Skip to content

feat(ci): GitHub Actions 2026 ベースライン強化 + 多OSスモーク導入 - #135

Merged
Chachamaru127 merged 8 commits into
mainfrom
claude/enhance-github-actions-cicd-ag7rx
May 15, 2026
Merged

Chachamaru127 merged 8 commits into
mainfrom
claude/enhance-github-actions-cicd-ag7rx

Conversation

@Chachamaru127

@Chachamaru127 Chachamaru127 commented May 15, 2026 •

Copy link
Copy Markdown
Owner

何が変わるか(非エンジニア向け)

GitHub Actions の CI/CD を「2026年版ベストプラクティス」に揃えました。配信先(Linux/macOS/Windows 全て)で本当に動くかを毎 PR で自動検証し、サプライチェーン攻撃に耐える防御層を追加します。

Before / After

観点 Before After
アクションのバージョン指定 @v6 のような書き換え可能なタグ 40桁の SHA で固定(Trivy-action 攻撃パターンを無効化)
自動更新の仕組み なし(手動更新で漏れがち) Dependabot 週次 PR(7日 cooldown)
配信先での動作確認 Linux 1OS のみ Linux / macOS / Windows の3OS マトリクス検証
ワークフロー権限 opencode-compat は無宣言(過剰権限) 全部 contents: read 最小権限 に矯正
PR の再 push 古い実行が走り続ける 古い実行を自動キャンセル(30〜50% 時短)
YAML 文法ミス検出 実行時に初めて気づく PR で actionlint が即検出
Go セットアップ重複 3箇所に同じコード 1つの composite action に集約
セキュリティスキャン なし CodeQL + OSSF Scorecard を Security タブに公開

重要な意思決定(事前確認済み)

ユーザー回答に基づいて以下を実装:

  1. Tier 全部 + 配信先動作担保: smoke-install.yml で 3 OS マトリクス検証を毎 PR 実行
  2. Dependabot 週次自動更新: github-actions / gomod / composite action 全て対象、7 日 cooldown 付き
  3. 新規ワークフローファイル作成: codeql.yml, scorecard.yml, smoke-install.yml を追加

レビューの完璧性

実装後、以下を全て確認済み:

  • ✅ actionlint -color 全ワークフロー 0 件エラー
  • ✅ bash tests/validate-plugin.sh 既存の事前失敗 2 件(私の変更と無関係)以外の regression なし
  • ✅ bash scripts/ci/check-consistency.sh 既存の事前失敗 1 件(i18n、私の変更と無関係)以外 OK
  • ✅ harness バイナリのローカル smoke 全 PASS(version, validate skills/agents/all, doctor)
  • ✅ plugin.json と VERSION の同期確認 PASS(4.10.0)
  • ✅ 全アクションの SHA は git ls-remote で実際にタグから引いた最新リリースの commit

SHA ピン化マッピング

Action Tag Commit SHA
actions/checkout v6.0.2 de0fac2e4500dabe0009e67214ff5f5447ce83dd
actions/setup-go v6.4.0 4a3601121dd01d1626a1e23e37211e3254c1c06c
actions/setup-node v6.4.0 48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e
actions/setup-python v5.6.0 a26af69be951a213d495a4c3e4e4022e16d87065
actions/upload-artifact v4.6.2 ea165f8d65b6e75b540449e92b4886f43607fa02
github/codeql-action v4.35.5 9e0d7b8d25671d64c341c19c0152d693099fb5ba
ossf/scorecard-action v2.4.3 4eaacf0543bb3f2c246792bd56e8cdeffafb205a

影響範囲・互換性

  • 既存ワークフローの動作: 機能は完全に維持。表面的な書式変更(SHA ピン、permissions、concurrency)のみ
  • Plans.md / VERSION / plugin.json: 一切変更なし(normal PR ルール準拠)
  • 新規ワークフローの実行頻度: codeql / scorecard / smoke-install は path フィルタ付き(無関係な編集ではスキップ)

試験計画

PR をマージする前に GitHub Actions タブで確認すべきこと:

  • validate-plugin の actionlint / validate / test-go の3 ジョブが全て緑
  • smoke-install の 3 OS マトリクスが全て緑(macOS/Windows ビルドが特に重要)
  • opencode-compat が path フィルタで適切にトリガーされるか(commands/skills 編集時のみ)
  • 古い validate-plugin 実行が新 push でキャンセルされるか(concurrency 動作)
  • CodeQL / Scorecard の初回実行が Security タブにレポートされるか

参考: 検索した最新ベストプラクティス


Generated by Claude Code

Summary by CodeRabbit

  • Chores

    • 自動セキュリティスキャン(CodeQL・OSSF Scorecard)を導入しました。
    • 依存関係の週次自動更新(Dependabot)を設定しました。
    • CI ワークフローの信頼性向上:アクション固定化、最小権限化、同時実行制御、チェックアウト最適化、Go 環境セットアップの集約を適用しました。
    • リリース/検証フローのタイムアウト延長と安定化を行いました。
  • New Features

    • クロスプラットフォームのスモークテストとプラグイン検証の自動化を追加しました。
  • Documentation

    • CHANGELOG の Unreleased に CI/CD と検証フローの変更点を追記しました。

Review Change Stack

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@coderabbitai

coderabbitai Bot commented May 15, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: e0df4727-1485-491a-906c-d67a89770fc7

📥 Commits

Reviewing files that changed from the base of the PR and between 0433dc8 and 9467f13.

📒 Files selected for processing (10)
  • .github/actions/setup-go-harness/action.yml
  • .github/dependabot.yml
  • .github/workflows/benchmark.yml
  • .github/workflows/codeql.yml
  • .github/workflows/opencode-compat.yml
  • .github/workflows/release.yml
  • .github/workflows/scorecard.yml
  • .github/workflows/smoke-install.yml
  • .github/workflows/validate-plugin.yml
  • CHANGELOG.md
✅ Files skipped from review due to trivial changes (1)
  • .github/dependabot.yml
🚧 Files skipped from review as they are similar to previous changes (8)
  • .github/workflows/release.yml
  • .github/workflows/scorecard.yml
  • .github/workflows/benchmark.yml
  • .github/workflows/smoke-install.yml
  • .github/actions/setup-go-harness/action.yml
  • .github/workflows/opencode-compat.yml
  • .github/workflows/codeql.yml
  • CHANGELOG.md

Walkthrough

Go セットアップを複合アクション化し、ワークフローのアクション参照を SHA 固定に更新、Dependabot を設定、CodeQL/Scorecard のスキャンとマルチプラットフォームのスモークテストを追加しました。

Changes

GitHub Actions CI/CD インフラストラクチャ統一と強化

Layer / File(s) Summary
Go セットアップ複合アクション
.github/actions/setup-go-harness/action.yml
go/go.mod を参照して Go をセットアップし、キャッシュ依存に go/go.sum を指定する複合アクションを追加。
Dependabot 自動依存更新設定
.github/dependabot.yml
ルートワークフロー、複合アクション、/go モジュールの週次更新スケジュール、PR 上限、クールダウン、ラベル、コミット接頭辞を定義。
ワークフロー更新:アクション SHA ピン留め・checkout 最適化
.github/workflows/...
複数ワークフローで actions をコミット SHA に固定化、checkout に persist-credentials/fetch-depth/filter: blob:none を追加。
opencode-compat ワークフロー調整
.github/workflows/opencode-compat.yml
push トリガーを main に制限し、permissions/concurrency と validate ジョブの更新を適用。
benchmark ワークフロー修正
.github/workflows/benchmark.yml
actions/checkout/setup-python/upload-artifact を SHA ピン留めし、scorecard の最新ファイル選択ロジックを find ... -print0 + mtime 比較へ変更。
release ワークフロー更新
.github/workflows/release.yml
permissions/concurrency/timeout の調整、checkout 最適化、Go セットアップを ./.github/actions/setup-go-harness に切替、シェル内の VERSION 抽出を削除。
セキュリティスキャン導入
.github/workflows/codeql.yml, .github/workflows/scorecard.yml
CodeQL(Go)と OSSF Scorecard のワークフローを追加。CodeQL は init→go build→analyze、Scorecard は SARIF を生成して Code Scanning にアップロード。
マルチプラットフォームスモークテスト
.github/workflows/smoke-install.yml
Ubuntu/macOS/Windows のマトリクスでハーネスをビルド・検証(Windows は .exe)、検証ステップと VERSION/plugin.json 整合性チェックを追加。
validate-plugin ワークフロー調整
.github/workflows/validate-plugin.yml
concurrency と actionlint ジョブを追加、validate/test-go の checkout と Go セットアップを最適化して ./.github/actions/setup-go-harness を利用。
CHANGELOG 更新
CHANGELOG.md
[Unreleased] に CI/CD 関連の追加・変更・修正点を追記。

