Skip to content

ci: refresh NVSkills CI workflow for fork validation - #379

Merged
rapids-bot[bot] merged 1 commit into
NVIDIA:mainfrom
AjayThorve:refactor/nvskills-ci-fork-template
Oct 9, 2026
Merged

rapids-bot[bot] merged 1 commit into
NVIDIA:mainfrom
AjayThorve:refactor/nvskills-ci-fork-template

Conversation

@AjayThorve

@AjayThorve AjayThorve commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Overview

Refresh the NVSkills CI reusable workflow pin to match the current NVIDIA Skills caller template, which includes support and guidance for maintainer-requested validation of fork PRs.

The caller already has the template's event filters, permissions, and secret mapping. This change replaces the August revision with the current revision while preserving the repository's immutable SHA pinning convention. No public API or breaking changes.

Details

  • Pin team-request.yml to 14a98ae278cec7e867695189d0f4003c08e4f765 (NVIDIA Skills main as of 2026-10-09).
  • Keep read-only caller permissions and the explicit dispatch-secret mapping.
  • Fork validation still requires an admin or maintainer of the base repository to comment /nvskills-ci, and the configured signing service account needs write access to the fork.

Central enablement is still required: NeMo-Fabric's onboarding entry currently inherits allow_fork_pull_requests: false. The NVSkills service owner must set allow_fork_pull_requests: true for this repository before fork requests can succeed. This caller update alone does not enable them.

Validation

  • pre-commit run --files .github/workflows/request-nvskills-ci.yml passed, including actionlint and copyright validation.
  • just --fmt --check passed.
  • git diff --check passed.
  • Compared the caller with the template at the pinned revision: identical apart from the SPDX header and immutable workflow reference.
  • Inspected the reusable caller, required-status workflow, and central fork policy. No live NVSkills dispatch was run; this change does not touch watched skills paths and central fork enablement remains pending.

Where should the reviewer start?

.github/workflows/request-nvskills-ci.yml: the reusable workflow SHA is the only changed line. Review the central enablement dependency above before treating fork validation as available.

Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)

  • Relates to: none

  • I confirm this contribution is my own work, or I have the right to submit it under this project's license.

  • I searched existing issues and open pull requests, and this does not duplicate existing work.

Summary by CodeRabbit

  • Chores
    • Updated the automation that handles NVIDIA skills CI requests. The workflow’s existing conditions, permissions, and secret handling remain unchanged.
  • User-facing changes
    • No changes to end-user features or behavior.

Signed-off-by: Ajay Thorve <athorve@nvidia.com>
@AjayThorve
AjayThorve requested a review from a team as a code owner October 9, 2026 17:55
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/NeMo-Fabric/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Enterprise
  • Run ID: 69bd84ad-4ea6-4d96-9ce4-48987bc1c44f

📥 Commits

Reviewing files that changed from the base of the PR and between c359c4d and 079bd36.


📒 Files selected for processing (1)
  • .github/workflows/request-nvskills-ci.yml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📜 Recent review details
⏰ Context from checks skipped due to timeout. (27)
  • GitHub Check: Pre-commit
  • GitHub Check: Test (Python 3.13, windows-amd64)
  • GitHub Check: Test adapters (Node 24)
  • GitHub Check: Test (x86_64)
  • GitHub Check: Test (Python 3.12, linux-arm64)
  • GitHub Check: Test (Python 3.13, macos-arm64)
  • GitHub Check: Test (Python 3.12, macos-arm64)
  • GitHub Check: Test (Python 3.14, linux-arm64)
  • GitHub Check: Test (Python 3.12, windows-amd64)
  • GitHub Check: Test (Python 3.13, linux-arm64)
  • GitHub Check: Test (Python 3.14, macos-arm64)
  • GitHub Check: Test (Python 3.14, linux-amd64)
  • GitHub Check: Test (Node 20.18.3)
  • GitHub Check: Test (Python 3.13, linux-amd64)
  • GitHub Check: Test adapters (Node 22.19.0)
  • GitHub Check: Test (Python 3.11, linux-arm64)
  • GitHub Check: Test (Python 3.11, linux-amd64)
  • GitHub Check: Test (Python 3.11, macos-arm64)
  • GitHub Check: Test (arm64)
  • GitHub Check: Cline E2E
  • GitHub Check: Test (Python 3.12, linux-amd64)
  • GitHub Check: Test (Node 24)
  • GitHub Check: Qwen Code E2E
  • GitHub Check: Test (Python 3.11, windows-amd64)
  • GitHub Check: OpenCode E2E
  • GitHub Check: Test (Python 3.14, windows-amd64)
  • GitHub Check: Hermes adapter (upstream Relay 0.9, Python 3.14)

🧰 Additional context used
📚 Code guidelines (1)
.agents/skills/maintain-ci/SKILL.md — configured

📓 Path-based instructions (1)
Source excerpt: Use this skill when a change touches `.github/workflows/*.yml` or `.github/workflows/*.yaml`, or when reviewing CI behavior for security, reliability, or reproducibility.

📄 CodeRabbit inference engine (.agents/skills/maintain-ci/SKILL.md)

Files:

  • .github/workflows/request-nvskills-ci.yml


🪛 zizmor (1.30.1)
.github/workflows/request-nvskills-ci.yml

[warning] 4-30: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block

(excessive-permissions)




🔇 Additional comments (1)
.github/workflows/request-nvskills-ci.yml (1)

27-27: LGTM!





Walkthrough

The request job now references the team-request workflow at commit 14a98ae278cec7e867695189d0f4003c08e4f765. Its conditions, permissions, and secret mapping remain unchanged.

Changes

NVSkills workflow pin

Layer / File(s) Summary
Update workflow reference
.github/workflows/request-nvskills-ci.yml
The request job now uses the team-request workflow at commit 14a98ae278cec7e867695189d0f4003c08e4f765 instead of 4f1e9e3e0e6913fbd5822acf4757aa6631e87cef.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 079bd

The workflow pin is compatible with its caller and presents no actionable merge-blocking risk. Fork validation still requires the separately reported central opt-in.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check Passed The title uses the allowed lowercase type ci, provides a concise imperative summary, stays under 72 characters, and has no trailing period.
Description check Passed The description includes the required Overview, reviewer guidance, Related Issues, and contribution confirmation sections. It also documents the changed workflow pin, validation results, and the pendi…
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.


✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@AjayThorve

Copy link
Copy Markdown
Collaborator Author

/merge

@rapids-bot
rapids-bot Bot merged commit 388fb36 into NVIDIA:main Oct 9, 2026
43 checks passed

This branch was successfully deployed

1 active deployment
fern — 079bd360 Deployed Oct 9, 2026 by rapids-bot[bot] via Clean up docs preview #1980
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants