiguously.

Test plan

  • Parsed all changed/added YAML (gh-pages.yml, lychee-prune.yml, test.yml, hugo.yaml) and mise.toml with yaml.safe_load / tomllib.load — all valid.
  • Verified the mise.toml version-extraction one-liner locally: prints v0.24.2.
  • uv run --with pytest --with ruamel.yaml pytest tests/ -q → 18 passed.
  • mise exec -- hugo --gc --minify → builds successfully (821 pages) with the new timeout: "600s".
  • actionlint run over all workflow files (via mise exec actionlint@latest) → no findings, exit code 0.

🤖 Generated with Claude Code

@shunk031
shunk031 force-pushed the ci/harden-workflows branch from c906315 to 95292ea Compare July 12, 2026 04:50
Comment thread .github/workflows/gh-pages.yml Outdated
with:
fail: true
lycheeVersion: v0.21.0
lycheeVersion: v0.24.2

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mise.toml と連携できたりします?二重管理キツイ気がして

Comment thread .github/workflows/pytest.yml Outdated
@@ -0,0 +1,33 @@
name: Pytest

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

pytest ってより test みたいな一般的な感じにしたいです

shunk031 and others added 4 commits July 12, 2026 18:27
…sions

- gh-pages.yml: deploy now depends on check-broken-links too, so a
  broken-link failure blocks the gh-pages publish instead of racing it.
- gh-pages.yml: add top-level permissions: contents: read (deploy uses
  a deploy_key secret, not GITHUB_TOKEN, so no write scope is needed).
- gh-pages.yml: move the push/workflow_dispatch + main-branch guard from
  the Deploy step's if: to the deploy job's if:, so PR runs skip the
  whole job instead of downloading the artifact just to no-op.
- Bump lychee from v0.21.0 to v0.24.2 in gh-pages.yml and
  lychee-prune.yml, and pin mise.toml's lychee tool to the same version.
- Add .github/workflows/pytest.yml to run the tests/ suite via
  'uv run --with pytest --with ruamel.yaml pytest tests/ -q' on PRs and
  pushes to main, scoped to tests/**, scripts/**, .agents/skills/**,
  and the workflow file itself.
- config/_default/hugo.yaml: change timeout from bare 600000 to "600s".
  Hugo v0.136.5 parses the bare number as seconds, so the effective
  timeout was ~166 hours; "600s" restores the original 10-minute
  intent (600000 was a leftover from Hugo's old milliseconds
  interpretation).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Read the lychee version from mise.toml in gh-pages.yml and
  lychee-prune.yml instead of hardcoding lycheeVersion in each
  workflow, so mise.toml is the single source of truth and the
  version is no longer managed in three places. In lychee-prune.yml
  the version is read right after checkout, before the prune-branch
  step switches branches.
- Rename the pytest workflow to a tool-agnostic name: pytest.yml ->
  test.yml, workflow name Pytest -> Test, job pytest -> test, and
  update the self-referencing paths filter accordingly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
lychee v0.24 errors out on root-relative links (e.g. /tags/...) in
local files unless --root-dir is given, whereas v0.21 silently
skipped them, so the v0.24.2 bump broke the check-broken-links job.
Point --root-dir at the built artifact directory, matching the
approach in PR #377.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
lychee >= v0.24 uses rustls, which cannot complete a TLS handshake
with book.impress.co.jp because the server only offers legacy TLS
cipher suites, even though the page is alive (curl returns 200).
Add it to the temporary excludes so the weekly prune workflow
re-checks it and removes the entry once the handshake succeeds.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@shunk031
shunk031 force-pushed the ci/harden-workflows branch from 357a8c3 to bd2008c Compare July 12, 2026 09:28
@shunk031
shunk031 merged commit c7c3a0a into main Jul 12, 2026
6 checks passed
@shunk031
shunk031 deleted the ci/harden-workflows branch July 12, 2026 09:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant