From f71a5aab39440318fcaa5e95694ec7cf533e4878 Mon Sep 17 00:00:00 2001 From: Kit OC5 Date: Wed, 23 Sep 2026 19:11:20 -0400 Subject: [PATCH] ci-hygiene allow: windy-pro disabled deploy job (needs-docker false positive) Co-Authored-By: Claude Opus 5.5 --- ci/ci-hygiene-allow.yml | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/ci/ci-hygiene-allow.yml b/ci/ci-hygiene-allow.yml index c33b7da..fdd8c98 100644 --- a/ci/ci-hygiene-allow.yml +++ b/ci/ci-hygiene-allow.yml @@ -2,4 +2,12 @@ # a host port. House rule 6 (09-23): installs come from a lockfile. Every entry # is an exception and MUST say why. Paths are fnmatch globs from the repo root. # Owner: Windy Git lane (13); changes go through the orchestrator. -allow: [] +allow: + - repo: windy-pro + paths: [".github/workflows/ci.yml"] + # ONLY the old deploy job's two docker lines. That job is `if: false` + # (CD boundary, 2026-07), and the compose line runs ON windyword.ai inside + # the ssh string. Any other docker step in ci.yml still flags. + matches: ['docker build -f account-server/Dockerfile -t windy-pro:', 'docker compose down && docker compose up -d --build'] + reason: "needs-docker false positive: the deploy job is if: false and its compose runs on the remote host over ssh. Added with the needs-docker rule (orchestrator option A, 09-23)." +