Skip to content

chore(workflow): add SDK parity dispatch workflow - #14

Open
salihdev0 wants to merge 1 commit into
mainfrom
feat/sdk-parity
Open

salihdev0 wants to merge 1 commit into
mainfrom
feat/sdk-parity

Conversation

@salihdev0

Copy link
Copy Markdown
  • Introduced a new GitHub Actions workflow for SDK parity dispatch.
  • Triggers on push and pull request events for changes in the 'src' directory and 'package.json'.
  • Utilizes a reusable workflow from the tapsilat/tapsilat-sdk-parity repository.
  • Inherits secrets for secure operations.

- Introduced a new GitHub Actions workflow for SDK parity dispatch.
- Triggers on push and pull request events for changes in the 'src' directory and 'package.json'.
- Utilizes a reusable workflow from the tapsilat/tapsilat-sdk-parity repository.
- Inherits secrets for secure operations.
Copilot AI review requested due to automatic review settings April 8, 2026 20:31

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new GitHub Actions workflow to dispatch an SDK parity check by calling a reusable workflow in tapsilat/tapsilat-sdk-parity, scoped to changes under src/** and package.json.

Changes:

  • Introduces sdk-parity-dispatch.yml workflow with push, pull_request, and workflow_dispatch triggers.
  • Calls an upstream reusable workflow and inherits repository secrets for that job.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +3 to +8
on:
push:
paths:
- "src/**"
- "package.json"
pull_request:

Copilot AI Apr 8, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

push is not scoped to any branches, so this workflow will run on every branch push (including feature branches), potentially dispatching parity jobs unexpectedly and increasing CI load. If dispatch should only happen for the default branch, add a branches: [ main ] (or your release branches) filter under push (and optionally under pull_request).

Copilot uses AI. Check for mistakes.
Comment on lines +15 to +16
parity-dispatch:
uses: tapsilat/tapsilat-sdk-parity/.github/workflows/reusable-sdk-parity-dispatch.yml@main

Copilot AI Apr 8, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The reusable workflow reference is pinned to @main, which is mutable and increases supply-chain risk (a change in the upstream repo can affect your CI without review). Prefer pinning to an immutable ref (a tag) or, ideally, a full commit SHA.

Copilot uses AI. Check for mistakes.
Comment on lines +8 to +17
pull_request:
paths:
- "src/**"
- "package.json"
workflow_dispatch:

jobs:
parity-dispatch:
uses: tapsilat/tapsilat-sdk-parity/.github/workflows/reusable-sdk-parity-dispatch.yml@main
secrets: inherit

Copilot AI Apr 8, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

secrets: inherit forwards all repository/environment secrets to the called workflow. Combined with the pull_request trigger, this can be risky if the reusable workflow checks out and executes PR code. Prefer explicitly passing only the required secrets (and/or restricting this job to trusted contexts such as push to default branch).

Copilot uses AI. Check for mistakes.
Comment on lines +12 to +17
workflow_dispatch:

jobs:
parity-dispatch:
uses: tapsilat/tapsilat-sdk-parity/.github/workflows/reusable-sdk-parity-dispatch.yml@main
secrets: inherit

Copilot AI Apr 8, 2026

Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider adding an explicit permissions: block for the workflow (or job) to ensure the GITHUB_TOKEN has only the minimum required scopes for dispatching. Without this, token permissions depend on repo defaults and can drift over time.

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants