ci: lint workflows and test the PR check's key-sharing decision - #75
Open
scott-lowe-vapi wants to merge 1 commit into
Open
scott-lowe-vapi wants to merge 1 commit into
scott-lowe-vapi wants to merge 1 commit into
Conversation
The PR check workflow decides whether a pull request gets this repository's Vapi keys. That decision was untested bash, and no workflow had ever been through actionlint. - tests/vapi-checks-workflow.test.ts runs the workflow's real steps from vapi-checks.yml with bash: the live-or-dry-run decision across own branches, manual runs, forks (including a look-alike repo name), Dependabot as actor or author, a missing head repo and other events; the run step's arguments (dry vs live, named check, merge-base selection, with and without a base ref) using a stub node; empty key variables being unset; and statically, that secrets are gated on a live run, the triggers are pull_request and workflow_dispatch only, the permissions are contents: read and statuses: write, and checkout doesn't persist credentials. Dropping the Dependabot-author guard fails the decision test. - The decision step now also requires a pull_request event before going live, so adding a trigger later can't widen who gets the keys. - ci.yml gets an actionlint job: a pinned release whose sha256 is checked before it runs, with shellcheck linting every run: block. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This was referenced Oct 3, 2026
Contributor
Author
This was referenced Oct 3, 2026
scott-lowe-vapi
marked this pull request as ready for review
October 3, 2026 07:19
This was referenced Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Value
V.A.L.U.E. tier: small — touches
.github/workflows/(a blast-radius path) and the logic deciding which PRs receive the repository's Vapi keys.tests/vapi-checks-workflow.test.tsruns the workflow's real steps, read fromvapi-checks.yml, with bash:pull_request_targetevent all run dry;node: dry vs live, a named check on dispatch,--changed-sinceonly when the base ref exists, and empty key variables unset;pull_requestandworkflow_dispatch, permissions arecontents: readandstatuses: write, and checkout doesn't persist credentials.pull_requestevent before going live, so adding a trigger later can't widen who gets the keys.ci.ymlgains anactionlintjob: a pinned release whose sha256 is verified before it runs. It also runs shellcheck over everyrun:block.Evidence of value
Testing plan
npm test(509 tests) andnpx tsc --noEmitpass.VAPI_CHECKS_ENABLED.Refs TEST-141
🤖 Generated with Claude Code