Repository navigation
feat: weekly Action to classify, upsert, and snapshot the board - #3
Conversation
Run the act-tools classifier on a schedule and dispatch, sync Project fields, and commit data/snapshot.json only when it changes. Co-authored-by: Cursor <cursoragent@cursor.com>
Review: act-rules/act-board#3 — feat: weekly Action to classify, upsert, and snapshot the boardHead SHA The shape of this workflow is right: a single GitHub App token minted per run, scoped to the two repos that need writes; the public Recommended Action: Request ChangesFindings 1–3 will make the first scheduled run fail or write wrong data. Blocking1.
|
| Check | Result |
|---|---|
| Secrets not echoed | Pass |
| Fail-fast APP_ID / APP_PRIVATE_KEY | Pass |
| Fail-fast ACT_BOARD_PROJECT_NUMBER | Partial — finding 6 |
| App token not used for w3c/wcag-act-rules | Pass |
| Snapshot commit only on change | Pass |
| act-tools checkout | Fail — findings 2 and 3 |
| No PEM in repo | Pass |
Blocking: - Check out act-rules.github.io with fetch-depth: 0. The classifier reads git history, which a shallow clone silently truncates. - Pin the act-tools checkout to ref issue-65-project-sync, the act-tools#71 branch that adds sync-act-board-project and write-act-board-snapshot. README says to retarget a main SHA once #71 merges. - Stop passing the App token to the act-tools checkout; act-tools is not in the App's repositories list. Should fix: - Add permissions: contents: read and timeout-minutes: 30. - Add concurrency group sync-act-board with cancel-in-progress: false, and git pull --rebase --autostash before pushing the snapshot commit. - Fail fast on ACT_BOARD_PROJECT_NUMBER in the first guard step, alongside the App secrets. - persist-credentials: false on all three sibling checkouts; only the root act-board checkout keeps credentials, for the push. Minor: - node-version 24, matching act-tools CI. - Ignore *.pem and the sibling checkout directories. - Seed data/snapshot.json as [] so the README link resolves. - Note that GitHub disables scheduled workflows after 60 days of inactivity. Co-authored-by: Cursor <cursoragent@cursor.com>
The issue-65-project-sync branch was deleted after merge, so the weekly workflow would fail to clone act-tools. Co-authored-by: Cursor <cursoragent@cursor.com>
implements the Action half of act-rules/act-tools#65; depends on the act-tools Project sync CLI landing on act-tools main; documents APP_ID, APP_PRIVATE_KEY, ACT_BOARD_PROJECT_NUMBER; generated issue bodies must not be edited.
Made with Cursor