Reusable GitHub Actions workflows, independent from any organisation's shared catalogue.
| Workflow | Purpose |
|---|---|
| release-please.yml | Release PR, tag and GitHub Release (single branch or dev → main prerelease flow) |
| sync-prerelease-branch.yml | Rebases dev on main after a release |
| python-lint.yml | ruff check + ruff format --check |
| python-typecheck.yml | ty (default), mypy or pyright on a uv project |
| scan-gitleaks.yml | gitleaks: leaked secrets in the git history (optional Security tab upload) |
| scan-trivy.yml | Trivy: dependencies, misconfigurations, container images |
| lint-helm.yml | chart-testing + helm-docs: Helm chart lint |
| build-docker.yml | buildx: build and push an image to ghcr.io or another registry |
| path-filter.yml | Which folders changed, to skip the jobs that do not apply |
| status-gate.yml | One required check that aggregates the other jobs |
| lint-commits.yml | commitlint: commits follow Conventional Commits |
| python-deadcode.yml | vulture: unused code |
Also provided: a shared Renovate preset and a Dependabot config (how to choose).
Full documentation is in docs/: getting started, release flow, one page per workflow, and troubleshooting.
Call a workflow from your project with uses: Mitchou10/github-workflow/.github/workflows/<name>.yml@v0.
Ready-to-copy callers and configs live in examples/.
This repo is versioned as a whole by release-please (see release.yml),
using conventional commits: feat: → minor, fix: → patch, feat!: / BREAKING CHANGE → major.
Every release moves the floating tags vX and vX.Y, so callers can pin @v0 (auto-updates),
@v0.1 or an exact @v0.1.2. A change to any workflow's inputs/outputs that breaks callers must be
committed as a breaking change.
Runs commitlint (pinned) on the commits of a pull request, or of a push. Add it on pull_request, see
examples/commits/caller.yml. Set LINT_PR_TITLE with squash merges. Allowed types,
scope requirement and header length are inputs; CONFIG_FILE swaps in your own commitlint config.
To block merging on failure, mark the job as a required status check in the branch protection.
Both run at the repository root by default; pass WORKING_DIRECTORY to target a sub-project.
See examples/python/caller.yml for all inputs.
Ruff rules: if the project has its own config (ruff.toml, .ruff.toml or [tool.ruff] in pyproject.toml),
it is used as is. Otherwise the defaults apply (RULES = E,F,I,UP,B, LINE_LENGTH = 120). Setting the
RULES, IGNORE, LINE_LENGTH or CONFIG_FILE inputs overrides either.
The typecheck needs a uv project (uv sync).
- Copy caller.yml to
.github/workflows/release.yml. - Copy release-please-config.json and .release-please-manifest.json to the repo root.
- Use conventional commits (
feat:,fix:, …). - Repo settings → Actions → allow "Read and write permissions" and "Allow GitHub Actions to create and approve pull requests".
Branches: main is production (stable vX.Y.Z), dev carries release candidates (vX.Y.Z-rc.N).
Copy also the -rc config/manifest, and keep the sync-prerelease-branch job last in the caller: after a
release it rebases dev on main. Create dev from main before the first run (the sync job also does it).
Auth: by default GITHUB_TOKEN is used, so the release PR does not trigger CI. Pass APP_CLIENT_ID +
APP_PRIVATE_KEY (or GH_PAT) to make it trigger checks.
Outputs: release-created, version, tag-name, pr-created.