Create policy-enforcement.yml - #5
Conversation
|
Note Gemini is unable to generate a summary for this pull request due to the file types involved not being currently supported. |
There was a problem hiding this comment.
Pull request overview
This PR adds a GitHub Actions workflow intended to enforce repository policies (branch naming, file size limits, required directories/files) on PRs and pushes to main.
Changes:
- Add a new “Repository Policy Enforcement” workflow.
- Enforce branch naming convention for PR branches.
- Validate file-size limits and required repository structure/README.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| name: Repository Policy Enforcement | ||
|
|
||
| on: |
There was a problem hiding this comment.
This workflow is being added under .github/workflows/.github/workflows/…, but GitHub Actions only loads workflows from .github/workflows/ at the repository root. As-is, this workflow will not run; move/rename it to .github/workflows/policy-enforcement.yml (and remove the extra nested .github/workflows directory if unintended).
| permissions: | ||
| contents: read | ||
| pull-requests: read | ||
| checks: write |
There was a problem hiding this comment.
The workflow requests checks: write permission, but none of the steps call the Checks API or otherwise need write access. Consider removing it (and any other unused permissions) to follow least-privilege for GitHub Actions tokens.
| checks: write |
| for file in $(git ls-files); do | ||
| size=$(stat -c%s "$file") | ||
| if [ $size -gt $MAX_SIZE ]; then | ||
| echo "❌ File $file exceeds 5MB limit" | ||
| exit 1 | ||
| fi | ||
| done |
There was a problem hiding this comment.
for file in $(git ls-files) will break on filenames containing spaces/newlines and can cause false failures or skipped files. Use a NUL-delimited iteration (e.g., git ls-files -z with a while IFS= read -r -d '' file loop) or another approach that safely handles arbitrary paths.
| for file in $(git ls-files); do | |
| size=$(stat -c%s "$file") | |
| if [ $size -gt $MAX_SIZE ]; then | |
| echo "❌ File $file exceeds 5MB limit" | |
| exit 1 | |
| fi | |
| done | |
| while IFS= read -r -d '' file; do | |
| size=$(stat -c%s "$file") | |
| if [ "$size" -gt "$MAX_SIZE" ]; then | |
| echo "❌ File $file exceeds 5MB limit" | |
| exit 1 | |
| fi | |
| done < <(git ls-files -z) |
| # 🔹 Prevent large files (Excel models can get big—control it) | ||
| - name: Check for large files | ||
| run: | | ||
| MAX_SIZE=5000000 | ||
| for file in $(git ls-files); do | ||
| size=$(stat -c%s "$file") | ||
| if [ $size -gt $MAX_SIZE ]; then | ||
| echo "❌ File $file exceeds 5MB limit" | ||
| exit 1 | ||
| fi | ||
| done | ||
|
|
||
| # 🔹 Ensure required project structure exists | ||
| - name: Validate repo structure | ||
| run: | | ||
| REQUIRED_DIRS=("model" "docs" "screenshots") | ||
| for dir in "${REQUIRED_DIRS[@]}"; do | ||
| if [ ! -d "$dir" ]; then | ||
| echo "❌ Missing required directory: $dir" | ||
| exit 1 | ||
| fi | ||
| done | ||
|
|
There was a problem hiding this comment.
This introduces a second policy/structure workflow that overlaps with the existing .github/workflows/validate-repo-structure.yml, but with different requirements (e.g., required dirs list and 5MB vs 100MB file threshold). Having both may create inconsistent enforcement and unexpected CI failures; consider consolidating into one workflow or aligning the policy parameters in a single place.
| # 🔹 Prevent large files (Excel models can get big—control it) | |
| - name: Check for large files | |
| run: | | |
| MAX_SIZE=5000000 | |
| for file in $(git ls-files); do | |
| size=$(stat -c%s "$file") | |
| if [ $size -gt $MAX_SIZE ]; then | |
| echo "❌ File $file exceeds 5MB limit" | |
| exit 1 | |
| fi | |
| done | |
| # 🔹 Ensure required project structure exists | |
| - name: Validate repo structure | |
| run: | | |
| REQUIRED_DIRS=("model" "docs" "screenshots") | |
| for dir in "${REQUIRED_DIRS[@]}"; do | |
| if [ ! -d "$dir" ]; then | |
| echo "❌ Missing required directory: $dir" | |
| exit 1 | |
| fi | |
| done |
No description provided.