Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
68 changes: 68 additions & 0 deletions .github/workflows/.github/workflows/policy-enforcement.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,68 @@
name: Repository Policy Enforcement

on:
Comment on lines +1 to +3

Copilot AI Mar 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This workflow is being added under .github/workflows/.github/workflows/…, but GitHub Actions only loads workflows from .github/workflows/ at the repository root. As-is, this workflow will not run; move/rename it to .github/workflows/policy-enforcement.yml (and remove the extra nested .github/workflows directory if unintended).

Copilot uses AI. Check for mistakes.
pull_request:
push:
branches: [ "main" ]

permissions:
contents: read
pull-requests: read
checks: write

Copilot AI Mar 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The workflow requests checks: write permission, but none of the steps call the Checks API or otherwise need write access. Consider removing it (and any other unused permissions) to follow least-privilege for GitHub Actions tokens.

Suggested change
checks: write

Copilot uses AI. Check for mistakes.

concurrency:
group: policy-${{ github.ref }}
cancel-in-progress: true

jobs:
policy-checks:
runs-on: ubuntu-latest

steps:
- name: Checkout repo
uses: actions/checkout@v4

# 🔹 Enforce branch naming convention
- name: Validate branch name
if: github.event_name == 'pull_request'
run: |
BRANCH_NAME="${{ github.head_ref }}"
echo "Checking branch: $BRANCH_NAME"
if [[ ! "$BRANCH_NAME" =~ ^(main|feature\/.+|bugfix\/.+|hotfix\/.+|chore\/.+)$ ]]; then
echo "❌ Invalid branch naming convention"
exit 1
fi

# 🔹 Prevent large files (Excel models can get big—control it)
- name: Check for large files
run: |
MAX_SIZE=5000000
for file in $(git ls-files); do
size=$(stat -c%s "$file")
if [ $size -gt $MAX_SIZE ]; then
echo "❌ File $file exceeds 5MB limit"
exit 1
fi
done
Comment on lines +40 to +46

Copilot AI Mar 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

for file in $(git ls-files) will break on filenames containing spaces/newlines and can cause false failures or skipped files. Use a NUL-delimited iteration (e.g., git ls-files -z with a while IFS= read -r -d '' file loop) or another approach that safely handles arbitrary paths.

Suggested change
for file in $(git ls-files); do
size=$(stat -c%s "$file")
if [ $size -gt $MAX_SIZE ]; then
echo "❌ File $file exceeds 5MB limit"
exit 1
fi
done
while IFS= read -r -d '' file; do
size=$(stat -c%s "$file")
if [ "$size" -gt "$MAX_SIZE" ]; then
echo "❌ File $file exceeds 5MB limit"
exit 1
fi
done < <(git ls-files -z)

Copilot uses AI. Check for mistakes.

# 🔹 Ensure required project structure exists
- name: Validate repo structure
run: |
REQUIRED_DIRS=("model" "docs" "screenshots")
for dir in "${REQUIRED_DIRS[@]}"; do
if [ ! -d "$dir" ]; then
echo "❌ Missing required directory: $dir"
exit 1
fi
done

Comment on lines +36 to +58

Copilot AI Mar 26, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This introduces a second policy/structure workflow that overlaps with the existing .github/workflows/validate-repo-structure.yml, but with different requirements (e.g., required dirs list and 5MB vs 100MB file threshold). Having both may create inconsistent enforcement and unexpected CI failures; consider consolidating into one workflow or aligning the policy parameters in a single place.

Suggested change
# 🔹 Prevent large files (Excel models can get big—control it)
- name: Check for large files
run: |
MAX_SIZE=5000000
for file in $(git ls-files); do
size=$(stat -c%s "$file")
if [ $size -gt $MAX_SIZE ]; then
echo "❌ File $file exceeds 5MB limit"
exit 1
fi
done
# 🔹 Ensure required project structure exists
- name: Validate repo structure
run: |
REQUIRED_DIRS=("model" "docs" "screenshots")
for dir in "${REQUIRED_DIRS[@]}"; do
if [ ! -d "$dir" ]; then
echo "❌ Missing required directory: $dir"
exit 1
fi
done

Copilot uses AI. Check for mistakes.
# 🔹 Ensure README exists
- name: Check README
run: |
if [ ! -f "README.md" ]; then
echo "❌ README.md is missing"
exit 1
fi

- name: Policy checks passed
run: echo "✅ All policy checks passed"
Loading