Repository navigation
ci: gate deploy on link check, add pytest workflow, and harden permissions - #374
Merged
Merged
Conversation
shunk031
force-pushed
the
ci/harden-workflows
branch
from
July 12, 2026 04:50
c906315 to
95292ea
Compare
shunk031
commented
Jul 12, 2026
| with: | ||
| fail: true | ||
| lycheeVersion: v0.21.0 | ||
| lycheeVersion: v0.24.2 |
Owner
Author
There was a problem hiding this comment.
mise.toml と連携できたりします?二重管理キツイ気がして
| @@ -0,0 +1,33 @@ | |||
| name: Pytest | |||
Owner
Author
There was a problem hiding this comment.
pytest ってより test みたいな一般的な感じにしたいです
…sions - gh-pages.yml: deploy now depends on check-broken-links too, so a broken-link failure blocks the gh-pages publish instead of racing it. - gh-pages.yml: add top-level permissions: contents: read (deploy uses a deploy_key secret, not GITHUB_TOKEN, so no write scope is needed). - gh-pages.yml: move the push/workflow_dispatch + main-branch guard from the Deploy step's if: to the deploy job's if:, so PR runs skip the whole job instead of downloading the artifact just to no-op. - Bump lychee from v0.21.0 to v0.24.2 in gh-pages.yml and lychee-prune.yml, and pin mise.toml's lychee tool to the same version. - Add .github/workflows/pytest.yml to run the tests/ suite via 'uv run --with pytest --with ruamel.yaml pytest tests/ -q' on PRs and pushes to main, scoped to tests/**, scripts/**, .agents/skills/**, and the workflow file itself. - config/_default/hugo.yaml: change timeout from bare 600000 to "600s". Hugo v0.136.5 parses the bare number as seconds, so the effective timeout was ~166 hours; "600s" restores the original 10-minute intent (600000 was a leftover from Hugo's old milliseconds interpretation). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Read the lychee version from mise.toml in gh-pages.yml and lychee-prune.yml instead of hardcoding lycheeVersion in each workflow, so mise.toml is the single source of truth and the version is no longer managed in three places. In lychee-prune.yml the version is read right after checkout, before the prune-branch step switches branches. - Rename the pytest workflow to a tool-agnostic name: pytest.yml -> test.yml, workflow name Pytest -> Test, job pytest -> test, and update the self-referencing paths filter accordingly. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
lychee v0.24 errors out on root-relative links (e.g. /tags/...) in local files unless --root-dir is given, whereas v0.21 silently skipped them, so the v0.24.2 bump broke the check-broken-links job. Point --root-dir at the built artifact directory, matching the approach in PR #377. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
lychee >= v0.24 uses rustls, which cannot complete a TLS handshake with book.impress.co.jp because the server only offers legacy TLS cipher suites, even though the page is alive (curl returns 200). Add it to the temporary excludes so the weekly prune workflow re-checks it and removes the entry once the handshake succeeds. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
shunk031
force-pushed
the
ci/harden-workflows
branch
from
July 12, 2026 09:28
357a8c3 to
bd2008c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
deploynowneeds: [build, check-broken-links]ingh-pages.yml, so a broken-link failure blocks the gh-pages publish instead of racing it (previouslycheck-broken-linksanddeployboth only depended onbuildand ran in parallel with no ordering guarantee).permissions: contents: readtogh-pages.yml. Deploy uses theACTIONS_DEPLOY_KEYdeploy_key secret, notGITHUB_TOKEN, so no write scope is required.(github.event_name == 'push' || github.event_name == 'workflow_dispatch') && github.ref == 'refs/heads/main'condition from theDeploystep'sif:up to thedeployjob'sif:. Previously PR runs still executed the wholedeployjob (downloading the artifact) only to skip the final step as a no-op; now the entire job is skipped on PRs.v0.21.0→v0.24.2(latest stable, pergh api repos/lycheeverse/lychee/releases/latest). The version is pinned once inmise.toml(lychee = "0.24.2", was"latest"), and bothgh-pages.ymlandlychee-prune.ymlread it frommise.tomlat runtime (tomllibone-liner → step output →lycheeVersion:) instead of hardcoding it per workflow, so there is no duplicate version management. Inlychee-prune.ymlthe version is read right after checkout, before the prune-branch step switches branches..github/workflows/test.yml(workflow nameTest, jobtest) runstests/viauv run --with pytest --with ruamel.yaml pytest tests/ -qusingastral-sh/setup-uv@v8.3.2(latest release), triggered onpull_requestandpushtomain, scoped withpaths:totests/**,scripts/**,.agents/skills/**, and the workflow file itself (.github/workflows/test.yml) so changes to the workflow are also CI-verified before merge.permissions: contents: readonly.config/_default/hugo.yaml's baretimeout: 600000changed totimeout: "600s". This is a behavioral change, not just a notation cleanup: Hugo v0.136.5 interprets the bare number600000as seconds, so the effective timeout was ~166 hours. The original600000appears to be a leftover from Hugo's old milliseconds interpretation (600000 ms = 10 min), so"600s"restores the originally intended 10-minute timeout unambiguously.Test plan
gh-pages.yml,lychee-prune.yml,test.yml,hugo.yaml) andmise.tomlwithyaml.safe_load/tomllib.load— all valid.v0.24.2.uv run --with pytest --with ruamel.yaml pytest tests/ -q→ 18 passed.mise exec -- hugo --gc --minify→ builds successfully (821 pages) with the newtimeout: "600s".actionlintrun over all workflow files (viamise exec actionlint@latest) → no findings, exit code 0.🤖 Generated with Claude Code