diff --git a/.github/workflows/ci-gate.yml b/.github/workflows/ci-gate.yml index e8ec7d6..ba7f808 100644 --- a/.github/workflows/ci-gate.yml +++ b/.github/workflows/ci-gate.yml @@ -52,7 +52,7 @@ jobs: terraform: ${{ steps.filter.outputs.terraform }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - - uses: dorny/paths-filter@7b450fff21473bca461d4b92ce414b9d0420d706 # v4 + - uses: dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4 id: filter with: filters: | @@ -62,6 +62,14 @@ jobs: - '.terraform.lock.hcl' - '.tflint.hcl' - 'tests/**' + # config/*.yml is not inert data: locals.tf reads it with + # yamldecode(file(...)) and it drives for_each on the repo, + # ruleset and merge-gate modules. Without this pattern a change + # to the inventory skips the Terraform job entirely, so a + # malformed entry merges green and fails later on someone + # else's .tf PR -- the same trap the ci-gate.yml pattern below + # was added to close. + - 'config/**' # This workflow defines the Terraform job (tool versions, tflint # invocation), so a change here must re-run it -- otherwise a # broken tool pin merges green as SKIPPED and only fails later, diff --git a/.terraform.lock.hcl b/.terraform.lock.hcl index b3fcaa8..59c94dc 100644 --- a/.terraform.lock.hcl +++ b/.terraform.lock.hcl @@ -2,25 +2,39 @@ # Manual edits may be lost in future updates. provider "registry.opentofu.org/hashicorp/vault" { - version = "5.10.1" + version = "5.11.0" constraints = "~> 5.10" hashes = [ - "h1:hu9CF1CrQGOCEF9sZEendFKRqbEXuHY4Rz2enypS/FE=", - "zh:0abf976c01f0c0732d0ccc6481e52008be5ee9c8e3d9b5eba0573c640fcf7019", - "zh:2aff4d7ee7ba9eb3de2cd5cda16ba92b4ec7a2b43232aec180984241a323b216", - "zh:2cc186fd0bfc44e100a22b0b40ae8ddcd0ec210a53c1da65d310ee758b1d2b08", - "zh:3f8fb8594736b34af4b26437dd4df4dd4042ad4905223995cfebb8a1f10682ec", - "zh:47fb41b18b74073f557dbcd6aad2183e416293405ccd70c0691a279cfe97f8cd", - "zh:517e2f2764d671c22d22def0384fdfc521b456458189189c0363375495d114dc", - "zh:5a49a2003636f2b8a547d494a6c06d43d62a68299775305408c52eff22b1c11f", - "zh:66d4e716920ada84b0c768f4aca4c8948388995462923349a01bd3818d82b618", - "zh:7599f652e89a3f18fa4b76a59d115cc63255cc36ce6b273850509ba25031abca", - "zh:9c3e38ae7e670de973b6255d7050f526cd2b3ca7c383d7ba7226fc204d97c507", - "zh:d04b046023fa9fd69def678f27e001c298ea34fc99ba51f835cda82e496fdb57", - "zh:d9acd8810f6660cd51bb4c25596632984ae18e93340c82a102d074c6eac95151", - "zh:e161bcb9a22607270b980eeff2ba693335fb62d6978516dff93dd4c91cda99b3", - "zh:ef47502f08cfcb5311b7b16a7905e0052bf28359e07cc00ed080ef454e0946cf", - "zh:f0640ddb52e7e90c5006ff571f6ad0554e593665320c764c57a3d8b7ec31b490", + "h1:/VnM9sVlqgehjBJfOxJM7KgwnYcHE5uTpKEbXut1dgg=", + "h1:9QuQbNWiyrvaAmTjeeTVIqySFz7hxTwXTH9Dd2B0Ujk=", + "h1:CE7sUKPs8tOYRSRKyWuacjN+V3eoNoT+56iqfHsrjD8=", + "h1:EwuMC38ibwQk49mUF+apjTzb0wWRVPQGZwYge5wA6ps=", + "h1:G2ObnEUOmG+q9BSMDSjGVxxAMwC3ezTNLk6CgctaqI0=", + "h1:P556Emgu4nsQg9wuf1UIcLiTDLIWzbV9qFE1Bzv8/rQ=", + "h1:POYjTf9eQspC5ysGLVJayOpA7n5Vys98LP1J75d2mko=", + "h1:Q92dy8O1cS+kD21Ao4KIBS0ui8Ver9jjbjKYxF6qByg=", + "h1:RQL9Vem/l4jijfgFZ4ehNyRwe4QeeKi7AjLMmOUEa7s=", + "h1:Z6gV6b9CnqE7Z9sFVsB6Ub+1AyBJdRqjxlgJpq5989E=", + "h1:kS0Z7uzQqZXmuKBWUykLzGCT3qMMVFuHHswJ3T5L+Ho=", + "h1:tc0pVZxI8kgQXMOX0IeN2Cfg8vlnPamyqsXFoB6lZdI=", + "h1:vUO2H6ji35jcTfd/zF0B5ZUP9Nq4xQL+65sZ68inBwc=", + "h1:wVCx0ojzj+iRA5/NGdmYZjevW3azkbnLRV1z/5NPLIE=", + "h1:xG8fsL7fQq0cdvKwMLX+vzbKs1rBRZs3l6r8SqYxKlg=", + "zh:0024bfedb1aedda197ae55a8178bbeaac24e91dc632c0d4cdb8b29966bbb4228", + "zh:2e0f9d6a9ef2c580ec10c57eabff8022374d7833c6619c0b1f176095fa4edbaf", + "zh:3f89756c2c644513be55cbe7881be17baa0d89cd10d7a73209d15ec870be2f93", + "zh:7d922d5ed9f9eff4e6aebfc248d8606dd71811d8c1a308f3cc3a7bead17e651c", + "zh:868e2d6c972421f78ba0376359b49c7a56e96269905884984e5d0176675aeb65", + "zh:9071383ec3933054e3c92ef42e7669173d6b5b1e821031b8fe5cf2ce4c7faf6b", + "zh:a4e1d240266c3c2eb3846fe10c002414f5154f30512acaec77ecbb3628312d7b", + "zh:a6735abb8e44a9ca9b4e637c1796b2648337c1437126f80145268b6e2ac8def4", + "zh:c686a397d3eeffc8a7d7765605056fb386f5e8c14f1e281f1090b46627602673", + "zh:cd668a12cbdabe1ae34efcd98c3877c9ed5da65f4445c62ac5013d5cd7d003e0", + "zh:cf35e72d633197a35b63c8b4ad7c567305dddbd1aaba3f56f627f5c684b69011", + "zh:d1ebd8c575ed3f9dcb1188ae3916a68afe6ff4c5831e9a8d5740c2a6cd3084e1", + "zh:d60c25f487e4fa789a3d08f4a79d93ed9a7180ef0e8be9e0f248becb3ce41642", + "zh:e2443e86da02b08cdf8287f06363de7a703059aab2b2383b7bdfa928e4370210", + "zh:ef8c36a0fda3b408484625ba3f297c3be6b9901cf6497193cee54f9355b6f549", ] } diff --git a/config/repos.yml b/config/repos.yml index 30cfa3c..8308d3f 100644 --- a/config/repos.yml +++ b/config/repos.yml @@ -378,6 +378,44 @@ repos: description: "Private: deep docs + a simplified, original SAM/Falcon-on-Lambda portal and LLM-assistant reference implementation" topics: [] + # Enrolled 2026-08-22. All four receive Renovate PRs but were unmanaged, so + # nothing held them to the module's repo-settings baseline and they had + # drifted away from it: raycast-smart-issue had merge commits disabled, and + # nix-openwhispr had both auto-merge and delete-branch-on-merge disabled. + # Descriptions, topics and visibility below mirror the live values, so + # enrolling changes settings and nothing else. cc-edge-pack-template had no + # description at all; the one below is drawn from its README. + cc-edge-pack-template: + visibility: public + description: "Template repo for dryvist Cribl packs - reusable test/release workflows and scaffolding" + topics: [] + + mlx-benchmarks: + visibility: public + description: "Benchmark harness for MLX and local LLMs on Apple Silicon (results: hf.co/datasets/JacobPEvans/mlx-benchmarks)" + topics: [] + + nix-openwhispr: + visibility: public + description: "Reproducible Nix packaging and macOS lifecycle integration for OpenWhispr" + topics: [] + + raycast-smart-issue: + visibility: public + description: "Too lazy to write GitHub issues yourself? Let a local AI do it. Raycast extension that turns a half-baked idea into a fully-structured issue using Ollama." + topics: + - ai-powered + - developer-tools + - github-issues + - llm + - local-ai + - ollama + - productivity + - raycast + - raycast-extension + - typescript + + # Recorded opt-outs from the org repo-conventions standard, consumed by the # `repo-conventions-sweep` workflow in the org `.github` repo. Terraform does # NOT read this key (locals.tf decodes only `.repos`) — it lives here so the diff --git a/gitflow.tf b/gitflow.tf index 4958e69..1a04b63 100644 --- a/gitflow.tf +++ b/gitflow.tf @@ -55,36 +55,6 @@ import { id = "llm-prompt-evals:develop" } -# The five repos enrolled alongside this block were each running git-flow by -# hand before config/repos.yml described them: develop already exists and is -# already the default branch on all five. Every one therefore adopts rather -# than creates, and the plan must show imports / no-op updates for them — a -# create-or-destroy on any of these is a bug, not an expected first apply. -import { - to = github_branch.develop["ansible-proxmox-ai"] - id = "ansible-proxmox-ai:develop" -} - -import { - to = github_branch.develop["nix-agy"] - id = "nix-agy:develop" -} - -import { - to = github_branch.develop["nix-codex"] - id = "nix-codex:develop" -} - -import { - to = github_branch.develop["nix-hermes"] - id = "nix-hermes:develop" -} - -import { - to = github_branch.develop["x10-lite"] - id = "x10-lite:develop" -} - # Make develop the default branch on git-flow repos: new clones and new PRs # target the integration branch, while main is reserved for releases. The # reference to github_branch.develop makes this depend on the branch existing