Derive repository from github context, drop with: inputs #3

Merged
james merged 2 commits from simplify/derive-repo-from-context into main 2026-09-06 21:54:14 +00:00
Owner

Reusable workflows run with the calling repo's own github context, so github.repository is already owner/name for whichever repo invoked this � no input needed, and nothing for a caller to get wrong. (This already happened once: security-scan.yml callers were copy-pasted with the wrong repo name under the wrong input key.)

  • security-scan.yml drops product-name, derives it from github.repository.
  • renovate.yml drops repository, passes github.repository to the Renovate CLI directly.

A caller now needs nothing but uses: + secrets: � no with: block at all.

Also documents pinning callers to a commit SHA rather than @main.

Reusable workflows run with the calling repo's own `github` context, so `github.repository` is already `owner/name` for whichever repo invoked this � no input needed, and nothing for a caller to get wrong. (This already happened once: `security-scan.yml` callers were copy-pasted with the wrong repo name under the wrong input key.) - `security-scan.yml` drops `product-name`, derives it from `github.repository`. - `renovate.yml` drops `repository`, passes `github.repository` to the Renovate CLI directly. A caller now needs nothing but `uses:` + `secrets:` � no `with:` block at all. Also documents pinning callers to a commit SHA rather than `@main`.
Derive repository from github context, drop with: inputs
Some checks failed
renovate.yml / Derive repository from github context, drop with: inputs (push) Failing after 0s
security-scan.yml / Derive repository from github context, drop with: inputs (push) Failing after 0s
renovate.yml / Derive repository from github context, drop with: inputs (pull_request) Failing after 0s
security-scan.yml / Derive repository from github context, drop with: inputs (pull_request) Failing after 0s
bb403bed1d
Reusable workflows run with the calling repo's own github context, so
github.repository is already "owner/name" for whichever repo invoked
this. Passing it as an explicit input just gave callers a value to get
wrong (already happened once: security-scan.yml callers were copy-pasted
with the wrong repo name under the wrong input key).

- security-scan.yml: drops the product-name input, derives it from
  github.repository instead.
- renovate.yml: drops the repository input, passes github.repository to
  the renovate CLI directly.

A caller now needs nothing but uses: + secrets: — no with: block, and
nothing left to copy-paste wrong.

Also documents: pin callers to a commit SHA, not @main (a mutable ref
would let a future push here change what every caller executes, since
these run with access to whatever secrets the caller passes).
Run these workflows on this repo too, not just as callees
Some checks failed
renovate.yml / Run these workflows on this repo too, not just as callees (push) Failing after 0s
security-scan.yml / Run these workflows on this repo too, not just as callees (push) Failing after 0s
renovate.yml / Run these workflows on this repo too, not just as callees (pull_request) Failing after 0s
security-scan.yml / Run these workflows on this repo too, not just as callees (pull_request) Failing after 0s
renovate.yml / Merge pull request 'Derive repository from github context, drop with: inputs' (#3) from simplify/derive-repo-from-context into main (pull_request) Failing after 0s
security-scan.yml / Merge pull request 'Derive repository from github context, drop with: inputs' (#3) from simplify/derive-repo-from-context into main (pull_request) Failing after 0s
80555fad49
Both files now trigger directly (push/pull_request for security-scan,
schedule/workflow_dispatch for renovate) in addition to workflow_call —
same behavior either way since everything's derived from context, so
there's nothing repo-specific to duplicate into a separate caller file.

Needs BALAM_URL, BALAM_TOKEN, and RENOVATE_TOKEN secrets configured on
this repo directly (previously only needed by callers).
james merged commit 8f90496e34 into main 2026-09-06 21:54:14 +00:00
james deleted branch simplify/derive-repo-from-context 2026-09-06 21:54:14 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ColibriSec/forgejo-workflows!3
No description provided.