forgejo-mcp/.tekton/openspec-validate-pr.yaml
Christoph Görn cb6f657644
ci: 🚀 enforce check-demos in PaC and pre-commit
Run the anchored-demo checker automatically instead of relying on
authors to invoke `just check-demos` by hand.

- rewrite checker in POSIX sh (no bashisms) so one script serves local
  shells, the pre-commit hook, and the minimal release-tools CI image;
  shellcheck-clean, verified under sh
- .tekton/tasks/openspec-validate.yaml: add a check-demos step to the
  existing openspec-validate task (same image/workspace/trigger)
- .tekton/openspec-validate-{pr,push}.yaml: also fire when the checker
  script changes
- .pre-commit-config.yaml: local check-demos hook, scoped to
  openspec spec/demo files and the script itself
2026-06-02 00:16:07 +02:00

59 lines
1.7 KiB
YAML

apiVersion: tekton.dev/v1
kind: PipelineRun
metadata:
name: forgejo-mcp-openspec-validate-pr
annotations:
pipelinesascode.tekton.dev/on-cel-expression: |
event == "pull_request" && target_branch == "main" && (
files.all.exists(f, f.startsWith('openspec/')) ||
files.all.exists(f, f == '.tekton/openspec-validate-pr.yaml') ||
files.all.exists(f, f == '.tekton/openspec-validate-push.yaml') ||
files.all.exists(f, f == '.tekton/tasks/openspec-validate.yaml') ||
files.all.exists(f, f == 'scripts/ci/check-spec-demo-anchors.sh')
)
pipelinesascode.tekton.dev/task: "[git-clone, .tekton/tasks/openspec-validate.yaml]"
pipelinesascode.tekton.dev/max-keep-runs: "5"
pipelinesascode.tekton.dev/cancel-in-progress: "true"
spec:
params:
- name: repo_url
value: "{{ repo_url }}"
- name: revision
value: "{{ revision }}"
pipelineSpec:
params:
- name: repo_url
- name: revision
workspaces:
- name: source
tasks:
- name: fetch-source
taskRef:
name: git-clone
workspaces:
- name: output
workspace: source
params:
- name: url
value: $(params.repo_url)
- name: revision
value: $(params.revision)
- name: validate
taskRef:
name: openspec-validate
runAfter:
- fetch-source
workspaces:
- name: source
workspace: source
workspaces:
- name: source
volumeClaimTemplate:
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi