feat(workflows): add node CI gold-standard reusables (node-test, node-build, node-ci)#248
Merged
Conversation
…-build, node-ci) Signed-off-by: Sebastian Mendel <sebastian.mendel@netresearch.de>
There was a problem hiding this comment.
Code Review
This pull request updates the documentation in docs/reusable-workflow-permissions.md to specify the permissions required for the node-ci.yml, node-test.yml, and node-build.yml reusable workflows. There are no review comments, and I have no feedback to provide.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
Org gitleaks-action requires a license key; without forwarding it the composed gitleaks job fails for org consumers (e.g. node-magento-eqp). Signed-off-by: Sebastian Mendel <sebastian.mendel@netresearch.de>
Pilot validated the composed workflow on the feature branch; the leaves land on main in this same merge, so reference them at @main. Signed-off-by: Sebastian Mendel <sebastian.mendel@netresearch.de>
Signed-off-by: Sebastian Mendel <sebastian.mendel@netresearch.de>
|
CybotTM
added a commit
to netresearch/node-magento-eqp
that referenced
this pull request
Jul 20, 2026
Pilots the org **node-ci** gold-standard meta-reusable (netresearch/.github#248). Replaces `lint.and.build.yml` + `codeql.yml` + `security.yml` with one `ci.yml` calling `node-ci.yml` (lint/type-check/test/build + node-audit + codeql + gitleaks + dependency-review). References the reusable's `@feat/node-gold-standard` branch for validation; flips to `@main` once #248 merges. Required checks (🔎 Lint, 🔨 Build) will be updated to the new `ci / …` names once the run reports them.
CybotTM
added a commit
to netresearch/node-red-contrib-magento-eqp
that referenced
this pull request
Jul 20, 2026
Adopts the org node-ci gold standard (netresearch/.github#248, validated on node-magento-eqp). Replaces lint.yml + codeql.yml + security.yml with one caller job.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Adds the node-typescript-package gold-standard: two leaves (
node-test.yml,node-build.yml) + thenode-ci.ymlmeta-reusable composing ts-check + node-test + node-build + node-audit + codeql + gitleaks + dependency-review. A consumer adopts its whole CI surface with one caller job.node-test/node-buildare referenced at@feat/node-gold-standard(TODO: flip to@mainpost-merge; they don't exist on main yet). Piloted against a bun consumer before merge. Local actionlint/yamllint/zizmor clean.