ci: add PR validation with canonical ok check#6
Merged
Conversation
Adds a CI workflow that runs on pull_request so this repo exposes the org-wide `ok` required status check. The validate job resolves baseliner.yaml via `baseliner policy` (offline, no token) and checks renovate.json is well-formed JSON. Prereq for onboarding into apply-branch-protection.sh.
The previous run value started with a double-quote, which YAML parses as a quoted scalar with trailing content — an invalid workflow that failed to compile (run produced zero jobs). Use a block scalar like the scan workflow does.
CameronBrooks11
added a commit
to anolishq/.github
that referenced
this pull request
Jun 18, 2026
Adds baseliner-control to the REPOS list now that its CI exposes the shared `ok` aggregator check (anolishq/baseliner-control#6). Brings the canonical classic main protection to all 14 org repos.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Onboards
baseliner-controlinto the org branch-protection convention.This repo previously had no PR-triggered CI —
baseliner.ymlonly runs on a weekly schedule + manual dispatch — so it could not carry the canonicalokrequired status check.This adds
ci.ymlrunning onpull_requestwith:baseliner policy --config baseliner.yaml(resolves the policy offline, no token; fails on a malformed/invalid config) + a JSON well-formedness check onrenovate.jsonOnce green and merged, the repo gets added to
REPOSinanolishq/.github→scripts/apply-branch-protection.shand protected like the rest.