Reusable GitHub Actions workflow templates for projects that need a self-hosted macOS verify gate, optional agent review, React lint CI, and a handful of supporting alarms/matrices. This is not a product and not a runnable CI stack by itself.
Clone or copy the YAML under workflows/, then adapt paths, package scripts,
labels, and runner labels to your repository. Treat every path and npm
script name as a placeholder until you map it.
Coding agents: start with AGENTS.md. That file is the adoption playbook.
| Template | File | Typical trigger | Runs on | Role |
|---|---|---|---|---|
| Verify gate | workflows/check.yml |
PR (non-draft) + push to default branch + optional nightly | [self-hosted, macOS] |
Hard gate: install, build, lint, unit/integration, optional E2E |
| Hosted verify gate | workflows/check-hosted.yml |
PR (non-draft) + push to default branch | ubuntu-latest |
Hosted sibling of check.yml. Ephemeral checkout, format/lint/typecheck/tests, plus slop job |
| React Doctor | workflows/react-doctor.yml |
PR + push to default branch | Usually same self-hosted macOS (or hosted) | Advisory React/a11y/perf scan; sticky PR comment; optional escalation job |
| Cursor review | workflows/cursor-review.yml |
PR (opened / ready_for_review; synchronize often label-gated) |
Self-hosted macOS when CLI + keychain constraints apply | Agent review → optional autofix → verify → fail closed on unresolved findings |
| Cursor review (readonly) | workflows/cursor-review-readonly.yml |
PR (opened / ready_for_review; synchronize often label-gated) |
ubuntu-latest |
Agent review, no push. Fail closed on confirmed findings. Start here before the autofix template |
| Slop check | scripts/slop-check.sh |
Local CLI or check / slop job |
Local or hosted CI | Mechanical slop rules on the PR diff. Runs locally and in CI |
| Queue stall alarm | workflows/queue-stall-alarm.yml |
Cron and/or workflow_dispatch |
ubuntu-latest (hosted) |
Detects jobs stuck queued waiting for a self-hosted runner |
| ffmpeg floor matrix | workflows/ffmpeg-floor.yml.example |
Often workflow_dispatch (+ optional path-filtered PR) |
Hosted Linux | Proves behavior on both sides of an ffmpeg major-version floor |
| Factory Droid | workflows/droid.yml.example |
@droid in issue/PR comments (and related events) |
Hosted Linux | On-demand Factory Droid exec via pinned action |
Supporting docs:
| Doc | Purpose |
|---|---|
| docs/secrets.md | Secret/variable names and where they go |
| docs/self-hosted-macos-runner.md | Runner labels, cache layout, git-config traps |
| docs/adopt-checklist.md | Human checklist mirroring AGENTS.md |
| docs/layered-review-pipeline.md | The tiering model and lessons from running the pipeline in production |
These templates were scrubbed for public use:
- No real org/repo names, runner hostnames, local usernames, home paths, or SSH host aliases.
- No API keys, PATs, healthcheck UUIDs, or billing incident details.
- Placeholders only:
YOUR_ORG/YOUR_REPO,$HOME/.cache/<project>-cargo-target,RUNNER_NAME,secrets.CURSOR_API_KEY, etc.
One thing the scrub cannot do for you: on a public repo, Actions logs are
world-readable and only registered secrets are masked. The cache diagnostics in
check.yml print $HOME-derived paths and $RUNNER_NAME. See
docs/self-hosted-macos-runner.md.
Never commit secrets. Put credentials in GitHub Actions secrets (or OIDC).
Pin third-party actions to a commit SHA when the job holds write permissions
or API keys (droid.yml.example shows the pattern). Prefer
pull_request over pull_request_target for untrusted fork code.
- Skim AGENTS.md §2 (catalog) and §7–8 (must customize / do not copy).
- Copy the workflows you need into
YOUR_ORG/YOUR_REPO/.github/workflows/. - Rename
*.examplefiles only after you have the matching scripts/secrets. - Configure secrets/vars per docs/secrets.md.
- Register a self-hosted macOS runner with labels matching the YAML
(
self-hosted,macOS, plus any custom labels you add). - Point
check.ymlat your verify script (e.g.npm run check), not the placeholder name. - Open a non-draft PR and confirm: draft skip works,
ready_for_reviewre-triggers, and the queue alarm still runs on hosted Ubuntu.
Tell another developer's coding agent:
Read https://github.com/RayFernando1337/ray-fernando-actions-templates/blob/main/AGENTS.md and adopt the workflows that match our stack. Scrub any host-specific paths; use our verify script and secrets names from docs/secrets.md.
MIT — copy and modify freely.