summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--.coderabbit.yaml1
-rw-r--r--.github/mergify.yml14
-rw-r--r--.github/workflows/check-stale.yml1
-rw-r--r--.github/workflows/codeql.yml30
4 files changed, 40 insertions, 6 deletions
diff --git a/.coderabbit.yaml b/.coderabbit.yaml
index 3afcc3b7..79e07c5b 100644
--- a/.coderabbit.yaml
+++ b/.coderabbit.yaml
@@ -26,4 +26,5 @@ knowledge_base:
# source where it is not.
usage: auto
project_keys:
+ - NOS
- VD
diff --git a/.github/mergify.yml b/.github/mergify.yml
index 4680cdfa..8636de9c 100644
--- a/.github/mergify.yml
+++ b/.github/mergify.yml
@@ -25,10 +25,12 @@ pull_request_rules:
- name: Flag product T-ID format violation in PR title or commit messages
description: >
Product-repo convention: PR title and every commit's first line must
- match `T<digits>: <text>` (optional `scope: ` prefix). Relocated from
- the central config (T8966) so the T-ID convention is opt-in per product
- repo. Name is intentionally distinct from any central rule name so this
- stays additive (not an `extends:` override).
+ match a `T<digits>:`, `NOS-<digits>:` or legacy `VD-<digits>:` task key
+ followed by text (optional `scope: ` prefix). NOS is the renamed VD Jira
+ project (2026-07). Relocated from the central config (T8966) so the T-ID
+ convention is opt-in per product repo. Name is intentionally distinct
+ from any central rule name so this stays additive (not an `extends:`
+ override).
conditions:
- '-closed'
- '-merged'
@@ -36,10 +38,10 @@ pull_request_rules:
- 'author!=copilot-swe-agent'
- 'author!=vyosbot'
- or:
- - '-title~=^(([a-zA-Z0-9\-_.]+:\s)?)T\d+:\s+[^\s]+.*'
+ - '-title~=^(([a-zA-Z0-9\-_.]+:[ ])?)(T[0-9]+|NOS-[0-9]+|VD-[0-9]+):[ ]+[^\s]+.*'
- and:
- 'label!=legacy'
- - 'commits[*].commit_message~=^(?!(([a-zA-Z0-9\-_.]+:\s)?)T\d+:\s+[^\s]+).*'
+ - 'commits[*].commit_message~=^(?!(([a-zA-Z0-9\-_.]+:[ ])?)(T[0-9]+|NOS-[0-9]+|VD-[0-9]+):[ ]+[^\s]+).*'
actions:
label:
toggle:
diff --git a/.github/workflows/check-stale.yml b/.github/workflows/check-stale.yml
index 1b173f50..e47e6ee0 100644
--- a/.github/workflows/check-stale.yml
+++ b/.github/workflows/check-stale.yml
@@ -4,6 +4,7 @@ on:
- cron: "0 0 * * *"
permissions:
+ issues: write
pull-requests: write
contents: read
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
new file mode 100644
index 00000000..9304b354
--- /dev/null
+++ b/.github/workflows/codeql.yml
@@ -0,0 +1,30 @@
+name: "Perform CodeQL Analysis"
+
+on:
+ push:
+ branches:
+ - rolling
+ paths:
+ - '**'
+ - '!.github/**'
+ - '!**/*.md'
+ pull_request:
+ branches:
+ - rolling
+ paths:
+ - '**'
+ - '!.github/**'
+ - '!**/*.md'
+ schedule:
+ - cron: '31 10 * * 0'
+
+permissions:
+ actions: read
+ contents: read
+ security-events: write
+
+jobs:
+ codeql-analysis-call:
+ uses: vyos/.github/.github/workflows/codeql-analysis.yml@production
+ with:
+ languages: "['python']"