name: Approve PR workflows # A pull_request workflow cannot approve itself: GitHub can hold it before # any job starts. This workflow only runs trusted default-branch code and # releases the ordinary, unprivileged PR workflows after build approval. on: pull_request_target: types: [opened, synchronize, reopened, labeled] permissions: contents: read pull-requests: read actions: write concurrency: group: approve-pr-${{ github.event.pull_request.number }} cancel-in-progress: true jobs: approve: # Match build-pr.yml's events, including other labels applied while this # PR still carries build-approved: each labeled event creates a build. if: contains(github.event.pull_request.labels.*.name, 'build-approved') runs-on: ubuntu-latest timeout-minutes: 5 steps: # Never check out the PR head or its merge ref with this write token. - uses: actions/checkout@v4 with: ref: ${{ github.event.repository.default_branch }} persist-credentials: false - id: vouch uses: mitchellh/vouch/action/check-user@f23dbb5e745334f97414ec70463ce7301071a661 # v1 with: user: ${{ github.event.pull_request.user.login }} allow-fail: true env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Approve this PR's pending build and test runs uses: actions/github-script@v7 env: VOUCH_STATUS: ${{ steps.vouch.outputs.status }} with: script: | const approve = require('./.github/scripts/approve-pr-workflows.cjs'); await approve({ github, context, core, vouchStatus: process.env.VOUCH_STATUS });