Skip to content

chore: drop the last workflow from main - #407

Closed
samijaber wants to merge 1 commit into
mainfrom
chore/remove-main-workflow
Closed

samijaber wants to merge 1 commit into
mainfrom
chore/remove-main-workflow

Conversation

@samijaber

@samijaber samijaber commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Step 2 of emptying main's .github/workflows. After this, the directory is empty.

Why

main is what customers clone. Anything under .github/workflows here either leaks Builder-internal automation into customer repos or — because the Builder GitHub App has no workflows permission — blocks them from pushing when they migrate to their own remote.

What

Delete create-template-snapshot.yml. Its golden snapshot request moves inline into sync.yml on the template branch.

The sync preserves main's own .github across merges (git checkout HEAD -- .github), so this deletion sticks.

Ordering

Merge after the companion template PR. Until that lands, sync.yml still dispatches this workflow by name and will fail without it.


Related

One investigation, four PRs. A customer hit refusing to allow a GitHub App to create or update workflow ... without workflows permission when migrating an Agent Native project to their own GitHub repo. Root cause: goldens were shipping the starter's workflow files into customer repos.

PR Repo What
BuilderIO/ai-services#6341 ai-services Bake goldens from a virgin first boot so the .github scrub runs
BuilderIO/ai-services#6342 ai-services Require and enforce golden provenance (fusion-git-sha)
#406 starter (template) Request the golden snapshot inline
#407 starter (main) Drop the last workflow from main

6341 and 6342 are independent. 406 must merge before 407.

Not addressed here: the Builder GitHub App manifest requests contents: write but not workflows, so it cannot push any .github/workflows/** change to a customer repo. That is a separate permission decision.

main is what customers clone, so .github/workflows is now empty. The
golden snapshot request it served moves inline into sync.yml on the
template branch, where the pushed main SHA is already in hand.

Merge the template-branch change first; until it lands the sync still
dispatches this workflow by name.
@samijaber

Copy link
Copy Markdown
Contributor Author

Wrong approach — main is machine-written by sync.yml, so a commit deleting the file there would be overwritten on the next sync. Folded into #406 instead, which adds the path to .github/starter-patch/delete.txt on the template branch so apply.mjs drops it from main on every sync.

@samijaber samijaber closed this Sep 23, 2026
@samijaber
samijaber deleted the chore/remove-main-workflow branch September 23, 2026 18:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant