diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 85e9c6b..b20ea77 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -7,14 +7,25 @@ on: branches: ["main"] workflow_dispatch: +permissions: + contents: read + jobs: + automation: + name: Validate GitHub automation + uses: DevOpsDerek/workflows/.github/workflows/validate-agentic-workflows.yml@dac4b81c298cb3ea6821ea312efa5375f42d5ccb + with: + gh-aw-version: v0.89.21 + lint: name: Lint (PSScriptAnalyzer) runs-on: ubuntu-latest steps: - name: Checkout code - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + with: + persist-credentials: false - name: Install PSScriptAnalyzer shell: pwsh @@ -47,7 +58,9 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v4 + uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + with: + persist-credentials: false - name: Install Pester shell: pwsh @@ -69,7 +82,7 @@ jobs: - name: Upload test results if: always() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: pester-test-results path: test-results.xml diff --git a/README.md b/README.md index a5f7e06..1a7abf7 100644 --- a/README.md +++ b/README.md @@ -79,6 +79,36 @@ pwsh ./run-tests.ps1 pwsh ./lint.ps1 ``` +## CI and Documentation Automation + +CI keeps separate PSScriptAnalyzer and Pester jobs, with tests running after +lint succeeds. CI analyzes both `lessons/` and `tests/` using +`PSScriptAnalyzerSettings.psd1` and fails on any diagnostic; the local +`lint.ps1` helper fails only on errors. Pester 5 or later writes NUnit XML to +`test-results.xml`, uploaded as `pester-test-results` even when tests fail. + +Automation validation comes from +[`DevOpsDerek/workflows` at commit `dac4b81c298cb3ea6821ea312efa5375f42d5ccb`](https://github.com/DevOpsDerek/workflows/tree/dac4b81c298cb3ea6821ea312efa5375f42d5ccb). +The catalog's checked-script helper does not support PowerShell, so it does +not replace this course's test or lint implementation. The central validator +lints Actions configuration and, when gh-aw sources exist, compiles them and +checks committed locks for drift. It is independent of the existing lint-to-test +dependency. This repository currently has no gh-aw sources or locks. + +**Manual course documentation upkeep is deferred.** The current gh-aw +compiler (`v0.89.21`) hardcodes persisted write-capable checkout credentials +in the PR safe-output job and has no supported override. The documentation +agent source and generated lock have been removed rather than hand-editing a +lock or introducing an insecure workaround. + +Reconsider this capability only after the central compiler supports +`persist-credentials: false` for the write job and credential handling is +verified in regenerated output. Any future adoption must pin the central API, +restrict proposals to bounded documentation-only draft PRs, preserve course +examples without executing lesson scripts, and require human review and manual +merge. No agent secret or PR-write setting is needed for the validator-only +adoption; no automated merge, release, deployment, or publishing is enabled. + ## Lesson Summary | # | Title | Key Concepts |