From 5728c99b17e9f82345bef5dd013e2530c824ecd2 Mon Sep 17 00:00:00 2001 From: NiftyAndy Date: Tue, 28 Jul 2026 03:54:58 -0400 Subject: [PATCH] feat(init): minimize consumer workflow footprint --- .github/scripts/doctor.sh | 4 +++- .github/scripts/sync-template.sh | 6 ------ README.md | 5 +++++ 3 files changed, 8 insertions(+), 7 deletions(-) diff --git a/.github/scripts/doctor.sh b/.github/scripts/doctor.sh index c064fd59..ba4b47d8 100755 --- a/.github/scripts/doctor.sh +++ b/.github/scripts/doctor.sh @@ -91,10 +91,12 @@ for workflow in ci codeql security test draft-pr release-pr release; do fi done -for script in ci.sh codeql-languages.sh profile.sh security.sh doctor.sh bootstrap.sh sync-template.sh init-repo.sh sync-protection.sh sync-codeowners.sh; do +for script in ci.sh profile.sh doctor.sh bootstrap.sh sync-template.sh init-repo.sh sync-protection.sh sync-codeowners.sh; do [ -x ".github/scripts/$script" ] || error "missing executable script: .github/scripts/$script" done +printf '%s\n' 'Remote CI, Test, Security, and CodeQL runtimes are loaded by reusable workflow wrappers.' + if [ "$errors" -gt 0 ]; then printf '%s\n' "Repository doctor found $errors error(s)." >&2 exit 1 diff --git a/.github/scripts/sync-template.sh b/.github/scripts/sync-template.sh index 2ed9831a..3ebc1827 100755 --- a/.github/scripts/sync-template.sh +++ b/.github/scripts/sync-template.sh @@ -243,17 +243,11 @@ files=( .github/ISSUE_TEMPLATE/bug_report.yml .github/ISSUE_TEMPLATE/config.yml .github/ISSUE_TEMPLATE/feature_request.yml - .github/actions/setup/action.yml - .github/actions/cache/action.yml - .github/actions/codeql/action.yml .github/scripts/profile.sh .github/scripts/bootstrap.sh .github/scripts/changed-files.sh .github/scripts/ci.sh - .github/scripts/codeql-languages.sh .github/scripts/doctor.sh - .github/scripts/security.sh - .github/scripts/sitecustomize.py .github/scripts/pre-commit.sh .github/scripts/sync-template.sh .github/scripts/init-repo.sh diff --git a/README.md b/README.md index 3dc8f6bf..af331d9e 100644 --- a/README.md +++ b/README.md @@ -42,6 +42,11 @@ the selected repository is saved in `.github/template.yml` and rendered into the small `ci.yml` and `test.yml` wrappers automatically. The equivalent environment variable is `REPO_FOUNDRY_RUNTIME_REPOSITORY`. +Normal synchronization imports only the local hook, agent-facing command, +profile/release, initializer, doctor, ownership, and protection entrypoints. +Workflow-only actions and Security/CodeQL analyzers stay in the versioned +runtime package and are not duplicated in consumer repositories. + The standard Security wrapper uses the same runtime contract, so dependency audits and the public-only Dependency Review policy can be upgraded centrally without copying security scripts into every consumer repository.