Repository navigation
Conversation
salihdev0
commented
Apr 8, 2026
- Introduced a new GitHub Actions workflow for SDK parity dispatch.
- Triggers on push and pull request events for changes in the 'src' directory and 'package.json'.
- Utilizes a reusable workflow from the tapsilat/tapsilat-sdk-parity repository.
- Inherits secrets for secure operations.
- Introduced a new GitHub Actions workflow for SDK parity dispatch. - Triggers on push and pull request events for changes in the 'src' directory and 'package.json'. - Utilizes a reusable workflow from the tapsilat/tapsilat-sdk-parity repository. - Inherits secrets for secure operations.
There was a problem hiding this comment.
Pull request overview
Adds a new GitHub Actions workflow to dispatch an SDK parity check by calling a reusable workflow in tapsilat/tapsilat-sdk-parity, scoped to changes under src/** and package.json.
Changes:
- Introduces
sdk-parity-dispatch.ymlworkflow withpush,pull_request, andworkflow_dispatchtriggers. - Calls an upstream reusable workflow and inherits repository secrets for that job.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| on: | ||
| push: | ||
| paths: | ||
| - "src/**" | ||
| - "package.json" | ||
| pull_request: |
There was a problem hiding this comment.
push is not scoped to any branches, so this workflow will run on every branch push (including feature branches), potentially dispatching parity jobs unexpectedly and increasing CI load. If dispatch should only happen for the default branch, add a branches: [ main ] (or your release branches) filter under push (and optionally under pull_request).
| parity-dispatch: | ||
| uses: tapsilat/tapsilat-sdk-parity/.github/workflows/reusable-sdk-parity-dispatch.yml@main |
There was a problem hiding this comment.
The reusable workflow reference is pinned to @main, which is mutable and increases supply-chain risk (a change in the upstream repo can affect your CI without review). Prefer pinning to an immutable ref (a tag) or, ideally, a full commit SHA.
| pull_request: | ||
| paths: | ||
| - "src/**" | ||
| - "package.json" | ||
| workflow_dispatch: | ||
|
|
||
| jobs: | ||
| parity-dispatch: | ||
| uses: tapsilat/tapsilat-sdk-parity/.github/workflows/reusable-sdk-parity-dispatch.yml@main | ||
| secrets: inherit |
There was a problem hiding this comment.
secrets: inherit forwards all repository/environment secrets to the called workflow. Combined with the pull_request trigger, this can be risky if the reusable workflow checks out and executes PR code. Prefer explicitly passing only the required secrets (and/or restricting this job to trusted contexts such as push to default branch).
| workflow_dispatch: | ||
|
|
||
| jobs: | ||
| parity-dispatch: | ||
| uses: tapsilat/tapsilat-sdk-parity/.github/workflows/reusable-sdk-parity-dispatch.yml@main | ||
| secrets: inherit |
There was a problem hiding this comment.
Consider adding an explicit permissions: block for the workflow (or job) to ensure the GITHUB_TOKEN has only the minimum required scopes for dispatching. Without this, token permissions depend on repo defaults and can drift over time.