ci: bind the no-mistakes attestation to the current PR head - #46
Merged
Conversation
yjuyjuy
added a commit
to yjuyjuy/tasks-axi
that referenced
this pull request
Aug 24, 2026
…e no-mistakes gate to the shared action (#6) * fix(cli): speed up standalone version queries (kunchenguid#34) * perf(cli): answer --version through the axi-sdk-js fast path Extract the package-version helper out of the heavy `src/cli.ts` graph into a leaf `src/version.ts` (node builtins only), and rewrite `bin/tasks-axi.ts` to answer a bare `-v`/`-V`/`--version` via `axi-sdk-js/fast-path`, dynamically importing the command graph only for everything else. Bumps axi-sdk-js to ^0.1.10 for the `./fast-path` subpath export. Version output is byte-identical and all other argv shapes still route through `runAxiCli` unchanged. Guarded by a deterministic ESM loader module trace with a negative control plus flag parity; no wall-clock assertion in CI. * no-mistakes(document): Confirm fast-path docs and lint cleanliness * no-mistakes: apply CI fixes * chore(main): release tasks-axi 0.2.5 (kunchenguid#35) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * fix(cli): accept canonical Forgejo pull request URLs (kunchenguid#36) * fix: accept canonical Forgejo pull request URLs as typed PR links One classification seam (isPrUrl in src/pr-url.ts) now decides what counts as a PR URL for prose link derivation, done/add --pr validation, and public-followup pr_url deliverables: canonical GitHub https://github.com/<owner>/<repo>/pull/<n> or Forgejo https://<host>/<owner>/<repo>/pulls/<n> with a positive, no-leading-zero number. Near misses (issue routes, singular/plural route confusion, trailing slash, query/fragment, whitespace, userinfo, ports, encoded separators, malformed segments) are rejected as --pr / pr_url values and derive as doc links, never pr. Fixes kunchenguid#19 * fix: validate pr links against the untrimmed input Review follow-ups from pipeline run 01KZFA73D662DCSJ4HVWKW21QX: --pr values and pr-kind addLinks are validated before any trim, so whitespace-padded input is rejected instead of normalized. The literal NUL byte in test/pr-url.test.ts is now written as a unicode source escape so git treats the file as text; an embedded-space rejection case is added alongside it. * chore: remove committed no-mistakes evidence (now on orphan branch) (kunchenguid#39) * chore: gitignore no-mistakes evidence dir (contributor safety) (kunchenguid#41) * chore(agents): use @AGENTS.md import instead of CLAUDE.md symlink (kunchenguid#42) Co-authored-by: Kun Chen <kun-1@kunchenguid.com> * ci: require no-mistakes pipeline attestation in the gate (kunchenguid#45) * ci: require no-mistakes pipeline attestation in the gate * test: run the no-mistakes gate script on POSIX legs only * ci: bind the no-mistakes attestation to the current PR head (kunchenguid#46) * ci: migrate the no-mistakes gate to the shared composite action (kunchenguid#47) Replace the inline gate `run:` block in .github/workflows/no-mistakes-required.yml with a thin caller of kunchenguid/no-mistakes/.github/actions/require-no-mistakes, pinned to an immutable commit SHA. Enforcement logic and its tests now live upstream, so this repository no longer carries a hand-copied script that can drift from its siblings. Drop `synchronize` from the pull_request trigger: the verdict is a pure function of the PR body, and the pipeline pushes before it writes the Pipeline section, so a push-triggered run pinned a failure to a head whose body the same run was about to fix. This repo's ruleset is advisory with no required status check, so dropping the trigger cannot wedge a merge. Remove test/workflows/no-mistakes-gate.test.ts, which extracted and executed the now-absent inline block, and point AGENTS.md at the shared action. * fix: make the generated skill defer to live CLI guidance (kunchenguid#48) * fix(skill): shrink SKILL.md to a CLI-deferring stub Installed skills go stale when the npm package is bumped. Keep only identity frontmatter plus pointers to live CLI help so regeneration cannot re-inflate baked command docs. Co-authored-by: Cursor <cursoragent@cursor.com> * no-mistakes(review): Align skill documentation with minimal generator contract * no-mistakes(document): Consolidate generated skill documentation --------- Co-authored-by: Cursor <cursoragent@cursor.com> * no-mistakes: apply CI fixes --------- Co-authored-by: Kun Chen <3233006+kunchenguid@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Evelyn Scidmore <13389701+escidmore@users.noreply.github.com> Co-authored-by: Kun Chen <kun-1@kunchenguid.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: Chris Yuan <cyuan@hyfin.app>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What Changed
The
Require no-mistakesgate parsed theno-mistakes-pipeline-attestation:v1comment and required review/test/document = completed, but it only printed the attestation'shead_sha- it never compared it to the PR's current head. A commit pushed directly after a no-mistakes run therefore passed the gate on a stale attestation.This ports lavish-axi
main's head-binding (PR #271) verbatim:PR_HEAD_SHA: ${{ github.event.pull_request.head.sha }}added to the gate step'senv:.head_shaand fails with an::error::saying the attestation is STALE for the current head (a commit was pushed after the no-mistakes run; re-rungit push no-mistakesto refresh it) unless it equals$PR_HEAD_SHA. Absent on either side fails closed too.paths-ignore, bot exemptions, job name, and the rest of the script. The gate script is now byte-identical to lavish-axi's; the only file-level difference remains this repo'spaths-ignorelist (noplugin.json).This is the attestation contract: a
synchronizeevent whose PR body was NOT rewritten by no-mistakes going red is the intended behavior, not a false positive.Tests
test/workflows/no-mistakes-gate.test.ts(which extracts and executes the workflow's exact inlinerun:block) gains four head-binding cases, mirroring lavish's:head_shais the PR's current headhead_shais not the current head (asserts the STALE error, the re-run hint, and both shas in the output)head_shaat allrunGateandattestationnow take an optional head sha, defaulting to the existingHEAD_SHAconstant, so every pre-existing case is unchanged.Transcript
Note
This is a direct PR for internal CI tooling, raised without the no-mistakes pipeline, so the advisory
Require no-mistakescheck will fail on it (no signature) - expected and non-blocking. Build/test/guard checks are the real signal.