Repository navigation
ci: apply the repository settings with the action itself - #72
Conversation
Run action.yml against this repository on push to main, daily and on demand, using the SETTINGS_ACTION secret. The allowed-actions patterns now include lycheeverse/lychee-action and davidanson/markdownlint-cli2-action, which mcvs-general-action v0.7.x runs as nested actions; without them the general workflow in #61 fails. All other settings match the current repository state. Branch protection is left unmanaged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sbp-bvanb
left a comment
There was a problem hiding this comment.
🤖 pr-reviewer report
Verdict:
Adds .github/workflows/settings.yml, which runs this repository's own action.yml with the SETTINGS_ACTION admin token on push to main, daily and on manual dispatch, and adds lycheeverse/lychee-action@* and davidanson/markdownlint-cli2-action@* to the allowed-actions patterns to unblock #61.
Should fix
- [security]
.github/workflows/settings.yml:23-28:pip install .installsclickunpinned, and it runs in the step that holds the admin token (inline comment).
Checks
- Git: pass (Conventional Commits title and commit; description explains why and matches the diff;
SETTINGS_ACTIONwas used by the workflow removed in05c21ce; description, merge options, tabs and topics match the live repository) - Correctness: pass (every
with:key exists inaction.yml; branch protection skipped; nopull_requesttrigger, so unmerged code never runs with the token) - Security: one finding (above);
persist-credentials: false,permissions: contents: read, secret scoped to the action step - Not verifiable with a non-admin token: current
default_workflow_permissionsandcan_approve_pull_request_reviews(the first run setsread/false)
🤖 doc-reviewer report
Verdict:
The root README layout (no ## Quickstart, inputs table and Testing inline, no docs/) predates this PR and is tracked in #69.
🤖 dependency-reviewer report
Verdict: ✅ Approved
actions/checkout@… # v7.0.1 (line 17) and actions/setup-python@… # v7.0.0 (line 20) are the latest stable releases and their SHAs match the tags.
🤖 github-actions-reviewer report
Verdict: ✅ Approved
Both external actions are pinned to full SHAs with exact-release comments; ./ (line 26) is a local action.
⚠️ CI (observed by the steward, not a reviewer finding)
The mcvs-general-action (yamllint) check fails on this head commit, and the other lint jobs were cancelled:
.github/workflows/settings.yml:8:13[quoted-strings] string value is redundantly quoted with double quotes.github/workflows/settings.yml:30:24[quoted-strings] string value is redundantly quoted with double quotes.github/workflows/settings.yml:37:46[quoted-strings] string value is redundantly quoted with double quotes
Drop the quotes on those three values. Line 37 contains *, so check that the unquoted value still parses as a plain string (it does when it doesn't start with *).
Generated by mcvs_review 3.1.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 6a9dd56.
The settings workflow installs the project in the step before the action runs with the admin SETTINGS_ACTION token, so click is now pinned to an exact version instead of taking whatever PyPI serves. Dependabot's pip-all group keeps the pin current. yamllint's quoted-strings rule flagged three redundantly quoted values; they parse to the same strings without quotes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sbp-bvanb
left a comment
There was a problem hiding this comment.
🤖 pr-reviewer report
Verdict: ❌ Changes requested
Adds the settings workflow that runs this repository's own action.yml (push to main, daily, manual dispatch) with SETTINGS_ACTION, adds lychee-action and markdownlint-cli2-action to the allowed-actions patterns, and pins click to 8.5.0.
Blocking
- [git] PR description: it does not mention the change at
pyproject.toml:10(dependencies = ["click"]→["click==8.5.0"]). That changes the runtime dependency for everypip install ., includingpython.yml, so it is a significant change. Add a bullet to "What" sayingclickis pinned to8.5.0and why (the install runs right before the step that holds the admin token).
Checks
- Git: fail (description omits the
clickpin); title and both commits follow Conventional Commits - Correctness: pass (every input exists in
action.yml; values match the readable live settings; branch protection skipped;SETTINGS_ACTIONmatches the self-run workflow removed in05c21ce) - Security: pass (no
pull_requesttrigger,persist-credentials: false,contents: read, SHA-pinned actions, SHA pinning stays required;clicknow pinned) - CI: pass (all 8 check runs succeeded on
5bc83bf) - Not verifiable with a non-admin token: current actions permissions, default workflow permissions and
can_approve_pull_request_reviews(already called out in the description)
🤖 doc-reviewer report
Verdict:
The root README layout (no ## Quickstart, inputs table and Testing inline, no docs/) predates this PR and is tracked in #69.