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

"🐰
設定整え、鍵をかけて進む道、
ハーネスは三つの星を越える。
スキャンは光り、依存は正しく、
CI は跳ねる、静かな朝に。"

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed PR タイトルは「feat(ci): GitHub Actions 2026 ベースライン強化 + 多OSスモーク導入」で、変更内容の中心である GitHub Actions の CI/CD 強化とマルチOS スモークテスト導入を正確に反映している。
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/enhance-github-actions-cicd-ag7rx

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a6c0ab8254

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/smoke-install.yml Outdated
Comment on lines +106 to +108
"$BIN" doctor . || {
echo "::warning::doctor reported non-zero on ${{ matrix.label }} — inspect logs above"
exit 0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Fail smoke job when doctor returns a real error

The Smoke — doctor step currently converts any non-zero exit from "$BIN" doctor . into success by logging a warning and exit 0, which means the workflow can stay green even when doctor detects an actual health regression. In a PR that breaks doctor-specific checks, this silently removes the protection this smoke workflow is meant to provide and can allow broken artifacts to pass CI.

Useful? React with 👍 / 👎.

Comment thread .github/workflows/validate-plugin.yml Outdated
filter: blob:none

- name: Run actionlint (workflow YAML lint)
uses: docker://rhysd/actionlint:1.7.12

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Pin actionlint container image by immutable digest

This introduces a mutable Docker tag (docker://rhysd/actionlint:1.7.12) in a workflow that otherwise hard-pins actions, so a retagged or compromised image could execute different code in CI without any repository change. Because this step runs on every validation workflow, pinning to a digest is needed to preserve the same supply-chain guarantees as the SHA-pinned actions.

Useful? React with 👍 / 👎.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🧹 Nitpick comments (1)
.github/actions/setup-go-harness/action.yml (1)

23-31: ⚡ Quick win

ビルド出力名のハードコードされたプラットフォーム指定を修正してください。

31行目で出力ファイル名が harness-linux-amd64 にハードコードされていますが、説明文(6行目)では「binaries」(複数形)と記述されており、複数プラットフォーム対応を示唆しています。このアクションがmacOSやWindowsで build: 'true' を指定して実行された場合、誤解を招くファイル名になります。

以下のいずれかの対応を推奨します:

  1. 未使用の場合:build 機能が実際に使われていない場合は削除する
  2. 使用される場合:$RUNNER_OS を検出して適切なファイル名を生成する
  3. Linux専用の場合:説明文を「Linux環境専用」と明記する

現時点では smoke-install.yml が独自のビルドロジック(68-78行目)を実装しており、この機能を使用していないようですが、将来の保守性向上のため明確化が必要です。

♻️ OS検出を追加する場合の提案
     - name: Build harness binary
       if: inputs.build == 'true'
       shell: bash
       working-directory: go
       env:
         OUTPUT_DIR: ${{ inputs.output-dir }}
       run: |
         mkdir -p "../${OUTPUT_DIR}"
-        go build -o "../${OUTPUT_DIR}/harness-linux-amd64" ./cmd/harness/
+        EXT=""
+        PLATFORM="${RUNNER_OS}-${RUNNER_ARCH}"
+        if [ "${RUNNER_OS}" = "Windows" ]; then
+          EXT=".exe"
+        fi
+        # Convert to lowercase and normalize (e.g., Linux->linux, macOS->darwin)
+        OS_LOWER=$(echo "${RUNNER_OS}" | tr '[:upper:]' '[:lower:]')
+        [ "$OS_LOWER" = "macos" ] && OS_LOWER="darwin"
+        go build -o "../${OUTPUT_DIR}/harness-${OS_LOWER}-${RUNNER_ARCH}${EXT}" ./cmd/harness/
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/actions/setup-go-harness/action.yml around lines 23 - 31, The build
step currently hardcodes the output filename "harness-linux-amd64" which is
misleading for non-Linux runners; update the Build harness binary step (the job
block that sets OUTPUT_DIR and runs go build) to detect $RUNNER_OS and generate
an OS/arch-appropriate output filename (or remove the step if unused) — for
example use $RUNNER_OS (and optionally $RUNNER_ARCH/GOOS/GOARCH) to compute the
filename instead of the hardcoded string, or document that this action is
Linux-only in the action description if you intend to keep a fixed name.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/codeql.yml:
- Line 41: The workflow pins for the CodeQL actions have an incorrect SHA for
github/codeql-action: locate the steps using the "uses:
github/codeql-action@..." entry and replace the current SHA commit with the
correct commit for v4.35.5 (f25eda876ebb741d872b63b9f2c6dfdd77f14b83); verify
the existing "uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd"
(actions/checkout) is already correct and leave it as-is, then open a PR to
update the protected workflow so the pinned SHAs match the intended tags.

In @.github/workflows/smoke-install.yml:
- Line 61: The workflow file .github/workflows/smoke-install.yml is protected by
deny rules and must not be edited; revert the change to the uses: line (the
modification to "uses:
actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd") so the file matches
the protected pattern again (restore the original actions/checkout reference or
remove the edit), or move any intended workflow adjustments to an allowed
location or request a repo-admin change to the protection rules instead.

In `@CHANGELOG.md`:
- Around line 9-25: Add a Before/After comparison table under the [Unreleased]
section summarizing the major CI/CD changes: list each affected item (e.g.,
"GitHub Actions サプライチェーン強化", `.github/workflows/codeql.yml`,
`.github/workflows/smoke-install.yml`, `.github/actions/setup-go-harness`,
`validate-plugin.yml`, `.github/dependabot.yml`) and show the before state and
the after state for each (for example: before: actions unpinned / no weekly
Dependabot; after: SHA-pinned actions + weekly Dependabot; before: no CodeQL;
after: CodeQL workflow added; before: no concurrency/per-job
permissions/persist-credentials; after: concurrency block added / workflow-level
permissions: contents: read / persist-credentials: false added; before:
opencode-compat branch trigger open; after: restricted to branches: [main]).
Ensure the table follows Keep a Changelog style and lives within the
[Unreleased] section so readers can quickly compare old vs new behavior.

---

Nitpick comments:
In @.github/actions/setup-go-harness/action.yml:
- Around line 23-31: The build step currently hardcodes the output filename
"harness-linux-amd64" which is misleading for non-Linux runners; update the
Build harness binary step (the job block that sets OUTPUT_DIR and runs go build)
to detect $RUNNER_OS and generate an OS/arch-appropriate output filename (or
remove the step if unused) — for example use $RUNNER_OS (and optionally
$RUNNER_ARCH/GOOS/GOARCH) to compute the filename instead of the hardcoded
string, or document that this action is Linux-only in the action description if
you intend to keep a fixed name.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: bbb2a8ff-069c-4b35-9f2c-36232d7dff5a

📥 Commits

Reviewing files that changed from the base of the PR and between 136665e and a6c0ab8.

📒 Files selected for processing (10)
  • .github/actions/setup-go-harness/action.yml
  • .github/dependabot.yml
  • .github/workflows/benchmark.yml
  • .github/workflows/codeql.yml
  • .github/workflows/opencode-compat.yml
  • .github/workflows/release.yml
  • .github/workflows/scorecard.yml
  • .github/workflows/smoke-install.yml
  • .github/workflows/validate-plugin.yml
  • CHANGELOG.md

Comment thread .github/workflows/codeql.yml
Comment thread .github/workflows/smoke-install.yml
Comment thread CHANGELOG.md

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/benchmark.yml (1)

1-195: ⚠️ Potential issue | 🔴 Critical | ⚡ Quick win

コーディングガイドライン違反: 保護対象ファイルの編集

このファイルは .github/workflows/* パスに該当し、コーディングガイドラインで編集が禁止されています。CI/CDインフラの更新が PR の目的であることは理解できますが、保護対象ファイルの変更には特別な承認プロセスや権限が必要な可能性があります。リポジトリメンテナーに確認してください。

As per coding guidelines: "Do not edit .github/workflows/*; these are protected by deny rules"

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/benchmark.yml around lines 1 - 195, This PR edits a
protected GitHub Actions workflow named "benchmark" (job "benchmark" and steps
like "Validate API Key", "Run benchmarks (with-plugin)", etc.), which violates
the rule forbidding edits to .github/workflows; revert any changes made to this
workflow file and remove it from the PR, then open an issue or contact the
repository maintainers to request the workflow change (include the intended
edits and rationale) so they can apply them via the approved process.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/benchmark.yml:
- Around line 1-195: This PR edits a protected GitHub Actions workflow named
"benchmark" (job "benchmark" and steps like "Validate API Key", "Run benchmarks
(with-plugin)", etc.), which violates the rule forbidding edits to
.github/workflows; revert any changes made to this workflow file and remove it
from the PR, then open an issue or contact the repository maintainers to request
the workflow change (include the intended edits and rationale) so they can apply
them via the approved process.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: bbb4b138-3ca0-4739-8f4b-1106665abdc2

📥 Commits

Reviewing files that changed from the base of the PR and between ad816eb and 0433dc8.

📒 Files selected for processing (4)
  • .github/actions/setup-go-harness/action.yml
  • .github/workflows/benchmark.yml
  • .github/workflows/release.yml
  • CHANGELOG.md
✅ Files skipped from review due to trivial changes (1)
  • CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • .github/workflows/release.yml

claude added 8 commits May 16, 2026 08:13
Adopt the GitHub Actions 2026 security baseline and add multi-OS delivery-
destination verification.

Security hardening
- Pin every action to a full commit SHA with version comments (defends against
  the Trivy-action March 2026 tag force-push pattern).
- Add `.github/dependabot.yml` for github-actions / gomod / composite-action
  weekly updates with a 7-day cooldown to absorb the typical compromise
  detection window.
- Add workflow-level `permissions: contents: read` everywhere; opencode-compat
  was previously unscoped (over-permissive). Release escalates to job-level
  `contents: write` only.
- Add `persist-credentials: false` to all checkouts.
- New CodeQL workflow (Go) and OSSF Scorecard workflow report to the Security
  tab on push, PR, and weekly schedules.

Performance
- Add `concurrency:` blocks so superseded PR runs auto-cancel; releases and
  benchmarks keep `cancel-in-progress: false` to avoid half-published runs.
- Use `filter: blob:none` on checkouts for partial clone speedup.
- Restrict opencode-compat push trigger to `branches: [main]`.

Quality and reuse
- New `actionlint` job in validate-plugin lints workflow YAML on every PR.
- Extract Go setup into `.github/actions/setup-go-harness` composite action
  reused by validate / test-go / release / codeql / smoke-install.

Delivery-destination guarantee
- New `smoke-install.yml` matrix job builds the harness binary on
  ubuntu-latest, macos-latest, and windows-latest, then runs `version`,
  `validate skills/agents/all`, `doctor`, and a plugin.json/VERSION drift
  check on every PR. Failure on any platform blocks merge.
Address Codex review feedback and the actionlint job failure.

actionlint job
- Drop `docker://rhysd/actionlint:1.7.12` (mutable Docker tag) and install
  via `go install github.com/rhysd/actionlint/cmd/actionlint@v1.7.12`
  instead. Go module proxy resolves @Version to a content-addressed cache
  entry, providing the same supply-chain immutability as a SHA-pinned
  action without depending on a Docker registry tag (Codex P2 #2). Reuses
  the existing setup-go-harness composite.

smoke-install doctor
- Add `${GITHUB_WORKSPACE}/bin` to GITHUB_PATH after building the harness
  binary so `harness` resolves bare. This makes doctor's "bin/harness in
  PATH" check pass on its own merit instead of relying on a fallback that
  swallowed every doctor exit (Codex P2 #1). Removed the `|| { warning;
  exit 0 }` block so a real health regression now blocks the smoke gate.
Actionlint's shellcheck integration (enabled on GitHub-hosted runners
where shellcheck is pre-installed) surfaced three pre-existing issues
when the new actionlint job started running.

- benchmark.yml Summary step: replace `ls -t … | head -1` with a
  null-delimited find loop (SC2012), and group $GITHUB_STEP_SUMMARY
  writes inside a single redirect block (SC2129). Behavior identical;
  output is the same.
- release.yml Create Release step: drop the unused
  `VERSION="${TAG#v}"` assignment (SC2034). `gh release create` only
  references `$TAG`; the older codepath that used `$VERSION` was
  retired earlier.

CHANGELOG: add a Before/After table to the [Unreleased] section per
.claude/rules/github-release.md (Keep a Changelog format requirement
for major changes), as flagged in PR review.
The build feature was never wired to a caller — smoke-install builds
inline with OS-detection logic, and validate-plugin's validate job
calls `go build` directly. Removing the dead input avoids the
hardcoded `harness-linux-amd64` filename trap and trims the composite
to a pure "Setup Go + cache" role.
`tests/test-i18n-japanese-ux-regression.sh` expects 9 skill surfaces
across `skills/`, `codex/.codex/skills/`, and `.agents/skills/`. The
latter is documented as a local-only development mirror (gitignored;
see docs/skill-orchestration-design-contract.md:220 and
docs/i18n-language-contract.md:177). CI checkouts lack the .agents/
directory by design, so the test counted only 6 surfaces and tripped
the `checked >= 9` assertion — pre-existing failure on main exposed
once validate started running end-to-end again on this branch.

Fix: in the validate-plugin workflow, recreate the same 5 directories
the test references (.agents/skills/harness-{work,review,plan,
x-article,x-announce}) and invoke sync-skill-mirrors.sh, which then
copies the canonical content from skills/ into the bootstrapped
directories. This mirrors what a local dev's workspace looks like
after a routine `sync-skill-mirrors.sh` run.

Verified locally: check-consistency.sh now reports "✅ すべての
チェックに合格しました" (was previously "❌ 1 個の問題"); the i18n
test prints "checked 9 Japanese skill descriptions".

No changes to the test assertions, no relaxation of any check — the
fix restores the workspace shape the test was written against.
`opencode-compat.yml` also invokes `scripts/ci/check-consistency.sh`,
which runs the same i18n japanese-ux regression test. Same bootstrap
required as in validate-plugin.yml to recreate the local-only
.agents/skills/ mirror from the skills/ SSOT before the test
inspects it.
@Chachamaru127
Chachamaru127 force-pushed the claude/enhance-github-actions-cicd-ag7rx branch from 1519678 to 9467f13 Compare May 15, 2026 23:17
@Chachamaru127
Chachamaru127 merged commit 2dbb881 into main May 15, 2026
10 checks passed
@Chachamaru127
Chachamaru127 deleted the claude/enhance-github-actions-cicd-ag7rx branch May 15, 2026 23:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants