ci: rename caller job ids to avoid colliding with reusable workflow's inner job name #15

Merged
james merged 1 commit from fix/security-scan-job-id-collision into main 2026-09-06 22:35:37 +00:00
Owner

The "two scans running" appearance on PRs isn't two triggers -- both entries share the same run_number/workflow_id/event/sha, and one has ~0 duration (the outer wrapper job dispatching the uses: call) while the other has the real ~25s of work (the reusable workflow's own inner job). They're both named scan (same for renovate), so Forgejo's reusable-workflow expansion suffixes the second one -1 to disambiguate, which reads as a duplicate.

Renaming the caller job ids (scan -> security-scan, renovate -> run-renovate) removes the naming collision so the run just shows one clearly-named wrapper and one clearly-named real job, instead of a confusing pair.

The "two scans running" appearance on PRs isn't two triggers -- both entries share the same run_number/workflow_id/event/sha, and one has ~0 duration (the outer wrapper job dispatching the `uses:` call) while the other has the real ~25s of work (the reusable workflow's own inner job). They're both named `scan` (same for `renovate`), so Forgejo's reusable-workflow expansion suffixes the second one `-1` to disambiguate, which reads as a duplicate. Renaming the caller job ids (`scan` -> `security-scan`, `renovate` -> `run-renovate`) removes the naming collision so the run just shows one clearly-named wrapper and one clearly-named real job, instead of a confusing pair.
ci: rename caller job ids to avoid colliding with reusable workflow's inner job name
All checks were successful
security-scan / scan (pull_request) Successful in 23s
security-scan / security-scan (pull_request) Successful in 0s
test / web (pull_request) Successful in 54s
test / go (pull_request) Successful in 2m6s
cc04d934a5
Both files' caller job was named the same as the reusable workflow's own
inner job (scan/scan, renovate/renovate). Forgejo's reusable-workflow
expansion lists both as sibling rows in the run, and since the names
collided it suffixed the second one -1 -- reading as two separate scans
running when it's actually one wrapper job (near-zero duration) plus one
real execution. Renaming the caller job id removes the collision.
james merged commit e75620f418 into main 2026-09-06 22:35:37 +00:00
james deleted branch fix/security-scan-job-id-collision 2026-09-06 22:35:37 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ColibriSec/balam!15
No description provided.