🤖 dependency-reviewer report
Verdict:
Every pin this PR adds is current: click==8.5.0, actions/checkout@… # v7.0.1, actions/setup-python@… # v7.0.0.
Should fix (lines not changed by this PR)
- [outdated]
pyproject.toml:15:coverage7.15.2 → 7.16.2 - [outdated]
pyproject.toml:16:mypy2.3.0 → 2.4.0 - [outdated]
pyproject.toml:19:types-requests2.33.0.20260712 → 2.33.0.20261006 - [outdated]
pyproject.toml:20:validate-pyproject0.25 → 0.26
These are tracked in #70 and are what Dependabot's #60 updates; no need to change them here.
🤖 github-actions-reviewer report
Verdict: ✅ Approved
actions/checkout and actions/setup-python are pinned to full SHAs with exact-release comments; ./ is a local action.
Resolved since the last review
.github/workflows/settings.yml:23unpinnedclick: fixed in 5bc83bf.- CI yamllint
quoted-stringsfailures: fixed in 5bc83bf (yamllint passes).
Generated by mcvs_review 3.1.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 5bc83bf.
sbp-bvanb
left a comment
There was a problem hiding this comment.
🤖 pr-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 5bc83bf | Commits: 2 | Files: 2
Verdict: ❌ Changes requested
Adds a settings workflow that runs this repository's own action.yml against 030/settings-action with the admin SETTINGS_ACTION token, adds lychee-action and markdownlint-cli2-action to the allowed-actions patterns, and pins click in pyproject.toml.
Blocking
- [git] PR description: it leaves out a significant change. Commit
5bc83bfchangespyproject.toml:10fromclicktoclick==8.5.0. Add a bullet to "What" saying thatclickis pinned, and why: it gets installed in the job that holds the admin token. - [pinning]
pyproject.toml:10/.github/workflows/settings.yml:24:click==8.5.0is pinned by version only, with no hash or lock file, andpip install .builds the project with unpinned build requirements (setuptools,setuptools-git-versioning), running build-backend code right before the step that getsGH_TOKEN: ${{ secrets.SETTINGS_ACTION }}.action.ymlcallspython3 "$ACTION_PATH/main.py"directly, so onlyclickis needed. Fix:uv pip compile pyproject.toml --generate-hashes -o requirements.txtandpip install --require-hashes -r requirements.txt.
Checks
- Git: fail (PR description leaves out the
clickpin) - Final newline: pass
- Pinning: fail (see above)
- Correctness: pass
- Security: pass, apart from the pinning finding (
permissions: contents: read,persist-credentials: false, admin token limited to theuses: ./step) - Over-engineering: pass
- N/A: Terraform, Chef, Docker, Claude plugins
🤖 doc-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 5bc83bf | Docs: 0
Verdict: ❌ Changes requested
The root README has no ## Quickstart, and it holds the inputs reference and the testing notes that belong in docs/. This PR does not touch the README; the problems were already there.
Blocking
- [quickstart]
README.md:10: no## Quickstartsection. Rename## Usageto## Quickstartand keep only the steps a reader needs: add the workflow, create the token, store the secret. - [lean]
README.md:52: the inputs table (lines 52-76) is reference material. Move it todocs/inputs.mdand link it. - [lean]
README.md:81: the Testing section does not belong in the README. Move it todocs/testing.mdand link it. - [lean]
README.md:10: once the content above moves, add a section (for example## Documentation) linking thedocs/pages.
Checks
- README: pass
- Quickstart: fail
- Lean: fail
- docs/ linked: pass (0 pages)
- Links: pass (2 checked)
🤖 dependency-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 5bc83bf | Dependencies: 10
Verdict:
Should fix
- [outdated]
pyproject.toml:15:coverage==7.15.2, latest7.16.2. - [outdated]
pyproject.toml:16:mypy==2.3.0, latest2.4.0. - [outdated]
pyproject.toml:19:types-requests==2.33.0.20260712, latest2.33.0.20261006. - [outdated]
pyproject.toml:20:validate-pyproject==0.25, latest0.26.
Checks
- Up to date: 6 (
actions/checkoutv7.0.1,actions/setup-pythonv7.0.0,click==8.5.0,mypy-extensions==1.1.0,pytest-cov==7.1.0,fastjsonschema<2.23) - Outdated: 4
- Dependabot: no finding (both ecosystems covered with
cooldownandgroups)
🤖 github-actions-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 5bc83bf | Actions: 3
Verdict: ✅ Approved
Checks
- Pinning: pass (
actions/checkout,actions/setup-pythonon full SHAs;uses: ./local) - Version comments: pass (2 verified)
Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 5bc83bf.
- Install main.py's only dependency with `pip install --require-hashes -r requirements.txt` instead of `pip install .`, so no unpinned build backend runs in the job that holds the admin token. - Bump coverage, mypy, types-requests and validate-pyproject. - Rename Usage to Quickstart and move the inputs table and testing notes to docs/. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sbp-bvanb
left a comment
There was a problem hiding this comment.
🤖 pr-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 8e09c46 | Commits: 3 | Files: 6
Verdict:
Adds a settings workflow that runs this repo's own action.yml on itself on push to main, daily and on demand. It adds lycheeverse/lychee-action@* and davidanson/markdownlint-cli2-action@* to the allowed-actions list, installs click from a hashed requirements.txt, bumps the dev pins and moves the inputs table and testing notes from the README to docs/.
Nits
- [docs]
README.md:14: the Quickstart example is YAML, but its code block is taggedbash. Change the tag toyaml. - [scope]
pyproject.toml:15-20: the dev pin bumps and the docs move are unrelated to the CI fix, and the description gives no reason for the bumps. Move them to their own PR or add a one-line reason.
Checks
- Git: pass
- Final newline: pass (6 files)
- Pinning: pass (
click==8.5.0in a hashedrequirements.txt; both hashes match PyPI) - Correctness: pass (settings match the live repo;
settings_protect_main_branch: falseskips branch protection; allow-list covers every action the workflows use) - Security: pass (no
pull_requesttrigger;SETTINGS_ACTIONonly passed to the./step;contents: read,persist-credentials: false; SHA pinning stays required) - Maintainability: pass
- Over-engineering: pass
- N/A: Terraform, Chef, Docker, Claude plugins
🤖 doc-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 8e09c46 | Docs: 2
Verdict: ✅ Approved
Checks
- README: pass
- Quickstart: pass (
README.md:10) - Lean: pass
- docs/ linked: pass (2 pages:
docs/inputs.md,docs/testing.md) - Links: pass (5 checked)
🤖 dependency-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 8e09c46 | Dependencies: 9
Verdict: ✅ Approved
Checks
- Up to date: 9 (
actions/checkoutv7.0.1,actions/setup-pythonv7.0.0,click==8.5.0inrequirements.txtandpyproject.toml,coverage==7.16.2,mypy==2.4.0,mypy-extensions==1.1.0,pytest-cov==7.1.0,types-requests==2.33.0.20261006,validate-pyproject==0.26) - Outdated: 0
- Dependabot:
github-actionsandpipentries at/cover the changed files, both withcooldownandgroups
🤖 github-actions-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 8e09c46 | Actions: 3
Verdict: ✅ Approved
Checks
- Pinning: pass (
actions/checkout,actions/setup-pythonon full SHAs;uses: ./local) - Version comments: pass (2 verified)
- Version precision: pass
Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 8e09c46.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sbp-bvanb
left a comment
There was a problem hiding this comment.
🤖 pr-reviewer report
Branch: ci-apply-settings-with-action → main | Head: fec5903 | Commits: 4 | Files: 6
Verdict: ❌ Changes requested
The PR adds a settings workflow that runs this repo's own action.yml against itself with the SETTINGS_ACTION token, adding lycheeverse/lychee-action@* and davidanson/markdownlint-cli2-action@* to the allowed actions. It also installs click from a hashed requirements.txt, bumps four dev pins and moves README content into docs/.
Blocking
- [pinning]
pyproject.toml:15-20: the diff changes four dev dependencies (coverage==7.16.2,mypy==2.4.0,types-requests==2.33.0.20261006,validate-pyproject==0.26), but no lock file or hashed file covers them;requirements.txtis compiled without--extra dev, andpython.ymlinstalls them withpip install .[dev], so their transitive dependencies are unpinned. Either drop the dev bumps from this PR (the description says the CI fix doesn't need them), or compileuv pip compile pyproject.toml --extra dev --generate-hashes -o requirements-dev.txtand install it inpython.ymlwith--require-hashes.
Nits
- [docs]
README.md:25: the Quickstart uses030/settings-action@v0.8.0; the latest release isv0.10.1, and withsettings_actions_require_sha_pinning: truea tag reference would not run. Use030/settings-action@<sha> # v0.10.1.
Checks
- Git: pass
- Final newline: pass
- Pinning: fail (dev extras in
pyproject.toml);click==8.5.0and both hashes inrequirements.txtmatch PyPI - Correctness: pass
- Security: pass (admin token never used on
pull_request;persist-credentials: false,contents: read) - Maintainability: pass
- Over-engineering: pass
- N/A: Terraform, Chef, Docker, Claude plugins
🤖 doc-reviewer report
Branch: ci-apply-settings-with-action → main | Head: fec5903 | Docs: 2
Verdict: ✅ Approved
Checks
- README: pass
- Quickstart: pass
- Lean: pass
- docs/ linked: pass (2 pages)
- Links: pass (5 checked)
🤖 dependency-reviewer report
Branch: ci-apply-settings-with-action → main | Head: fec5903 | Dependencies: 10
Verdict: ✅ Approved
Checks
- Up to date: 10
- Outdated: 0
- Dependabot:
.github/workflows/settings.ymlandrequirements.txtcovered by the existingdirectory: /entries, both withcooldownandgroups
🤖 github-actions-reviewer report
Branch: ci-apply-settings-with-action → main | Head: fec5903 | Actions: 3
Verdict: ✅ Approved
Checks
- Pinning: pass
- Version comments: pass (2 verified)
Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit fec5903.
The dev pin bumps are not needed for the CI fix and are not covered by a hashed file, so leave them to Dependabot. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sbp-bvanb
left a comment
There was a problem hiding this comment.
🤖 pr-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Commits: 5 | Files: 6
Verdict: ❌ Changes requested
Adds a settings workflow that runs this repo's own action.yml with the SETTINGS_ACTION admin token, so it can allow lycheeverse/lychee-action@* and davidanson/markdownlint-cli2-action@*. It also pins click through a hashed requirements.txt and moves the README's inputs table and testing notes into docs/.
Blocking
- [git/description]
.github/workflows/settings.yml:9: the description says the workflow "does not run onpull_request, so unmerged code never runs with the admin token". That is not true:workflow_dispatchlets anyone with write access pick any branch, and the run then uses that branch'ssettings.ymland./action withSETTINGS_ACTION. (The repo secret is already available to any push-triggered workflow on any branch, so this is not a new escalation, but the claim is wrong.) Either correct the description, or make the claim true by movingSETTINGS_ACTIONinto an environment whose deployment branches are limited tomainand settingenvironment:on the job.
Checks
- Git: fail (description claim above)
- Final newline: pass
- Pinning: pass
- Correctness: pass (inputs exist in
action.yml; values match the live repo; Quickstart SHA is thev0.10.1tag) - Security: pass, apart from the dispatch point above
- Maintainability/docs: pass
- Over-engineering: pass
- N/A: Terraform, Chef, Docker, Claude plugins
🤖 doc-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Docs: 2
Verdict: ✅ Approved
Checks
- README: pass
- Quickstart: pass
- Lean: pass
- docs/ linked: pass (2 pages)
- Links: pass (5 checked)
🤖 dependency-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Dependencies: 10
Verdict:
Should fix
- [outdated]
pyproject.toml:15:coverage==7.15.2, latest7.16.2. - [outdated]
pyproject.toml:16:mypy==2.3.0, latest2.4.0. - [outdated]
pyproject.toml:19:types-requests==2.33.0.20260712, latest2.33.0.20261006. - [outdated]
pyproject.toml:20:validate-pyproject==0.25, latest0.26.
Checks
- Up to date: 6
- Outdated: 4
- Dependabot:
settings.ymlandrequirements.txtcovered by the existing entries, both withcooldownandgroups
🤖 github-actions-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Actions: 3
Verdict: ✅ Approved
Checks
- Pinning: pass
- Version comments: pass (2 verified)
Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 9a856d4.
sbp-bvanb
left a comment
There was a problem hiding this comment.
🤖 pr-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Commits: 5 | Files: 6
Verdict:
Adds a settings workflow that applies this repository's own settings through uses: ./, allowing lycheeverse/lychee-action@* and davidanson/markdownlint-cli2-action@*; installs click from a hashed requirements.txt; moves the README's inputs table and testing notes to docs/.
Should fix
- [docs]
README.md:25: this PR's own workflow has to install click before the action runs (.github/workflows/settings.yml:23-25), because the action runspython3 "$ACTION_PATH/main.py"andmain.pyimports click (also at the pinnedv0.10.1SHA,action.yml:187). The Quickstart has only the bareuses:step, so someone who copies it can hitModuleNotFoundError: click. Add the setup-python andpip install --require-hashes -r requirements.txtsteps to the Quickstart, or install the dependency insideaction.yml.
Nits
- [git] PR description: mention that
pyproject.toml:10changesclicktoclick==8.5.0, which also affectspip install .[dev]inpython.yml.
Checks
- Git: pass
- Final newline: pass
- Pinning: pass (both
requirements.txthashes match PyPI for click 8.5.0) - Correctness: pass (inputs exist in
action.yml; values match the live repo; README SHA is thev0.10.1tag) - Security: pass (no
pull_requesttrigger;contents: read;persist-credentials: false; theworkflow_dispatchexposure is described in the PR) - Over-engineering: see the README finding
- N/A: Terraform, Chef, Docker, Claude plugins
🤖 doc-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Docs: 2
Verdict: ✅ Approved
Checks
- README: pass
- Quickstart: pass (
README.md:10) - Lean: pass
- docs/ linked: pass (2 pages)
- Links: pass (5 checked)
🤖 dependency-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Dependencies: 9
Verdict:
Should fix
- [outdated]
pyproject.toml:15:coverage==7.15.2, latest7.16.2. - [outdated]
pyproject.toml:16:mypy==2.3.0, latest2.4.0. - [outdated]
pyproject.toml:19:types-requests==2.33.0.20260712, latest2.33.0.20261006. - [outdated]
pyproject.toml:20:validate-pyproject==0.25, latest0.26.
Checks
- Up to date: 5
- Outdated: 4
- Dependabot:
settings.ymlandrequirements.txtcovered by the existing entries, withcooldownandgroups
🤖 github-actions-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 9a856d4 | Actions: 3
Verdict: ✅ Approved
Checks
- Pinning: pass
- Version comments: pass (2 verified)
- Version precision: pass
Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 9a856d4.
main.py imports click, but the action never installed it, so a caller that copies the bare Quickstart step can hit ModuleNotFoundError. The action now creates a private venv in RUNNER_TEMP and installs requirements.txt with --require-hashes, so callers need no extra steps and their Python is left alone. The settings workflow no longer needs its own setup-python and install steps. requirements.txt is recompiled with --universal. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sbp-bvanb
left a comment
There was a problem hiding this comment.
🤖 pr-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 46a5937 | Commits: 6 | Files: 7
Verdict:
The PR adds a settings workflow that runs this repository's own action.yml against itself, adding lychee-action and markdownlint-cli2-action to the allowed actions. It makes the action install click from a hashed requirements.txt into its own venv, and moves the inputs table and testing notes from the README to docs/.
Nits
- [docs]
README.md:27: the Quickstart pinsa27696394dd22683f19303883d8ef275b7287e83 # v0.10.1, which matches the tag, but that release doesn't have the new venv/click install step, so the bare Quickstart can still hitModuleNotFoundError; Dependabot won't update a pin inside a README. Bump the pin to the first release that contains this change once it is tagged. - [readability]
action.yml:132: the new install step is the only step inruns.stepswith no blank line before the next step. Add a blank line after line 132.
Checks
- Git: pass
- Final newline: pass
- Pinning: pass (
requirements.txthashes match PyPI's sdist and wheel for click 8.5.0;actions/checkoutpinned by SHA) - Correctness: pass
- Security: pass (no
pull_requesttrigger;persist-credentials: false;contents: read; no build backend in the job that holds the admin token) - Over-engineering: pass
- N/A: Terraform, Chef, Docker, Claude plugins
🤖 doc-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 46a5937 | Docs: 2
Verdict: ✅ Approved
Checks
- README: pass
- Quickstart: pass (
README.md:10) - Lean: pass
- docs/ linked: pass (2 pages)
- Links: pass (5 checked)
🤖 dependency-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 46a5937 | Dependencies: 9
Verdict:
Should fix
- [outdated]
pyproject.toml:15:coverage==7.15.2, latest7.16.2. - [outdated]
pyproject.toml:16:mypy==2.3.0, latest2.4.0. - [outdated]
pyproject.toml:19:types-requests==2.33.0.20260712, latest2.33.0.20261006. - [outdated]
pyproject.toml:20:validate-pyproject==0.25, latest0.26.
Checks
- Up to date: 5
- Outdated: 4
- Dependabot:
settings.ymlandrequirements.txtcovered by the existing entries, withcooldownandgroups
🤖 github-actions-reviewer report
Branch: ci-apply-settings-with-action → main | Head: 46a5937 | Actions: 2
Verdict: ✅ Approved
Checks
- Pinning: pass (
actions/checkouton a full SHA;uses: ./local) - Version comments: pass (1 verified)
- Version precision: pass
Generated by mcvs_review 3.3.0 (pr-reviewer, doc-reviewer, dependency-reviewer, github-actions-reviewer) at commit 46a5937.
Why
The
generalworkflow on #61 fails before linting anything:mcvs-general-action v0.7.x runs those two actions as nested actions. This repository's allowed-actions policy is exactly what this action manages, so instead of changing it by hand, the repository now applies its own settings with its own
action.yml.What
New
.github/workflows/settings.yml:uses: ./(this repository'saction.yml) on push tomain, daily at 06:42 UTC and onworkflow_dispatch. It does not run onpull_request, so pull requests (including ones from forks) never run with the admin token.workflow_dispatchcan still be started from any branch by anyone with write access, using that branch's workflow and action withSETTINGS_ACTION; that is no wider than today, since the repository secret is already available to push-triggered workflows on any branch. Restricting the secret tomainwould need an environment with a deployment-branch rule, which is a repository-settings change outside this PR.SETTINGS_ACTIONsecret (the same secret the earlier self-run workflow used before05c21ce).lycheeverse/lychee-action@*anddavidanson/markdownlint-cli2-action@*to the allowed patterns. SHA pinning stays required.selectedactions with GitHub-owned allowed and verified creators not allowed.settings_protect_main_branch: false).clicktoclick==8.5.0inpyproject.toml(whichpip install .[dev]inpython.ymlalso picks up) and compiles it into a hashedrequirements.txt.action.ymlnow installs that file itself, with--require-hashes, into a private venv inRUNNER_TEMP, and runsmain.pywith that venv's Python. Before,main.pyimportedclickbut the action never installed it, so a caller copying the bare Quickstart step could hitModuleNotFoundError; the settings workflow therefore needs no setup-python or install step of its own. No build backend runs in the job that holds the admin token.docs/, leaving a Quickstart (with the example pinned to thev0.10.1SHA, since the example itself requires SHA pinning) and a Documentation section. Not needed for the CI fix, but small enough to do here rather than in a follow-up PR.Check before merging
readand "workflows can approve PRs" tofalse. These could not be read with a non-admin token; if they differ today, the first run changes them.SETTINGS_ACTIONmust still be a valid token with admin rights on this repository.After merging
The push to
mainapplies the new allow-list. Then re-run thegeneralchecks on #61. The same allow-list change is probably needed for 030/gomod-go-version-updater-action, whosegeneraland PR-validation workflows end instartup_failure.yamllint and actionlint pass locally.
🤖 Generated with Claude Code