Repository navigation
ci: split CI workflow into dedicated test and publish workflows - #5
Conversation
|
Warning Review limit reachedNext included review available in 9 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout | ||
| uses: actions/checkout@v4 |
There was a problem hiding this comment.
WARNING: Action version pinned to a major-version tag, not a SHA commit
The PR description claims this matches docker.yml's "zizmor-compliant style", but docker.yml pins every action to a SHA + version comment (e.g. actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2). Pinning to @v4 here still trips zizmor's unpinned-uses audit, so the new permissions: contents: read block only fixes the excessive-permissions audit — the unpinned-uses finding remains. The same fix is needed for actions/setup-java@v5 (line 30) and actions/upload-artifact@v4 (line 40).
| uses: actions/checkout@v4 | |
| uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 |
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
Code Review SummaryStatus: 1 Issue Found | Recommendation: Address before merge Overview
Issue Details (click to expand)WARNING
Related observations (not flagged inline)
Files Reviewed (3 files)
Fix these issues in Kilo Cloud Reviewed by minimax-m3 · Input: 0 · Output: 0 · Cached: 0 |
Summary
ci.ymlinto two dedicated workflows:test.yml— builds and tests on PRs tomainand pushes tomain, uploads test results as an artifact. Adds least-privilege top-levelpermissions: contents: readand acancel-in-progressconcurrency group per ref (matchingdocker.yml's zizmor-compliant style).publish.yml— publishes to GitHub Packages onv*tag pushes only. Since cross-workflowneeds:isn't possible, tests are re-run inside this workflow andpublishkeepsneeds: testso publishing stays gated on a green build.ci.yml.Validation
publish needs testverified).Follow-up
If branch protection marks
CI / Build & Testas a required status check, update it to the new check name (Test / Build & Test).