ci: validate governance sources and label-sync targets - #10
Merged
Conversation
|
| Filename | Overview |
|---|---|
| .github/workflows/validate.yml | Adds a read-only workflow that validates governance scripts, manifests, shell syntax, and the label parser regression test. |
| scripts/sync-labels.sh | Rejects duplicate targets, fixes whitespace-sensitive quote removal for label names, and guards direct execution so functions can be tested safely. |
| scripts/test-sync-labels.sh | Adds a focused regression test confirming that a quoted label name containing spaces and a colon is decoded correctly. |
| scripts/tests/quoted-label.yml | Provides the quoted-label fixture used by the new shell regression test. |
Reviews (3): Last reviewed commit: "merge: update governance branch with mai..." | Re-trigger Greptile
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Issue 29 follow-up. Add credential-free governance source validation and reject duplicate label-sync targets. Includes manifest checks, Shell/Python validation, and no policy behavior changes beyond fail-closed duplicate handling. Derek-only commits; no secrets accessed.