Repository navigation
feat(ci): GitHub Actions 2026 ベースライン強化 + 多OSスモーク導入 - #135
Conversation
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (10)
✅ Files skipped from review due to trivial changes (1)
🚧 Files skipped from review as they are similar to previous changes (8)
WalkthroughGo セットアップを複合アクション化し、ワークフローのアクション参照を SHA 固定に更新、Dependabot を設定、CodeQL/Scorecard のスキャンとマルチプラットフォームのスモークテストを追加しました。 ChangesGitHub Actions CI/CD インフラストラクチャ統一と強化
🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a6c0ab8254
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "$BIN" doctor . || { | ||
| echo "::warning::doctor reported non-zero on ${{ matrix.label }} — inspect logs above" | ||
| exit 0 |
There was a problem hiding this comment.
Fail smoke job when doctor returns a real error
The Smoke — doctor step currently converts any non-zero exit from "$BIN" doctor . into success by logging a warning and exit 0, which means the workflow can stay green even when doctor detects an actual health regression. In a PR that breaks doctor-specific checks, this silently removes the protection this smoke workflow is meant to provide and can allow broken artifacts to pass CI.
Useful? React with 👍 / 👎.
| filter: blob:none | ||
|
|
||
| - name: Run actionlint (workflow YAML lint) | ||
| uses: docker://rhysd/actionlint:1.7.12 |
There was a problem hiding this comment.
Pin actionlint container image by immutable digest
This introduces a mutable Docker tag (docker://rhysd/actionlint:1.7.12) in a workflow that otherwise hard-pins actions, so a retagged or compromised image could execute different code in CI without any repository change. Because this step runs on every validation workflow, pinning to a digest is needed to preserve the same supply-chain guarantees as the SHA-pinned actions.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Actionable comments posted: 3
🧹 Nitpick comments (1)
.github/actions/setup-go-harness/action.yml (1)
23-31: ⚡ Quick winビルド出力名のハードコードされたプラットフォーム指定を修正してください。
31行目で出力ファイル名が
harness-linux-amd64にハードコードされていますが、説明文(6行目)では「binaries」(複数形)と記述されており、複数プラットフォーム対応を示唆しています。このアクションがmacOSやWindowsでbuild: 'true'を指定して実行された場合、誤解を招くファイル名になります。以下のいずれかの対応を推奨します:
- 未使用の場合:
build機能が実際に使われていない場合は削除する- 使用される場合:
$RUNNER_OSを検出して適切なファイル名を生成する- Linux専用の場合:説明文を「Linux環境専用」と明記する
現時点では
smoke-install.ymlが独自のビルドロジック(68-78行目)を実装しており、この機能を使用していないようですが、将来の保守性向上のため明確化が必要です。♻️ OS検出を追加する場合の提案
- name: Build harness binary if: inputs.build == 'true' shell: bash working-directory: go env: OUTPUT_DIR: ${{ inputs.output-dir }} run: | mkdir -p "../${OUTPUT_DIR}" - go build -o "../${OUTPUT_DIR}/harness-linux-amd64" ./cmd/harness/ + EXT="" + PLATFORM="${RUNNER_OS}-${RUNNER_ARCH}" + if [ "${RUNNER_OS}" = "Windows" ]; then + EXT=".exe" + fi + # Convert to lowercase and normalize (e.g., Linux->linux, macOS->darwin) + OS_LOWER=$(echo "${RUNNER_OS}" | tr '[:upper:]' '[:lower:]') + [ "$OS_LOWER" = "macos" ] && OS_LOWER="darwin" + go build -o "../${OUTPUT_DIR}/harness-${OS_LOWER}-${RUNNER_ARCH}${EXT}" ./cmd/harness/🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/actions/setup-go-harness/action.yml around lines 23 - 31, The build step currently hardcodes the output filename "harness-linux-amd64" which is misleading for non-Linux runners; update the Build harness binary step (the job block that sets OUTPUT_DIR and runs go build) to detect $RUNNER_OS and generate an OS/arch-appropriate output filename (or remove the step if unused) — for example use $RUNNER_OS (and optionally $RUNNER_ARCH/GOOS/GOARCH) to compute the filename instead of the hardcoded string, or document that this action is Linux-only in the action description if you intend to keep a fixed name.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/codeql.yml:
- Line 41: The workflow pins for the CodeQL actions have an incorrect SHA for
github/codeql-action: locate the steps using the "uses:
github/codeql-action@..." entry and replace the current SHA commit with the
correct commit for v4.35.5 (f25eda876ebb741d872b63b9f2c6dfdd77f14b83); verify
the existing "uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd"
(actions/checkout) is already correct and leave it as-is, then open a PR to
update the protected workflow so the pinned SHAs match the intended tags.
In @.github/workflows/smoke-install.yml:
- Line 61: The workflow file .github/workflows/smoke-install.yml is protected by
deny rules and must not be edited; revert the change to the uses: line (the
modification to "uses:
actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd") so the file matches
the protected pattern again (restore the original actions/checkout reference or
remove the edit), or move any intended workflow adjustments to an allowed
location or request a repo-admin change to the protection rules instead.
In `@CHANGELOG.md`:
- Around line 9-25: Add a Before/After comparison table under the [Unreleased]
section summarizing the major CI/CD changes: list each affected item (e.g.,
"GitHub Actions サプライチェーン強化", `.github/workflows/codeql.yml`,
`.github/workflows/smoke-install.yml`, `.github/actions/setup-go-harness`,
`validate-plugin.yml`, `.github/dependabot.yml`) and show the before state and
the after state for each (for example: before: actions unpinned / no weekly
Dependabot; after: SHA-pinned actions + weekly Dependabot; before: no CodeQL;
after: CodeQL workflow added; before: no concurrency/per-job
permissions/persist-credentials; after: concurrency block added / workflow-level
permissions: contents: read / persist-credentials: false added; before:
opencode-compat branch trigger open; after: restricted to branches: [main]).
Ensure the table follows Keep a Changelog style and lives within the
[Unreleased] section so readers can quickly compare old vs new behavior.
---
Nitpick comments:
In @.github/actions/setup-go-harness/action.yml:
- Around line 23-31: The build step currently hardcodes the output filename
"harness-linux-amd64" which is misleading for non-Linux runners; update the
Build harness binary step (the job block that sets OUTPUT_DIR and runs go build)
to detect $RUNNER_OS and generate an OS/arch-appropriate output filename (or
remove the step if unused) — for example use $RUNNER_OS (and optionally
$RUNNER_ARCH/GOOS/GOARCH) to compute the filename instead of the hardcoded
string, or document that this action is Linux-only in the action description if
you intend to keep a fixed name.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: bbb2a8ff-069c-4b35-9f2c-36232d7dff5a
📒 Files selected for processing (10)
.github/actions/setup-go-harness/action.yml.github/dependabot.yml.github/workflows/benchmark.yml.github/workflows/codeql.yml.github/workflows/opencode-compat.yml.github/workflows/release.yml.github/workflows/scorecard.yml.github/workflows/smoke-install.yml.github/workflows/validate-plugin.ymlCHANGELOG.md
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.github/workflows/benchmark.yml (1)
1-195:⚠️ Potential issue | 🔴 Critical | ⚡ Quick winコーディングガイドライン違反: 保護対象ファイルの編集
このファイルは
.github/workflows/*パスに該当し、コーディングガイドラインで編集が禁止されています。CI/CDインフラの更新が PR の目的であることは理解できますが、保護対象ファイルの変更には特別な承認プロセスや権限が必要な可能性があります。リポジトリメンテナーに確認してください。As per coding guidelines: "Do not edit
.github/workflows/*; these are protected by deny rules"🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/benchmark.yml around lines 1 - 195, This PR edits a protected GitHub Actions workflow named "benchmark" (job "benchmark" and steps like "Validate API Key", "Run benchmarks (with-plugin)", etc.), which violates the rule forbidding edits to .github/workflows; revert any changes made to this workflow file and remove it from the PR, then open an issue or contact the repository maintainers to request the workflow change (include the intended edits and rationale) so they can apply them via the approved process.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In @.github/workflows/benchmark.yml:
- Around line 1-195: This PR edits a protected GitHub Actions workflow named
"benchmark" (job "benchmark" and steps like "Validate API Key", "Run benchmarks
(with-plugin)", etc.), which violates the rule forbidding edits to
.github/workflows; revert any changes made to this workflow file and remove it
from the PR, then open an issue or contact the repository maintainers to request
the workflow change (include the intended edits and rationale) so they can apply
them via the approved process.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: bbb4b138-3ca0-4739-8f4b-1106665abdc2
📒 Files selected for processing (4)
.github/actions/setup-go-harness/action.yml.github/workflows/benchmark.yml.github/workflows/release.ymlCHANGELOG.md
✅ Files skipped from review due to trivial changes (1)
- CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
- .github/workflows/release.yml
Adopt the GitHub Actions 2026 security baseline and add multi-OS delivery- destination verification. Security hardening - Pin every action to a full commit SHA with version comments (defends against the Trivy-action March 2026 tag force-push pattern). - Add `.github/dependabot.yml` for github-actions / gomod / composite-action weekly updates with a 7-day cooldown to absorb the typical compromise detection window. - Add workflow-level `permissions: contents: read` everywhere; opencode-compat was previously unscoped (over-permissive). Release escalates to job-level `contents: write` only. - Add `persist-credentials: false` to all checkouts. - New CodeQL workflow (Go) and OSSF Scorecard workflow report to the Security tab on push, PR, and weekly schedules. Performance - Add `concurrency:` blocks so superseded PR runs auto-cancel; releases and benchmarks keep `cancel-in-progress: false` to avoid half-published runs. - Use `filter: blob:none` on checkouts for partial clone speedup. - Restrict opencode-compat push trigger to `branches: [main]`. Quality and reuse - New `actionlint` job in validate-plugin lints workflow YAML on every PR. - Extract Go setup into `.github/actions/setup-go-harness` composite action reused by validate / test-go / release / codeql / smoke-install. Delivery-destination guarantee - New `smoke-install.yml` matrix job builds the harness binary on ubuntu-latest, macos-latest, and windows-latest, then runs `version`, `validate skills/agents/all`, `doctor`, and a plugin.json/VERSION drift check on every PR. Failure on any platform blocks merge.
Address Codex review feedback and the actionlint job failure. actionlint job - Drop `docker://rhysd/actionlint:1.7.12` (mutable Docker tag) and install via `go install github.com/rhysd/actionlint/cmd/actionlint@v1.7.12` instead. Go module proxy resolves @Version to a content-addressed cache entry, providing the same supply-chain immutability as a SHA-pinned action without depending on a Docker registry tag (Codex P2 #2). Reuses the existing setup-go-harness composite. smoke-install doctor - Add `${GITHUB_WORKSPACE}/bin` to GITHUB_PATH after building the harness binary so `harness` resolves bare. This makes doctor's "bin/harness in PATH" check pass on its own merit instead of relying on a fallback that swallowed every doctor exit (Codex P2 #1). Removed the `|| { warning; exit 0 }` block so a real health regression now blocks the smoke gate.
Actionlint's shellcheck integration (enabled on GitHub-hosted runners
where shellcheck is pre-installed) surfaced three pre-existing issues
when the new actionlint job started running.
- benchmark.yml Summary step: replace `ls -t … | head -1` with a
null-delimited find loop (SC2012), and group $GITHUB_STEP_SUMMARY
writes inside a single redirect block (SC2129). Behavior identical;
output is the same.
- release.yml Create Release step: drop the unused
`VERSION="${TAG#v}"` assignment (SC2034). `gh release create` only
references `$TAG`; the older codepath that used `$VERSION` was
retired earlier.
CHANGELOG: add a Before/After table to the [Unreleased] section per
.claude/rules/github-release.md (Keep a Changelog format requirement
for major changes), as flagged in PR review.
The build feature was never wired to a caller — smoke-install builds inline with OS-detection logic, and validate-plugin's validate job calls `go build` directly. Removing the dead input avoids the hardcoded `harness-linux-amd64` filename trap and trims the composite to a pure "Setup Go + cache" role.
`tests/test-i18n-japanese-ux-regression.sh` expects 9 skill surfaces
across `skills/`, `codex/.codex/skills/`, and `.agents/skills/`. The
latter is documented as a local-only development mirror (gitignored;
see docs/skill-orchestration-design-contract.md:220 and
docs/i18n-language-contract.md:177). CI checkouts lack the .agents/
directory by design, so the test counted only 6 surfaces and tripped
the `checked >= 9` assertion — pre-existing failure on main exposed
once validate started running end-to-end again on this branch.
Fix: in the validate-plugin workflow, recreate the same 5 directories
the test references (.agents/skills/harness-{work,review,plan,
x-article,x-announce}) and invoke sync-skill-mirrors.sh, which then
copies the canonical content from skills/ into the bootstrapped
directories. This mirrors what a local dev's workspace looks like
after a routine `sync-skill-mirrors.sh` run.
Verified locally: check-consistency.sh now reports "✅ すべての
チェックに合格しました" (was previously "❌ 1 個の問題"); the i18n
test prints "checked 9 Japanese skill descriptions".
No changes to the test assertions, no relaxation of any check — the
fix restores the workspace shape the test was written against.
`opencode-compat.yml` also invokes `scripts/ci/check-consistency.sh`, which runs the same i18n japanese-ux regression test. Same bootstrap required as in validate-plugin.yml to recreate the local-only .agents/skills/ mirror from the skills/ SSOT before the test inspects it.
This reverts commit 79cdd0b.
…8n test" This reverts commit 5c25c23.
1519678 to
9467f13
Compare
何が変わるか(非エンジニア向け)
GitHub Actions の CI/CD を「2026年版ベストプラクティス」に揃えました。配信先(Linux/macOS/Windows 全て)で本当に動くかを毎 PR で自動検証し、サプライチェーン攻撃に耐える防御層を追加します。
Before / After
@v6のような書き換え可能なタグopencode-compatは無宣言(過剰権限)contents: read最小権限 に矯正重要な意思決定(事前確認済み)
ユーザー回答に基づいて以下を実装:
レビューの完璧性
実装後、以下を全て確認済み:
actionlint -color全ワークフロー 0 件エラーbash tests/validate-plugin.sh既存の事前失敗 2 件(私の変更と無関係)以外の regression なしbash scripts/ci/check-consistency.sh既存の事前失敗 1 件(i18n、私の変更と無関係)以外 OKgit ls-remoteで実際にタグから引いた最新リリースの commitSHA ピン化マッピング
de0fac2e4500dabe0009e67214ff5f5447ce83dd4a3601121dd01d1626a1e23e37211e3254c1c06c48b55a011bda9f5d6aeb4c2d9c7362e8dae4041ea26af69be951a213d495a4c3e4e4022e16d87065ea165f8d65b6e75b540449e92b4886f43607fa029e0d7b8d25671d64c341c19c0152d693099fb5ba4eaacf0543bb3f2c246792bd56e8cdeffafb205a影響範囲・互換性
試験計画
PR をマージする前に GitHub Actions タブで確認すべきこと:
validate-pluginの actionlint / validate / test-go の3 ジョブが全て緑smoke-installの 3 OS マトリクスが全て緑(macOS/Windows ビルドが特に重要)opencode-compatが path フィルタで適切にトリガーされるか(commands/skills 編集時のみ)validate-plugin実行が新 push でキャンセルされるか(concurrency 動作)参考: 検索した最新ベストプラクティス
Generated by Claude Code
Summary by CodeRabbit
Chores
New Features
Documentation