Skip to content

ci: apply the repository settings with the action itself - #72

Merged
030 merged 6 commits into
mainfrom
ci-apply-settings-with-action
Oct 10, 2026
Merged

030 merged 6 commits into
mainfrom
ci-apply-settings-with-action

Conversation

@sbp-bvanb

@sbp-bvanb sbp-bvanb commented Oct 10, 2026 •

Copy link
Copy Markdown
Collaborator

Why

The general workflow on #61 fails before linting anything:

The actions lycheeverse/lychee-action@e747777… and DavidAnson/markdownlint-cli2-action@21c1be1… are not allowed in 030/settings-action because all actions must be from a repository owned by 030, created by GitHub, or match one of the patterns: 030/*, schubergphilis/*, zizmorcore/zizmor-action@*.

mcvs-general-action v0.7.x runs those two actions as nested actions. This repository's allowed-actions policy is exactly what this action manages, so instead of changing it by hand, the repository now applies its own settings with its own action.yml.

What

New .github/workflows/settings.yml:

  • Runs uses: ./ (this repository's action.yml) on push to main, daily at 06:42 UTC and on workflow_dispatch. It does not run on pull_request, so pull requests (including ones from forks) never run with the admin token. workflow_dispatch can still be started from any branch by anyone with write access, using that branch's workflow and action with SETTINGS_ACTION; that is no wider than today, since the repository secret is already available to push-triggered workflows on any branch. Restricting the secret to main would need an environment with a deployment-branch rule, which is a repository-settings change outside this PR.
  • Authenticates with the existing SETTINGS_ACTION secret (the same secret the earlier self-run workflow used before 05c21ce).
  • Adds lycheeverse/lychee-action@* and davidanson/markdownlint-cli2-action@* to the allowed patterns. SHA pinning stays required.
  • Sets everything else to the current repository state: description, merge options, tabs, topics, selected actions with GitHub-owned allowed and verified creators not allowed.
  • Leaves branch protection unmanaged (settings_protect_main_branch: false).
  • Pins click to click==8.5.0 in pyproject.toml (which pip install .[dev] in python.yml also picks up) and compiles it into a hashed requirements.txt. action.yml now installs that file itself, with --require-hashes, into a private venv in RUNNER_TEMP, and runs main.py with that venv's Python. Before, main.py imported click but the action never installed it, so a caller copying the bare Quickstart step could hit ModuleNotFoundError; the settings workflow therefore needs no setup-python or install step of its own. No build backend runs in the job that holds the admin token.
  • Moves the README's inputs table and testing notes to docs/, leaving a Quickstart (with the example pinned to the v0.10.1 SHA, since the example itself requires SHA pinning) and a Documentation section. Not needed for the CI fix, but small enough to do here rather than in a follow-up PR.

Check before merging

  • Default workflow permissions are set to read and "workflows can approve PRs" to false. These could not be read with a non-admin token; if they differ today, the first run changes them.
  • SETTINGS_ACTION must still be a valid token with admin rights on this repository.

After merging

The push to main applies the new allow-list. Then re-run the general checks on #61. The same allow-list change is probably needed for 030/gomod-go-version-updater-action, whose general and PR-validation workflows end in startup_failure.

yamllint and actionlint pass locally.

🤖 Generated with Claude Code

Run action.yml against this repository on push to main, daily and on
demand, using the SETTINGS_ACTION secret. The allowed-actions patterns
now include lycheeverse/lychee-action and
davidanson/markdownlint-cli2-action, which mcvs-general-action v0.7.x
runs as nested actions; without them the general workflow in #61 fails.

All other settings match the current repository state. Branch
protection is left unmanaged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@sbp-bvanb sbp-bvanb left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 pr-reviewer report

Verdict: ⚠️ Approved with comments

Adds .github/workflows/settings.yml, which runs this repository's own action.yml with the SETTINGS_ACTION admin token on push to main, daily and on manual dispatch, and adds lycheeverse/lychee-action@* and davidanson/markdownlint-cli2-action@* to the allowed-actions patterns to unblock #61.

Should fix

  • [security] .github/workflows/settings.yml:23-28: pip install . installs click unpinned, and it runs in the step that holds the admin token (inline comment).

Checks

  • Git: pass (Conventional Commits title and commit; description explains why and matches the diff; SETTINGS_ACTION was used by the workflow removed in 05c21ce; description, merge options, tabs and topics match the live repository)
  • Correctness: pass (every with: key exists in action.yml; branch protection skipped; no pull_request trigger, so unmerged code never runs with the token)
  • Security: one finding (above); persist-credentials: false, permissions: contents: read, secret scoped to the action step
  • Not verifiable with a non-admin token: current default_workflow_permissions and can_approve_pull_request_reviews (the first run sets read / false)

🤖 doc-reviewer report

Verdict: ⚠️ No findings from this diff

The root README layout (no ## Quickstart, inputs table and Testing inline, no docs/) predates this PR and is tracked in #69.

🤖 dependency-reviewer report

Verdict: ✅ Approved

actions/checkout@… # v7.0.1 (line 17) and actions/setup-python@… # v7.0.0 (line 20) are the latest stable releases and their SHAs match the tags.

🤖 github-actions-reviewer report

Verdict: ✅ Approved

Both external actions are pinned to full SHAs with exact-release comments; ./ (line 26) is a local action.

⚠️ CI (observed by the steward, not a reviewer finding)

The mcvs-general-action (yamllint) check fails on this head commit, and the other lint jobs were cancelled:

  • .github/workflows/settings.yml:8:13 [quoted-strings] string value is redundantly quoted with double quotes
  • .github/workflows/settings.yml:30:24 [quoted-strings] string value is redundantly quoted with double quotes
  • .github/workflows/settings.yml:37:46 [quoted-strings] string value is redundantly quoted with double quotes

Drop the quotes on those three values. Line 37 contains *, so check that the unquoted value still parses as a plain string (it does when it doesn't start with *).


Generated by mcvs_review 3.1.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 6a9dd56.

Comment thread .github/workflows/settings.yml Outdated
The settings workflow installs the project in the step before the
action runs with the admin SETTINGS_ACTION token, so click is now pinned
to an exact version instead of taking whatever PyPI serves. Dependabot's
pip-all group keeps the pin current.

yamllint's quoted-strings rule flagged three redundantly quoted values;
they parse to the same strings without quotes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@sbp-bvanb sbp-bvanb left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 pr-reviewer report

Verdict: ❌ Changes requested

Adds the settings workflow that runs this repository's own action.yml (push to main, daily, manual dispatch) with SETTINGS_ACTION, adds lychee-action and markdownlint-cli2-action to the allowed-actions patterns, and pins click to 8.5.0.

Blocking

  • [git] PR description: it does not mention the change at pyproject.toml:10 (dependencies = ["click"] → ["click==8.5.0"]). That changes the runtime dependency for every pip install ., including python.yml, so it is a significant change. Add a bullet to "What" saying click is pinned to 8.5.0 and why (the install runs right before the step that holds the admin token).

Checks

  • Git: fail (description omits the click pin); title and both commits follow Conventional Commits
  • Correctness: pass (every input exists in action.yml; values match the readable live settings; branch protection skipped; SETTINGS_ACTION matches the self-run workflow removed in 05c21ce)
  • Security: pass (no pull_request trigger, persist-credentials: false, contents: read, SHA-pinned actions, SHA pinning stays required; click now pinned)
  • CI: pass (all 8 check runs succeeded on 5bc83bf)
  • Not verifiable with a non-admin token: current actions permissions, default workflow permissions and can_approve_pull_request_reviews (already called out in the description)

🤖 doc-reviewer report

Verdict: ⚠️ No findings from this diff

The root README layout (no ## Quickstart, inputs table and Testing inline, no docs/) predates this PR and is tracked in #69.

🤖 dependency-reviewer report

Verdict: ⚠️ Approved with comments

Every pin this PR adds is current: click==8.5.0, actions/checkout@… # v7.0.1, actions/setup-python@… # v7.0.0.

Should fix (lines not changed by this PR)

  • [outdated] pyproject.toml:15: coverage 7.15.2 → 7.16.2
  • [outdated] pyproject.toml:16: mypy 2.3.0 → 2.4.0
  • [outdated] pyproject.toml:19: types-requests 2.33.0.20260712 → 2.33.0.20261006
  • [outdated] pyproject.toml:20: validate-pyproject 0.25 → 0.26

These are tracked in #70 and are what Dependabot's #60 updates; no need to change them here.

🤖 github-actions-reviewer report

Verdict: ✅ Approved

actions/checkout and actions/setup-python are pinned to full SHAs with exact-release comments; ./ is a local action.

