Context
.github/workflows contains 23 separate workflow files (ci, lint, test, typecheck, e2e, contracts, database, docs, accessibility, bundle-size, privacy-tests, rls-audit, security-audit, migration-audit, migration-drift-check, debt-policy, validate-docs, generate-openapi, flaky-test-triage, staging-deploy, blue-green-deploy, post-deploy-health-check, rollback, branch-protection). Setup steps are duplicated across all of them, they trigger on overlapping paths, and no one can tell from the checks list which failures actually block a merge.
Scope
- Extract shared setup (Node, npm cache, Rust toolchain, Supabase) into reusable composite actions.
- Collapse the quality workflows into one
pr.yml with jobs, keeping deploy and scheduled workflows separate.
- Define which checks are required for merge and align branch protection with that list.
- Add path filters so unrelated changes do not trigger the full matrix.
Acceptance criteria
Files / areas
.github/workflows, .github/actions
Part of the SYNCRO v2 rewrite. Epic: H — Infrastructure, CI & DevEx.
Context
.github/workflowscontains 23 separate workflow files (ci, lint, test, typecheck, e2e, contracts, database, docs, accessibility, bundle-size, privacy-tests, rls-audit, security-audit, migration-audit, migration-drift-check, debt-policy, validate-docs, generate-openapi, flaky-test-triage, staging-deploy, blue-green-deploy, post-deploy-health-check, rollback, branch-protection). Setup steps are duplicated across all of them, they trigger on overlapping paths, and no one can tell from the checks list which failures actually block a merge.Scope
pr.ymlwith jobs, keeping deploy and scheduled workflows separate.Acceptance criteria
Files / areas
.github/workflows,.github/actionsPart of the SYNCRO v2 rewrite. Epic: H — Infrastructure, CI & DevEx.