summaryrefslogtreecommitdiff
path: root/.github
diff options
context:
space:
mode:
Diffstat (limited to '.github')
-rw-r--r--.github/mergify.yml26
-rw-r--r--.github/workflows/codecoverage.yml2
-rw-r--r--.github/workflows/codeql.yml30
3 files changed, 45 insertions, 13 deletions
diff --git a/.github/mergify.yml b/.github/mergify.yml
index 43353ea4..1cb5bb73 100644
--- a/.github/mergify.yml
+++ b/.github/mergify.yml
@@ -7,16 +7,18 @@ pull_request_rules:
- name: Flag product T-ID format violation in PR title or commit messages
description: >
Product-repo convention: the PR title AND every commit's first line must
- match `T<digits>: <text>` (optional `scope: ` prefix). The title is always
- checked; the per-commit check is exempted when a maintainer applies the
- `legacy` label — an escape hatch for grandfathered PRs whose commit history
- cannot be rewritten (repos that squash-merge AND block force-push, e.g.
- vyos.vyos enforces `non_fast_forward` on ~ALL branches with zero bypass).
- New PRs are still nudged toward the convention; `legacy` is the deliberate,
- maintainer-controlled opt-out. Relocated from the central config (T8966)
- so the convention is opt-in per product repo. Name is intentionally
- distinct from any central rule name so this stays additive (not an
- `extends:` override). Legacy-label escape added 2026-06-08 (T8966).
+ match a `T<digits>:`, `NOS-<digits>:` or legacy `VD-<digits>:` task key
+ followed by text (optional `scope: ` prefix). NOS is the renamed VD Jira
+ project (2026-07). The title is always checked; the per-commit check is
+ exempted when a maintainer applies the `legacy` label — an escape hatch for
+ grandfathered PRs whose commit history cannot be rewritten (repos that
+ squash-merge AND block force-push, e.g. vyos.vyos enforces
+ `non_fast_forward` on ~ALL branches with zero bypass). New PRs are still
+ nudged toward the convention; `legacy` is the deliberate,
+ maintainer-controlled opt-out. Relocated from the central config (T8966) so
+ the convention is opt-in per product repo. Name is intentionally distinct
+ from any central rule name so this stays additive (not an `extends:`
+ override). Legacy-label escape added 2026-06-08 (T8966).
conditions:
- '-closed'
- '-merged'
@@ -24,10 +26,10 @@ pull_request_rules:
- 'author!=copilot-swe-agent'
- 'author!=vyosbot'
- or:
- - '-title~=^(([a-zA-Z0-9\-_.]+:\s)?)T\d+:\s+[^\s]+.*'
+ - '-title~=^(([a-zA-Z0-9\-_.]+:[ ])?)(T[0-9]+|NOS-[0-9]+|VD-[0-9]+):[ ]+[^\s]+.*'
- and:
- 'label!=legacy'
- - 'commits[*].commit_message~=^(?!(([a-zA-Z0-9\-_.]+:\s)?)T\d+:\s+[^\s]+).*'
+ - 'commits[*].commit_message~=^(?!(([a-zA-Z0-9\-_.]+:[ ])?)(T[0-9]+|NOS-[0-9]+|VD-[0-9]+):[ ]+[^\s]+).*'
actions:
label:
toggle:
diff --git a/.github/workflows/codecoverage.yml b/.github/workflows/codecoverage.yml
index ee71e179..5f8945d8 100644
--- a/.github/workflows/codecoverage.yml
+++ b/.github/workflows/codecoverage.yml
@@ -29,7 +29,7 @@ jobs:
fetch-depth: "0"
- name: Set up Python ${{ env.python_version }}
- uses: actions/setup-python@v6
+ uses: actions/setup-python@v7
with:
python-version: ${{ env.python_version }}
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
new file mode 100644
index 00000000..b83b94e0
--- /dev/null
+++ b/.github/workflows/codeql.yml
@@ -0,0 +1,30 @@
+name: "Perform CodeQL Analysis"
+
+on:
+ push:
+ branches:
+ - main
+ paths:
+ - '**'
+ - '!.github/**'
+ - '!**/*.md'
+ pull_request:
+ branches:
+ - main
+ paths:
+ - '**'
+ - '!.github/**'
+ - '!**/*.md'
+ schedule:
+ - cron: '52 13 * * 0'
+
+permissions:
+ actions: read
+ contents: read
+ security-events: write
+
+jobs:
+ codeql-analysis-call:
+ uses: vyos/.github/.github/workflows/codeql-analysis.yml@production
+ with:
+ languages: "['python']"