Skip to content

feat: weekly Action to classify, upsert, and snapshot the board - #3

Merged
WilcoFiers merged 3 commits into
mainfrom
issue-65-weekly-sync
Sep 18, 2026
Merged

WilcoFiers merged 3 commits into
mainfrom
issue-65-weekly-sync

Conversation

@WilcoFiers

Copy link
Copy Markdown
Member

implements the Action half of act-rules/act-tools#65; depends on the act-tools Project sync CLI landing on act-tools main; documents APP_ID, APP_PRIVATE_KEY, ACT_BOARD_PROJECT_NUMBER; generated issue bodies must not be edited.

Made with Cursor

Run the act-tools classifier on a schedule and dispatch, sync Project fields, and commit data/snapshot.json only when it changes.

Co-authored-by: Cursor <cursoragent@cursor.com>
@WilcoFiers

Copy link
Copy Markdown
Member Author

Review: act-rules/act-board#3 — feat: weekly Action to classify, upsert, and snapshot the board

Head SHA a1c8de4d83d297c64a7ba284d7f8f5bf80c22b99 · base main · +150 −1 · 3 files

The shape of this workflow is right: a single GitHub App token minted per run, scoped to the two repos that need writes; the public w3c/wcag-act-rules checked out without a token; secrets never printed; the snapshot committed only when it actually changed. The problems are in the details of how the sibling repos are checked out, and in a dependency on act-tools code that is not on main yet.

Recommended Action: Request Changes

Findings 1–3 will make the first scheduled run fail or write wrong data.


Blocking

1. act-rules.github.io is checked out shallow, which silently breaks the classifier

.github/workflows/sync.yml L42–L46

actions/checkout defaults to fetch-depth: 1. The classifier uses git log on that repo. Set fetch-depth: 0 for act-rules.github.io. Keep depth 1 for wcag-act-rules.

2. Two yarn commands do not exist on act-tools main, and the checkout is unpinned

sync-act-board-project and write-act-board-snapshot come from act-tools#71. Pin the act-tools checkout ref to the #71 branch issue-65-project-sync (or its latest SHA) so this workflow can run before/as that PR merges; README should say to retarget a main SHA after #71 lands.

3. App token is passed to the act-tools checkout, but act-tools is not in the token's repository list

Drop the token from the act-tools checkout (persist-credentials: false). Do not add act-tools to the App repositories: list.


Should fix before merge

4. Add permissions: contents: read and timeout-minutes: 30.

5. Add concurrency: { group: sync-act-board, cancel-in-progress: false }. After snapshot commit, git pull --rebase --autostash then git push.

6. Fail fast on ACT_BOARD_PROJECT_NUMBER in the same first guard step as App secrets.

7. persist-credentials: false on act-tools, act-rules.github.io, and wcag-act-rules checkouts. Only the root act-board checkout needs credentials for push.


Minor

8. Use Node 24 to match act-tools CI (integrate.yml). SHA-pinning first-party actions is optional.

9. .gitignore: approval-report.json, .DS_Store, *.pem, act-tools/, act-rules.github.io/, wcag-act-rules/.

10. README links data/snapshot.json which 404s — seed [] or drop the link.

11. Note in the README that GitHub disables scheduled workflows after 60 days of inactivity.

Explicit checks

Check Result
Secrets not echoed Pass
Fail-fast APP_ID / APP_PRIVATE_KEY Pass
Fail-fast ACT_BOARD_PROJECT_NUMBER Partial — finding 6
App token not used for w3c/wcag-act-rules Pass
Snapshot commit only on change Pass
act-tools checkout Fail — findings 2 and 3
No PEM in repo Pass

WilcoFiers and others added 2 commits September 18, 2026 12:35
Blocking:
- Check out act-rules.github.io with fetch-depth: 0. The classifier reads
  git history, which a shallow clone silently truncates.
- Pin the act-tools checkout to ref issue-65-project-sync, the act-tools#71
  branch that adds sync-act-board-project and write-act-board-snapshot.
  README says to retarget a main SHA once #71 merges.
- Stop passing the App token to the act-tools checkout; act-tools is not in
  the App's repositories list.

Should fix:
- Add permissions: contents: read and timeout-minutes: 30.
- Add concurrency group sync-act-board with cancel-in-progress: false, and
  git pull --rebase --autostash before pushing the snapshot commit.
- Fail fast on ACT_BOARD_PROJECT_NUMBER in the first guard step, alongside
  the App secrets.
- persist-credentials: false on all three sibling checkouts; only the root
  act-board checkout keeps credentials, for the push.

Minor:
- node-version 24, matching act-tools CI.
- Ignore *.pem and the sibling checkout directories.
- Seed data/snapshot.json as [] so the README link resolves.
- Note that GitHub disables scheduled workflows after 60 days of inactivity.

Co-authored-by: Cursor <cursoragent@cursor.com>
The issue-65-project-sync branch was deleted after merge, so the weekly workflow would fail to clone act-tools.

Co-authored-by: Cursor <cursoragent@cursor.com>
@WilcoFiers
WilcoFiers merged commit 605346e into main Sep 18, 2026
@WilcoFiers
WilcoFiers deleted the issue-65-weekly-sync branch September 18, 2026 10:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant