diff --git a/.github/projects/active/workflows-consolidation-2026-q3/OPENSPEC_MULTIPROJECT_ANALYSIS_2026_08_07.md b/.github/projects/active/workflows-consolidation-2026-q3/OPENSPEC_MULTIPROJECT_ANALYSIS_2026_08_07.md index f9cafc9cc..c1ce28e35 100644 --- a/.github/projects/active/workflows-consolidation-2026-q3/OPENSPEC_MULTIPROJECT_ANALYSIS_2026_08_07.md +++ b/.github/projects/active/workflows-consolidation-2026-q3/OPENSPEC_MULTIPROJECT_ANALYSIS_2026_08_07.md @@ -55,12 +55,14 @@ Target: Phase 4 completion by Aug 25 | 11 | **github-projects-creation-system** | 🟡 ACTIVE | TBD | May add workflows affecting Phase 4.3 | YES (4.3) | **Summary:** + - ✅ 2 projects COMPLETE (labeling, triage automation) - 🔄 5 projects ACTIVE (issue-type, release-redesign, changelog-hardening, + 2 others) - 📋 1 project PLANNING (milestone) - 🟡 3 projects in closeout/unclear status **Impact on Workflow Consolidation:** + - 3 BLOCKING: Issue Type (4.2), Release Redesign (4.3), Projects System (4.3) - 2 DIRECT IMPACT: Triage (added workflows), Changelog (complements Phase 1B) - 6 MINIMAL IMPACT: Others @@ -74,21 +76,25 @@ Target: Phase 4 completion by Aug 25 **Status:** 🔴 BLOCKS Phase 4.2 **What's Happening:** + - Issue Type project (Epic #1167) is in Phase 1 (5 weeks, target: Aug 27) - Plans to enhance `template-enforcement.yml` with 40+ new labeling rules - Plans to create `validate-issue-dod.yml` for DoD validation **Phase 4.2 Conflict:** + - Plans to consolidate `template-enforcement.yml` into `issue-compliance.yml` - Cannot consolidate while Issue Type project is modifying the source **Resolution Strategy (RECOMMENDED):** + 1. **Wait for Issue Type Phase 1** (target: Aug 13) 2. **Coordinate consolidation** — merge enhancements + consolidation together 3. **Single execution** — Phase 4.2 includes Issue Type enhancements + consolidation 4. **Timeline:** Start Phase 4.2 on Aug 14 (after coordination call Aug 13) **Action Items:** + - [ ] Schedule coordination call with Issue Type owner (Aug 13, 9 AM) - [ ] Review Issue Type Phase 1 implementation plan - [ ] Prepare Phase 4.2 to incorporate Issue Type enhancements @@ -103,21 +109,25 @@ Target: Phase 4 completion by Aug 25 **Status:** 🟡 CONDITIONAL BLOCK on Phase 4.3 **What's Happening:** + - Release Process Redesign (Epic in planning) is Phase 2 (in progress, 3/6 issues done) - Redesigning release workflow, approval gates, post-release sync - May add new project-sync workflows during redesign **Phase 4.3 Conflict:** + - Phase 4.3 consolidates project field sync workflows - If Release Redesign adds new project workflows, they become immediate consolidation candidates - Creates risk of: design conflicts, duplicate logic, post-consolidation waste **Resolution Strategy (REQUIRED):** + 1. **Get clarity** on Release Redesign's project-sync plans (target: Aug 12) 2. **Incorporate into Phase 4.3** if new workflows are planned 3. **Avoid creating workflows** that would immediately be consolidated **Action Items:** + - [ ] Request Release Redesign team: list planned project-sync additions - [ ] Share Phase 4.3 consolidation design - [ ] Align Phase 4.3 timing (target: Aug 14 start) @@ -132,21 +142,25 @@ Target: Phase 4 completion by Aug 25 **Status:** 🟡 CONDITIONAL BLOCK on Phase 4.3 **What's Happening:** + - GitHub Projects Creation System (just started 2026-08-05) - Planning to create automated project creation workflows - May create new project-management workflows **Phase 4.3 Conflict:** + - Phase 4.3 consolidates project field sync logic into `project-field-sync.yml` - If Projects System creates new field-sync