Skip to content

ci: split CI workflow into dedicated test and publish workflows - #5

Merged
IamCoder18 merged 1 commit into
mainfrom
IamCoder18/extract-CI-into-multiple-workflows
Sep 11, 2026
Merged

IamCoder18 merged 1 commit into
mainfrom
IamCoder18/extract-CI-into-multiple-workflows

Conversation

@IamCoder18

Copy link
Copy Markdown
Owner

Summary

  • Extract the monolithic ci.yml into two dedicated workflows:
    • test.yml — builds and tests on PRs to main and pushes to main, uploads test results as an artifact. Adds least-privilege top-level permissions: contents: read and a cancel-in-progress concurrency group per ref (matching docker.yml's zizmor-compliant style).
    • publish.yml — publishes to GitHub Packages on v* tag pushes only. Since cross-workflow needs: isn't possible, tests are re-run inside this workflow and publish keeps needs: test so publishing stays gated on a green build.
  • Delete the old ci.yml.
  • Update README badges from CI to Test + Publish.

Validation

  • All workflow files parse as valid YAML with the expected job graphs (publish needs test verified).
  • actionlint/zizmor not installed locally — syntax-level validation only.

Follow-up

If branch protection marks CI / Build & Test as a required status check, update it to the new check name (Test / Build & Test).

@coderabbitai

coderabbitai Bot commented Sep 11, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 9 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: e2ec814f-3cce-4297-88f2-da40246fa8e8

📥 Commits

Reviewing files that changed from the base of the PR and between fa66e6b and 5668733.

📒 Files selected for processing (3)
  • .github/workflows/publish.yml
  • .github/workflows/test.yml
  • README.md

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

WARNING: Action version pinned to a major-version tag, not a SHA commit

The PR description claims this matches docker.yml's "zizmor-compliant style", but docker.yml pins every action to a SHA + version comment (e.g. actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2). Pinning to @v4 here still trips zizmor's unpinned-uses audit, so the new permissions: contents: read block only fixes the excessive-permissions audit — the unpinned-uses finding remains. The same fix is needed for actions/setup-java@v5 (line 30) and actions/upload-artifact@v4 (line 40).

Suggested change
uses: actions/checkout@v4
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

Reply with @kilocode-bot fix it to have Kilo Code address this issue.

@kilo-code-bot

kilo-code-bot Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: 1 Issue Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 1
SUGGESTION 0
Issue Details (click to expand)

WARNING

File Line Issue
.github/workflows/test.yml 27 actions/checkout@v4 is pinned to a major-version tag, not a SHA. The same pattern needs to be applied to actions/setup-java@v5 (line 30) and actions/upload-artifact@v4 (line 40). See inline comment.

Related observations (not flagged inline)

  • .github/workflows/publish.yml has the same unpinned-action issue on lines 19, 22, 32, 48, 51, but those lines are unchanged from the renamed ci.yml so they fall outside this PR's review scope. Worth fixing in a follow-up so the repo actually achieves the zizmor-compliant posture the PR description claims.
  • .github/workflows/publish.yml is missing a concurrency block, which test.yml and docker.yml both have. Without it, force-pushing the same v* tag (or two tags in quick succession) can race two publish jobs against each other. Adding concurrency: { group: publish-${{ github.ref }}, cancel-in-progress: true } would mirror docker.yml's pattern.
Files Reviewed (3 files)
  • .github/workflows/publish.yml - 0 inline issues (related observation only)
  • .github/workflows/test.yml - 1 issue
  • README.md - 0 issues

Fix these issues in Kilo Cloud


Reviewed by minimax-m3 · Input: 0 · Output: 0 · Cached: 0

@IamCoder18
IamCoder18 merged commit e26dd59 into main Sep 11, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant