mirror of
https://github.com/pchuan98/codex.git
synced 2026-07-01 00:31:56 +08:00
ci: fail jobs that dirty the worktree (#29720)
## Why CI jobs should not silently leave tracked changes or untracked files in the repository worktree. ## What - Add a shared final worktree-cleanliness action to 19 checkout-bearing PR and main CI jobs. - Ignore the intentional SDK scratch directory and nested V8 checkout. - Pin Bazelisk in shared CI setup so `.bazelversion` remains authoritative, avoiding `MODULE.bazel.lock` deltas on Windows runners. - Leave `rust-ci-full` and release-only workflows unchanged. - Update `AGENTS.md` to discourage review bots from asking for `MODULE.bazel.lock` changes.
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
name: check-clean-worktree
|
||||
description: Fail when a CI job leaves tracked changes or untracked files in the repository worktree.
|
||||
|
||||
runs:
|
||||
using: composite
|
||||
steps:
|
||||
- name: Check for a clean worktree
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
|
||||
status="$(git -C "${GITHUB_WORKSPACE}" status --porcelain=v1 --untracked-files=normal --ignore-submodules=none)"
|
||||
if [[ -z "${status}" ]]; then
|
||||
exit 0
|
||||
fi
|
||||
|
||||
echo "::error::CI job left tracked changes or untracked files in the repository worktree"
|
||||
printf '%s\n' "${status}"
|
||||
exit 1
|
||||
@@ -34,6 +34,10 @@ runs:
|
||||
|
||||
- name: Set up Bazel
|
||||
uses: bazel-contrib/setup-bazel@c5acdfb288317d0b5c0bbd7a396a3dc868bb0f86 # 0.19.0
|
||||
# Without an explicit Bazelisk version, setup-bazel leaves PATH unchanged
|
||||
# and Windows can use the runner's standalone Bazel, ignoring .bazelversion.
|
||||
with:
|
||||
bazelisk-version: 1.28.1
|
||||
|
||||
- name: Configure Bazel repository cache
|
||||
id: configure_bazel_repository_cache
|
||||
|
||||
Reference in New Issue
Block a user