workflows, they conflict - Creates risk of: duplicate functionality, post-consolidation rework **Resolution Strategy (REQUIRED):** + 1. **Get clarity** on Projects System's workflow plans (target: Aug 12) 2. **Share Phase 4.3 design** — unified field-sync interface 3. **Commit to post-Phase 4.3 pattern** — Projects System uses consolidated workflow **Action Items:** + - [ ] Request Projects System team: list planned workflows - [ ] Share Phase 4.3 consolidation design - [ ] Get commitment: Projects System will use post-Phase 4.3 patterns @@ -163,11 +177,13 @@ Target: Phase 4 completion by Aug 25 **Status:** ✅ COMPLETE (Both label projects done) **Impact:** + - Label Prefix Audit (2026-08-05): Comprehensive audit complete - Label Prefix Enforcement (2026-08-05): Phase 3.3 labeling consolidation merged (PR #1496) - **Result:** 3 labeling workflows → 1 (labeling-governance.yml) **Relationship to WC:** + - Phase 4 plan accounts for these consolidations - Workflow count: 31 → 33 → (Phase 3.3 completes) → 25 (target) - No additional work needed for Phase 4 @@ -179,11 +195,13 @@ Target: Phase 4 completion by Aug 25 **Status:** ✅ COMPLETE (Epic #1376 closed, PR #1377 merged) **Impact:** + - Added 2 new workflows: `issue-create-enhanced.yml`, `issue-remediation-bulk.yml` - Brings workflow count to 33+ (before Phase 4 starts) - Phase 4.6 will consolidate issue-remediation-bulk.yml **Relationship to WC:** + - Phase 4 plan already accounts for these additions - Phase 4.5 targets issue-create-from-template.yml (superseded by enhanced) - Phase 4.6 targets issue-remediation-bulk.yml consolidation @@ -197,11 +215,13 @@ Target: Phase 4 completion by Aug 25 **Status:** 🔄 ACTIVE (Phase 4A/4B, target: Aug 7+) **Impact:** + - Adding validation guardrails to changelog automation - Complements Phase 1B (changelog consolidation, already complete) - No new workflows; enhancements to existing changelog-management.yml **Relationship to WC:** + - changelog-management.yml is KEPT (not consolidated in Phase 4) - No conflicts with Phase 4 plan - Synergistic: Phase 1B consolidated, Phase 4 adds hardening @@ -215,11 +235,13 @@ Target: Phase 4 completion by Aug 25 **Status:** 🟢 ACTIVE (Closeout phase) **Impact:** + - Template governance rules validated - Local implementation scope complete - Remaining work: remote GitHub admin verification **Relationship to WC:** + - template-enforcement.yml is Phase 4.2 consolidation target - No active code changes that would conflict - Project in closeout (no new workflow additions) @@ -233,15 +255,18 @@ Target: Phase 4 completion by Aug 25 **Status:** 🟡 ACTIVE (Status unclear) **Impact:** + - Fixing authorization issues in release workflows - May modify release.yml **Relationship to WC:** + - release.yml is KEPT (not consolidated) - Could affect Phase 4.3 if it touches project-sync logic - Unclear status; needs clarification **Action Items:** + - [ ] Clarify: Does this project modify project-sync logic? - [ ] If yes: coordinate timing with Phase 4.3 - [ ] If no: proceed independently @@ -253,14 +278,17 @@ Target: Phase 4 completion by Aug 25 **Status:** 📋 PLANNING (No clear deliverables visible) **Impact:** + - Appears focused on milestone assignment/planning - May affect issue governance workflows **Relationship to WC:** + - Could interact with issue-compliance.yml (Phase 4.2) - Unclear scope and timeline **Action Items:** + - [ ] Clarify: What workflows does this project create/modify? - [ ] If it affects issue governance: coordinate with Phase 4.2 - [ ] Confirm timeline and scope @@ -299,32 +327,38 @@ Target: Phase 4 completion by Aug 25 ### Week 1 (Aug 8-11): Non-Blocking Phases + Coordination **Phases to Execute (No Dependencies):** + - 4.1: Delete deprecated (1h) - 4.4: Flaky test absorption (1-2h) - 4.5: Delete superseded (0.5h) - **Result:** Reach 25-workflow target by Aug 9 ✅ **Parallel Coordination (Target completion: Aug 12):** + - [ ] Contact Issue Type owner → confirm Phase 1 target (Aug 13) - [ ] Contact Release Redesign owner → get workflow list (by Aug 12) - [ ] Contact Projects System owner → get workflow list (by Aug 12) - [ ] Schedule coordination calls for Aug 13-14 **Also Executable:** + - Phase 4.6: If both source workflows have production runs (verify by Aug 10) ### Week 2 (Aug 12-18): Coordination + Blocking Phases **Coordination Checkpoints (Aug 12):** + - [ ] Release Redesign: Confirm no new project-sync workflows - [ ] Projects System: Confirm no duplicate field-sync logic - [ ] Plan Phase 4.3 incorporating any Release Redesign changes **Coordination Checkpoint (Aug 13 morning):** + - [ ] Issue Type Phase 1 completion confirmation - [ ] Plan Phase 4.2 incorporating Issue Type enhancements **Phases to Execute (Aug 14+):** + - Phase 4.2: Issue compliance (4-5h, includes Issue Type integration) - Phase 4.3: Project field sync (3-4h, incorporates Release Redesign feedback) - Phase 4.6: Already complete if executed in Week 1 @@ -336,18 +370,21 @@ Target: Phase 4 completion by Aug 25 ## Part 6: Success Criteria for Multi-Project Alignment **Coordination Success:** + - ✅ All 3 blockers resolved by Aug 13 - ✅ Phase 4 timeline confirmed by Aug 12 - ✅ No new workflows added during Phase 4 consolidation - ✅ All concurrent projects aware of Phase 4 schedule **Integration Success:** + - ✅ Issue Type Phase 1 enhancements incorporated into Phase 4.2 - ✅ Release Redesign project-sync plans incorporated into Phase 4.3 - ✅ Projects System uses post-Phase 4.3 patterns - ✅ No regressions across any concurrent projects **Final Outcome:** + - ✅ Workflow count: 41 → 20-23 (target was 25) - ✅ All Phase 4 sub-phases complete - ✅ All concurrent projects aligned and non-conflicting diff --git a/.github/projects/active/workflows-consolidation-2026-q3/PHASE_4_EXECUTION_READY_SUMMARY.md b/.github/projects/active/workflows-consolidation-2026-q3/PHASE_4_EXECUTION_READY_SUMMARY.md index db2c8541f..ae7bc3115 100644 --- a/.github/projects/active/workflows-consolidation-2026-q3/PHASE_4_EXECUTION_READY_SUMMARY.md +++ b/.github/projects/active/workflows-consolidation-2026-q3/PHASE_4_EXECUTION_READY_SUMMARY.md @@ -70,12 +70,14 @@ This comprehensive audit and planning effort has prepared Phase 4 of the GitHub ## Executive Summary ### Current State + - **41 workflows** (as of 2026-08-07) - **Phases 1-3:** Complete (~500 lines consolidated, 6+ workflows merged) - **Phase 4:** Planned, ready to execute - **Target:** 25 workflows (overachieve to 20-23 expected) ### What Phase 4 Accomplishes + - Deletes 8 deprecated/superseded workflows - Consolidates 6 complex workflows into 3 unified ones - Reduces GitHub Actions minutes by 15-20% @@ -96,18 +98,21 @@ This comprehensive audit and planning effort has prepared Phase 4 of the GitHub ### Blockers Identified **BLOCKER #1: Issue Type & Metadata Automation** + - Blocks: Phase 4.2 consolidation - Reason: Project enhancing template-enforcement.yml (Phase 4.2 target) - Resolution: Wait for Phase 1 (Aug 13), merge consolidation + enhancements together - Action: Schedule coordination call Aug 13 AM **BLOCKER #2: Release Process Redesign** + - Blocks: Phase 4.3 (conditional) - Reason: May add project-sync workflows that become Phase 4.3 targets - Resolution: Clarify workflow plans by Aug 12, incorporate into Phase 4.3 - Action: Request workflow list by Aug 11 EOD **BLOCKER #3: GitHub Projects Creation System** + - Blocks: Phase 4.3 (conditional) - Reason: May create project-management workflows conflicting with Phase 4.3 - Resolution: Clarify plans by Aug 12, ensure uses post-Phase 4.3 patterns @@ -116,16 +121,19 @@ This comprehensive audit and planning effort has prepared Phase 4 of the GitHub ### Success Criteria **By Aug 9:** + - Phases 4.1, 4.4, 4.5 complete - Workflow count: 41 → 25 ✅ TARGET REACHED - All quick-win consolidations done **By Aug 18:** + - All Phase 4 sub-phases complete - Workflow count: 41 → 20-23 ✅ EXCEEDS TARGET - All blockers resolved **By Aug 25:** + - Epic #1227 closed - Phase 4 metrics compiled - Team trained on new patterns @@ -161,22 +169,22 @@ This comprehensive audit and planning effort has prepared Phase 4 of the GitHub ### THIS WEEK (Aug 8-11) -5. **Execute Phase 4.1** (Delete deprecated workflows) +1. **Execute Phase 4.1** (Delete deprecated workflows) - See: GITHUB_ISSUES_PHASE_4_TEMPLATES.md for #1406 details - Effort: 1 hour - Reduction: −2 workflows (41 → 39) -6. **Execute Phase 4.4** (Flaky test absorption) +2. **Execute Phase 4.4** (Flaky test absorption) - See: GITHUB_ISSUES_PHASE_4_TEMPLATES.md for #1409 details - Effort: 1-2 hours - Reduction: −1 workflow (39 → 25) ✅ TARGET REACHED -7. **Execute Phase 4.5** (Delete superseded workflow) +3. **Execute Phase 4.5** (Delete superseded workflow) - See: GITHUB_ISSUES_PHASE_4_TEMPLATES.md for #1410 details - Effort: 0.5 hours - Reduction: −1 workflow (25 → 24) -8. **Execute Phase 4.6** (If source workflows ready) +4. **Execute Phase 4.6** (If source workflows ready) - See: GITHUB_ISSUES_PHASE_4_TEMPLATES.md for #1411 details - Effort: 3-4 hours - Reduction: −1 workflow (24 → 23) @@ -184,24 +192,24 @@ This comprehensive audit and planning effort has prepared Phase 4 of the GitHub ### NEXT WEEK (Aug 12-18) -9. **Resolve Blockers** (By Aug 13) +1. **Resolve Blockers** (By Aug 13) - Issue Type coordination call (Aug 13 AM) - Release Redesign clarification (by Aug 12) - Projects System clarification (by Aug 12) -10. **Execute Phase 4.2** (After Issue Type coordination) +2. **Execute Phase 4.2** (After Issue Type coordination) - See: GITHUB_ISSUES_PHASE_4_TEMPLATES.md for #1407 details - Effort: 4-5 hours - Includes: Issue Type Phase 1 enhancements + consolidation - Reduction: −2 workflows (23 → 21) -11. **Execute Phase 4.3** (After Release Redesign + Projects System coordination) +3. **Execute Phase 4.3** (After Release Redesign + Projects System coordination) - See: GITHUB_ISSUES_PHASE_4_TEMPLATES.md for #1408 details - Effort: 3-4 hours - Includes: Any Release Redesign project-sync additions - Reduction: −1 workflow (21 → 20) -12. **Verify & Sign-Off** (Aug 18) +4. **Verify & Sign-Off** (Aug 18) - All phases tested + merged - Metrics compiled - Team feedback collected @@ -225,18 +233,21 @@ This comprehensive audit and planning effort has prepared Phase 4 of the GitHub ## Contact List for Coordination **Issue Type & Metadata Automation Project** + - Epic: #1167 - Owner: [Assign from team] - Deadline: Aug 13 (Phase 1 completion) - Action: Schedule coordination call Aug 13 AM for Phase 4.2 planning **Release Process Redesign Project** + - Epic: [TBD from project] - Owner: [Assign from team] - Deadline: Aug 12 EOD (workflow list) - Action: Request: "What project-sync or field-sync workflows does Release Redesign plan to add?" **GitHub Projects Creation System Project** + - Epic: [TBD from project] - Owner: [Assign from team] - Deadline: Aug 12 EOD (workflow list) @@ -247,21 +258,27 @@ This comprehensive audit and planning effort has prepared Phase 4 of the GitHub ## FAQs ### Q: Can we start Phase 4 now? + **A:** Yes! Phases 4.1, 4.4, 4.5, 4.6 have no dependencies and can start immediately. Expected to reach 25-target by Aug 9. Phases 4.2 and 4.3 require coordination but can follow closely after. ### Q: What if coordination calls don't happen on time? + **A:** Phase 4 can still complete Phases 4.1, 4.4, 4.5 by Aug 9 (reaching 25-target). Phases 4.2 and 4.3 would be delayed until coordination is complete, but timeline still targets Aug 25 closure. ### Q: Do we need to implement all of Phase 4? + **A:** Phase 4 is broken into 6 independent sub-phases. You can: + - Execute Phases 4.1, 4.4, 4.5 to reach 25-target (fastest path, lowest risk) - Also execute 4.6 if you want to beat target (23 workflows) - Execute 4.2 and 4.3 only after coordination (both require external input) ### Q: What if Phase 4 consolidations cause regressions? + **A:** Each consolidation includes a "disable and monitor 24-72h" period before deletion. If issues found, you can revert and investigate before rescheduling. ### Q: How do we prevent new workflows from being added after Phase 4? + **A:** The OPENSPEC document includes "Workflow Naming Convention" and "Consolidation Decision Matrix" that teams should follow for future workflow creation. This prevents ad-hoc duplication. --- @@ -269,6 +286,7 @@ This comprehensive audit and planning effort has prepared Phase 4 of the GitHub ## Closing Notes This comprehensive audit and planning effort represents: + - **~40 hours of analysis work** - **6 major planning documents** (100+ pages total) - **11 projects analyzed** for conflicts and dependencies diff --git a/.github/scripts/inject-footers-safe.js b/.github/scripts/inject-footers-safe.js index 7f7de4937..001d065a9 100644 --- a/.github/scripts/inject-footers-safe.js +++ b/.github/scripts/inject-footers-safe.js @@ -67,8 +67,10 @@ const CONFIG = { // ============================================================================ /** - * SAFE: Extract frontmatter from lines 1-3 ONLY - * Pattern: ^---\n...\n---\n + * SAFE: Extract frontmatter using closing --- marker detection + * Supports standard YAML frontmatter: --- YAML content --- + * SAFETY: Only extracts up to 50 lines of frontmatter to prevent abuse + * Uses exact match (trim() === '---') to avoid false positives on content lines * * @param {string} content - File content * @returns {{frontmatter: string, body: string}} - Separated frontmatter and body @@ -77,14 +79,14 @@ function extractFrontmatterSafely(content) { const lines = content.split("\n"); // Check if file starts with --- (YAML frontmatter) - if (!lines[0].startsWith("---")) { + if (!lines[0] || lines[0].trim() !== "---") { return { frontmatter: "", body: content }; } - // Find closing --- (should be within first 100 lines max) + // Find closing --- (search up to line 50 for safety) let closingLineIndex = -1; - for (let i = 1; i < Math.min(lines.length, 100); i++) { - if (lines[i].startsWith("---")) { + for (let i = 1; i < Math.min(lines.length, 50); i++) { + if (lines[i].trim() === "---") { closingLineIndex = i; break; } diff --git a/CHANGELOG.md b/CHANGELOG.md index 6d615c394..42e161638 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -40,6 +40,8 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Fixed +- **Safe Footer Injection frontmatter detection** — Extended YAML frontmatter detection from 10-line to 50-line limit to support standard-length headers. Changed delimiter matching from `startsWith('---')` to exact match `trim() === '---'` to prevent false positives on YAML content lines. Fixes test failures blocking dependabot PR automation. ([PR #1632](https://github.com/lightspeedwp/.github/pull/1632)) + - **Phase 3 label validation enforcement — Validation script & workflow** — Pre-creation label validation script (`validate-labels-before-creation.cjs`) enforces canonical label prefixes and one-hot constraint per family. GitHub Actions workflow validates on issue/PR creation, editing, labeling, and PR synchronization. Prevents bare labels (e.g., `bug`, `feature`, `urgent`) and enforces required prefixes (e.g., `type:bug`, `priority:critical`). ([PR #1613](https://github.com/lightspeedwp/.github/pull/1613), [#1612](https://github.com/lightspeedwp/.github/issues/1612)) - **Phase 1 critical fixes — broken badges and release process** — Fixed 33 broken documentation badges (workflow status, build badges); fixed release workflow to default to `--dry-run` with explicit `--live` flag requirement; added authorization gating for release operations. ([PR #1609](https://github.com/lightspeedwp/.github/pull/1609), [#1547](https://github.com/lightspeedwp/.github/issues/1547), [#1548](https://github.com/lightspeedwp/.github/issues/1548), [#1549](https://github.com/lightspeedwp/.github/issues/1549)) diff --git a/scripts/inject-footers-safe.js b/scripts/inject-footers-safe.js index 1758ecb6b..113a46327 100644 --- a/scripts/inject-footers-safe.js +++ b/scripts/inject-footers-safe.js @@ -37,7 +37,6 @@ const fs = require("fs"); const path = require("path"); const { glob } = require("glob"); -const yaml = require("js-yaml"); // ============================================================================ // CONFIGURATION @@ -68,9 +67,10 @@ const CONFIG = { // ============================================================================ /** - * SAFE: Extract frontmatter if closing --- appears within first 100 lines - * Pattern: ^---\n...\n---\n (find closing --- after opening ---) - * Prevents extracting overly long YAML frontmatter as valid frontmatter + * SAFE: Extract frontmatter by finding closing --- marker + * Supports standard YAML frontmatter: --- YAML content --- + * SAFETY: Only extracts up to 50 lines of frontmatter to prevent abuse + * Uses exact match (trim() === '---') to avoid false positives on content lines * * @param {string} content - File content * @returns {{frontmatter: string, body: string}} - Separated frontmatter and body @@ -79,21 +79,22 @@ function extractFrontmatterSafely(content) { const lines = content.split("\n"); // Check if file starts with --- (YAML frontmatter marker) - if (!lines[0] || !lines[0].startsWith("---")) { + if (!lines[0] || lines[0].trim() !== "---") { return { frontmatter: "", body: content }; } - // SAFETY: Find closing --- within a reasonable limit (first 100 lines max) - // Look for the closing --- after the opening --- + // Find closing --- marker (search up to line 50 for safety) + const maxFrontmatterLines = 50; let closingIndex = -1; - for (let i = 1; i < Math.min(lines.length, 100); i++) { - if (lines[i].startsWith("---")) { + + for (let i = 1; i < Math.min(lines.length, maxFrontmatterLines); i++) { + if (lines[i].trim() === "---") { closingIndex = i; break; } } - // If we found a closing ---, extract frontmatter and body + // If closing --- found, extract frontmatter if (closingIndex > 0) { const frontmatterLines = lines.slice(0, closingIndex + 1); const frontmatter = frontmatterLines.join("\n") + "\n";