Resolved since the last review

  • .github/workflows/settings.yml:23 unpinned click: fixed in 5bc83bf.
  • CI yamllint quoted-strings failures: fixed in 5bc83bf (yamllint passes).

Generated by mcvs_review 3.1.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 5bc83bf.

@sbp-bvanb sbp-bvanb left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 pr-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 5bc83bf | Commits: 2 | Files: 2
Verdict: ❌ Changes requested

Adds a settings workflow that runs this repository's own action.yml against 030/settings-action with the admin SETTINGS_ACTION token, adds lychee-action and markdownlint-cli2-action to the allowed-actions patterns, and pins click in pyproject.toml.

Blocking

  • [git] PR description: it leaves out a significant change. Commit 5bc83bf changes pyproject.toml:10 from click to click==8.5.0. Add a bullet to "What" saying that click is pinned, and why: it gets installed in the job that holds the admin token.
  • [pinning] pyproject.toml:10 / .github/workflows/settings.yml:24: click==8.5.0 is pinned by version only, with no hash or lock file, and pip install . builds the project with unpinned build requirements (setuptools, setuptools-git-versioning), running build-backend code right before the step that gets GH_TOKEN: ${{ secrets.SETTINGS_ACTION }}. action.yml calls python3 "$ACTION_PATH/main.py" directly, so only click is needed. Fix: uv pip compile pyproject.toml --generate-hashes -o requirements.txt and pip install --require-hashes -r requirements.txt.

Checks

  • Git: fail (PR description leaves out the click pin)
  • Final newline: pass
  • Pinning: fail (see above)
  • Correctness: pass
  • Security: pass, apart from the pinning finding (permissions: contents: read, persist-credentials: false, admin token limited to the uses: ./ step)
  • Over-engineering: pass
  • N/A: Terraform, Chef, Docker, Claude plugins

🤖 doc-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 5bc83bf | Docs: 0
Verdict: ❌ Changes requested

The root README has no ## Quickstart, and it holds the inputs reference and the testing notes that belong in docs/. This PR does not touch the README; the problems were already there.

Blocking

  • [quickstart] README.md:10: no ## Quickstart section. Rename ## Usage to ## Quickstart and keep only the steps a reader needs: add the workflow, create the token, store the secret.
  • [lean] README.md:52: the inputs table (lines 52-76) is reference material. Move it to docs/inputs.md and link it.
  • [lean] README.md:81: the Testing section does not belong in the README. Move it to docs/testing.md and link it.
  • [lean] README.md:10: once the content above moves, add a section (for example ## Documentation) linking the docs/ pages.

Checks

  • README: pass
  • Quickstart: fail
  • Lean: fail
  • docs/ linked: pass (0 pages)
  • Links: pass (2 checked)

🤖 dependency-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 5bc83bf | Dependencies: 10
Verdict: ⚠️ Approved with comments

Should fix

  • [outdated] pyproject.toml:15: coverage==7.15.2, latest 7.16.2.
  • [outdated] pyproject.toml:16: mypy==2.3.0, latest 2.4.0.
  • [outdated] pyproject.toml:19: types-requests==2.33.0.20260712, latest 2.33.0.20261006.
  • [outdated] pyproject.toml:20: validate-pyproject==0.25, latest 0.26.

Checks

  • Up to date: 6 (actions/checkout v7.0.1, actions/setup-python v7.0.0, click==8.5.0, mypy-extensions==1.1.0, pytest-cov==7.1.0, fastjsonschema<2.23)
  • Outdated: 4
  • Dependabot: no finding (both ecosystems covered with cooldown and groups)

🤖 github-actions-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 5bc83bf | Actions: 3
Verdict: ✅ Approved

Checks

  • Pinning: pass (actions/checkout, actions/setup-python on full SHAs; uses: ./ local)
  • Version comments: pass (2 verified)

Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 5bc83bf.

Comment thread pyproject.toml
- Install main.py's only dependency with `pip install --require-hashes -r
  requirements.txt` instead of `pip install .`, so no unpinned build
  backend runs in the job that holds the admin token.
- Bump coverage, mypy, types-requests and validate-pyproject.
- Rename Usage to Quickstart and move the inputs table and testing notes
  to docs/.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@sbp-bvanb sbp-bvanb left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 pr-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 8e09c46 | Commits: 3 | Files: 6
Verdict: ⚠️ Approved with comments

Adds a settings workflow that runs this repo's own action.yml on itself on push to main, daily and on demand. It adds lycheeverse/lychee-action@* and davidanson/markdownlint-cli2-action@* to the allowed-actions list, installs click from a hashed requirements.txt, bumps the dev pins and moves the inputs table and testing notes from the README to docs/.

Nits

  • [docs] README.md:14: the Quickstart example is YAML, but its code block is tagged bash. Change the tag to yaml.
  • [scope] pyproject.toml:15-20: the dev pin bumps and the docs move are unrelated to the CI fix, and the description gives no reason for the bumps. Move them to their own PR or add a one-line reason.

Checks

  • Git: pass
  • Final newline: pass (6 files)
  • Pinning: pass (click==8.5.0 in a hashed requirements.txt; both hashes match PyPI)
  • Correctness: pass (settings match the live repo; settings_protect_main_branch: false skips branch protection; allow-list covers every action the workflows use)
  • Security: pass (no pull_request trigger; SETTINGS_ACTION only passed to the ./ step; contents: read, persist-credentials: false; SHA pinning stays required)
  • Maintainability: pass
  • Over-engineering: pass
  • N/A: Terraform, Chef, Docker, Claude plugins

🤖 doc-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 8e09c46 | Docs: 2
Verdict: ✅ Approved

Checks

  • README: pass
  • Quickstart: pass (README.md:10)
  • Lean: pass
  • docs/ linked: pass (2 pages: docs/inputs.md, docs/testing.md)
  • Links: pass (5 checked)

🤖 dependency-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 8e09c46 | Dependencies: 9
Verdict: ✅ Approved

Checks

  • Up to date: 9 (actions/checkout v7.0.1, actions/setup-python v7.0.0, click==8.5.0 in requirements.txt and pyproject.toml, coverage==7.16.2, mypy==2.4.0, mypy-extensions==1.1.0, pytest-cov==7.1.0, types-requests==2.33.0.20261006, validate-pyproject==0.26)
  • Outdated: 0
  • Dependabot: github-actions and pip entries at / cover the changed files, both with cooldown and groups

🤖 github-actions-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 8e09c46 | Actions: 3
Verdict: ✅ Approved

Checks

  • Pinning: pass (actions/checkout, actions/setup-python on full SHAs; uses: ./ local)
  • Version comments: pass (2 verified)
  • Version precision: pass

Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 8e09c46.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@sbp-bvanb sbp-bvanb left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 pr-reviewer report

Branch: ci-apply-settings-with-action → main | Head: fec5903 | Commits: 4 | Files: 6
Verdict: ❌ Changes requested

The PR adds a settings workflow that runs this repo's own action.yml against itself with the SETTINGS_ACTION token, adding lycheeverse/lychee-action@* and davidanson/markdownlint-cli2-action@* to the allowed actions. It also installs click from a hashed requirements.txt, bumps four dev pins and moves README content into docs/.

Blocking

  • [pinning] pyproject.toml:15-20: the diff changes four dev dependencies (coverage==7.16.2, mypy==2.4.0, types-requests==2.33.0.20261006, validate-pyproject==0.26), but no lock file or hashed file covers them; requirements.txt is compiled without --extra dev, and python.yml installs them with pip install .[dev], so their transitive dependencies are unpinned. Either drop the dev bumps from this PR (the description says the CI fix doesn't need them), or compile uv pip compile pyproject.toml --extra dev --generate-hashes -o requirements-dev.txt and install it in python.yml with --require-hashes.

Nits

  • [docs] README.md:25: the Quickstart uses 030/settings-action@v0.8.0; the latest release is v0.10.1, and with settings_actions_require_sha_pinning: true a tag reference would not run. Use 030/settings-action@<sha> # v0.10.1.

Checks

  • Git: pass
  • Final newline: pass
  • Pinning: fail (dev extras in pyproject.toml); click==8.5.0 and both hashes in requirements.txt match PyPI
  • Correctness: pass
  • Security: pass (admin token never used on pull_request; persist-credentials: false, contents: read)
  • Maintainability: pass
  • Over-engineering: pass
  • N/A: Terraform, Chef, Docker, Claude plugins

🤖 doc-reviewer report

Branch: ci-apply-settings-with-action → main | Head: fec5903 | Docs: 2
Verdict: ✅ Approved

Checks

  • README: pass
  • Quickstart: pass
  • Lean: pass
  • docs/ linked: pass (2 pages)
  • Links: pass (5 checked)

🤖 dependency-reviewer report

Branch: ci-apply-settings-with-action → main | Head: fec5903 | Dependencies: 10
Verdict: ✅ Approved

Checks

  • Up to date: 10
  • Outdated: 0
  • Dependabot: .github/workflows/settings.yml and requirements.txt covered by the existing directory: / entries, both with cooldown and groups

🤖 github-actions-reviewer report

Branch: ci-apply-settings-with-action → main | Head: fec5903 | Actions: 3
Verdict: ✅ Approved

Checks

  • Pinning: pass
  • Version comments: pass (2 verified)

Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit fec5903.

Comment thread pyproject.toml Outdated
The dev pin bumps are not needed for the CI fix and are not covered by
a hashed file, so leave them to Dependabot.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@sbp-bvanb sbp-bvanb left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 pr-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Commits: 5 | Files: 6
Verdict: ❌ Changes requested

Adds a settings workflow that runs this repo's own action.yml with the SETTINGS_ACTION admin token, so it can allow lycheeverse/lychee-action@* and davidanson/markdownlint-cli2-action@*. It also pins click through a hashed requirements.txt and moves the README's inputs table and testing notes into docs/.

Blocking

  • [git/description] .github/workflows/settings.yml:9: the description says the workflow "does not run on pull_request, so unmerged code never runs with the admin token". That is not true: workflow_dispatch lets anyone with write access pick any branch, and the run then uses that branch's settings.yml and ./ action with SETTINGS_ACTION. (The repo secret is already available to any push-triggered workflow on any branch, so this is not a new escalation, but the claim is wrong.) Either correct the description, or make the claim true by moving SETTINGS_ACTION into an environment whose deployment branches are limited to main and setting environment: on the job.

Checks

  • Git: fail (description claim above)
  • Final newline: pass
  • Pinning: pass
  • Correctness: pass (inputs exist in action.yml; values match the live repo; Quickstart SHA is the v0.10.1 tag)
  • Security: pass, apart from the dispatch point above
  • Maintainability/docs: pass
  • Over-engineering: pass
  • N/A: Terraform, Chef, Docker, Claude plugins

🤖 doc-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Docs: 2
Verdict: ✅ Approved

Checks

  • README: pass
  • Quickstart: pass
  • Lean: pass
  • docs/ linked: pass (2 pages)
  • Links: pass (5 checked)

🤖 dependency-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Dependencies: 10
Verdict: ⚠️ Approved with comments

Should fix

  • [outdated] pyproject.toml:15: coverage==7.15.2, latest 7.16.2.
  • [outdated] pyproject.toml:16: mypy==2.3.0, latest 2.4.0.
  • [outdated] pyproject.toml:19: types-requests==2.33.0.20260712, latest 2.33.0.20261006.
  • [outdated] pyproject.toml:20: validate-pyproject==0.25, latest 0.26.

Checks

  • Up to date: 6
  • Outdated: 4
  • Dependabot: settings.yml and requirements.txt covered by the existing entries, both with cooldown and groups

🤖 github-actions-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Actions: 3
Verdict: ✅ Approved

Checks

  • Pinning: pass
  • Version comments: pass (2 verified)

Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 9a856d4.

Comment thread .github/workflows/settings.yml

@sbp-bvanb sbp-bvanb left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 pr-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Commits: 5 | Files: 6
Verdict: ⚠️ Approved with comments

Adds a settings workflow that applies this repository's own settings through uses: ./, allowing lycheeverse/lychee-action@* and davidanson/markdownlint-cli2-action@*; installs click from a hashed requirements.txt; moves the README's inputs table and testing notes to docs/.

Should fix

  • [docs] README.md:25: this PR's own workflow has to install click before the action runs (.github/workflows/settings.yml:23-25), because the action runs python3 "$ACTION_PATH/main.py" and main.py imports click (also at the pinned v0.10.1 SHA, action.yml:187). The Quickstart has only the bare uses: step, so someone who copies it can hit ModuleNotFoundError: click. Add the setup-python and pip install --require-hashes -r requirements.txt steps to the Quickstart, or install the dependency inside action.yml.

Nits

  • [git] PR description: mention that pyproject.toml:10 changes click to click==8.5.0, which also affects pip install .[dev] in python.yml.

Checks

  • Git: pass
  • Final newline: pass
  • Pinning: pass (both requirements.txt hashes match PyPI for click 8.5.0)
  • Correctness: pass (inputs exist in action.yml; values match the live repo; README SHA is the v0.10.1 tag)
  • Security: pass (no pull_request trigger; contents: read; persist-credentials: false; the workflow_dispatch exposure is described in the PR)
  • Over-engineering: see the README finding
  • N/A: Terraform, Chef, Docker, Claude plugins

🤖 doc-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Docs: 2
Verdict: ✅ Approved

Checks

  • README: pass
  • Quickstart: pass (README.md:10)
  • Lean: pass
  • docs/ linked: pass (2 pages)
  • Links: pass (5 checked)

🤖 dependency-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Dependencies: 9
Verdict: ⚠️ Approved with comments

Should fix

  • [outdated] pyproject.toml:15: coverage==7.15.2, latest 7.16.2.
  • [outdated] pyproject.toml:16: mypy==2.3.0, latest 2.4.0.
  • [outdated] pyproject.toml:19: types-requests==2.33.0.20260712, latest 2.33.0.20261006.
  • [outdated] pyproject.toml:20: validate-pyproject==0.25, latest 0.26.

Checks

  • Up to date: 5
  • Outdated: 4
  • Dependabot: settings.yml and requirements.txt covered by the existing entries, with cooldown and groups

🤖 github-actions-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Actions: 3
Verdict: ✅ Approved

Checks

  • Pinning: pass
  • Version comments: pass (2 verified)
  • Version precision: pass

Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 9a856d4.

Comment thread README.md
main.py imports click, but the action never installed it, so a caller
that copies the bare Quickstart step can hit ModuleNotFoundError. The
action now creates a private venv in RUNNER_TEMP and installs
requirements.txt with --require-hashes, so callers need no extra steps
and their Python is left alone. The settings workflow no longer needs
its own setup-python and install steps.

requirements.txt is recompiled with --universal.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@sbp-bvanb sbp-bvanb left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 pr-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 46a5937 | Commits: 6 | Files: 7
Verdict: ⚠️ Approved with comments

The PR adds a settings workflow that runs this repository's own action.yml against itself, adding lychee-action and markdownlint-cli2-action to the allowed actions. It makes the action install click from a hashed requirements.txt into its own venv, and moves the inputs table and testing notes from the README to docs/.

Nits

  • [docs] README.md:27: the Quickstart pins a27696394dd22683f19303883d8ef275b7287e83 # v0.10.1, which matches the tag, but that release doesn't have the new venv/click install step, so the bare Quickstart can still hit ModuleNotFoundError; Dependabot won't update a pin inside a README. Bump the pin to the first release that contains this change once it is tagged.
  • [readability] action.yml:132: the new install step is the only step in runs.steps with no blank line before the next step. Add a blank line after line 132.

Checks

  • Git: pass
  • Final newline: pass
  • Pinning: pass (requirements.txt hashes match PyPI's sdist and wheel for click 8.5.0; actions/checkout pinned by SHA)
  • Correctness: pass
  • Security: pass (no pull_request trigger; persist-credentials: false; contents: read; no build backend in the job that holds the admin token)
  • Over-engineering: pass
  • N/A: Terraform, Chef, Docker, Claude plugins

🤖 doc-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 46a5937 | Docs: 2
Verdict: ✅ Approved

Checks

  • README: pass
  • Quickstart: pass (README.md:10)
  • Lean: pass
  • docs/ linked: pass (2 pages)
  • Links: pass (5 checked)

🤖 dependency-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 46a5937 | Dependencies: 9
Verdict: ⚠️ Approved with comments

Should fix

  • [outdated] pyproject.toml:15: coverage==7.15.2, latest 7.16.2.
  • [outdated] pyproject.toml:16: mypy==2.3.0, latest 2.4.0.
  • [outdated] pyproject.toml:19: types-requests==2.33.0.20260712, latest 2.33.0.20261006.
  • [outdated] pyproject.toml:20: validate-pyproject==0.25, latest 0.26.

Checks

  • Up to date: 5
  • Outdated: 4
  • Dependabot: settings.yml and requirements.txt covered by the existing entries, with cooldown and groups

🤖 github-actions-reviewer report

Branch: ci-apply-settings-with-action → main | Head: 46a5937 | Actions: 2
Verdict: ✅ Approved

Checks

  • Pinning: pass (actions/checkout on a full SHA; uses: ./ local)
  • Version comments: pass (1 verified)
  • Version precision: pass

Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 46a5937.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants