Skip to content

Scope Update Readme to pushes on main - #19

Merged
matt-edmondson merged 1 commit into
mainfrom
claude/dependabot-ci-workflow-rollout-fbrhdn
Sep 16, 2026
Merged

matt-edmondson merged 1 commit into
mainfrom
claude/dependabot-ci-workflow-rollout-fbrhdn

Conversation

@matt-edmondson

Copy link
Copy Markdown
Contributor

What

update-readme.yml: on: push: → on: push: branches: [main]. Schedule and manual triggers unchanged.

Why

An unfiltered push: fires on every branch and every tag, and both are wrong for a workflow that regenerates the organization profile README.

On a tag — actions/checkout leaves a detached HEAD, so the commit step's bare git push has no upstream to push to and the run fails. This is a blocker rather than a hypothetical: the shared CI callers reference a moving release tag, so every promotion would produce a failing run in this repository. The release tag cannot be created until this merges — a tag pushed today would use the version of this workflow at that commit and still fail.

On a feature branch — it regenerates a file that only means anything on main and commits it to whatever branch was pushed. That is not theoretical either:

main still regenerates on every push, which is the only place the profile README is read from, so the profile page is unaffected.

Testing

actionlint 1.7.7 with shellcheck — no new findings. The two pre-existing SC2086 infos in this file are untouched.

The mechanism is the documented behaviour of an unfiltered push: trigger, and the branch-push half of it is directly evidenced by the bot commits on #16–#18 and the conflict I resolved on #18.

🤖 Generated with Claude Code

https://claude.ai/code/session_014RABe2NufFc9hwm94iB3Rf


Generated by Claude Code

`on: push:` with no filter fires on every branch and every tag, and both are
wrong for a workflow that regenerates the organization profile README.

On a tag, actions/checkout leaves a detached HEAD, so the commit step's bare
`git push` has no upstream and the run fails. That matters now rather than in
the abstract: the shared CI callers reference a moving `release` tag, so every
promotion would have produced a failing run in this repository.

On a feature branch it regenerates a file that only means anything on main and
commits it to that branch. Three pull requests in a row picked up a bot README
commit they had no reason to carry, and on #18 main and the branch regenerated
different snapshots of the same table and conflicted -- a merge conflict in a
generated file, on a pull request that never touched it.

The schedule and manual triggers are unchanged; main still regenerates on every
push, which is the only place the profile README is read from.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014RABe2NufFc9hwm94iB3Rf
@matt-edmondson
matt-edmondson merged commit 18552d5 into main Sep 16, 2026
3 checks passed
@matt-edmondson
matt-edmondson deleted the claude/dependabot-ci-workflow-rollout-fbrhdn branch September 16, 2026 03:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants