The upstream and rebuild syncs push with GITHUB_TOKEN, so GitHub holds their build and test runs for approval. Their approve job only released those runs once a maintainer had applied build-approved, and never ran for the push that opened the PR, so every sync PR sat waiting. The sync now labels its own PR build-approved, and the approve job runs for created PRs as well as updated ones.
35 lines
1.8 KiB
JavaScript
35 lines
1.8 KiB
JavaScript
const approvePrWorkflows = require('./approve-pr-workflows.cjs');
|
|
|
|
const BOT = 'github-actions[bot]';
|
|
|
|
// A sync workflow pushes its branch with GITHUB_TOKEN. GitHub holds the
|
|
// resulting pull_request runs for approval and, unlike a person's push,
|
|
// creates no pull_request_target run, so approve-pr.yml never sees it. The
|
|
// sync workflow therefore releases the runs for the commit it just pushed,
|
|
// under the same rule approve-pr.yml applies: only while build-approved is
|
|
// on the PR. The sync applies that label itself, so its pushes build without
|
|
// a maintainer. It acts only on its own bot-authored, same-repository PR for
|
|
// the branch and commit it pushed.
|
|
module.exports = async function approveSyncPush({ github, context, core,
|
|
number, branch, headSha, since, approve = approvePrWorkflows, ...options }) {
|
|
if (!Number.isInteger(number) || !branch || !headSha || !since) {
|
|
throw new Error('Missing sync PR number, branch, head SHA or push time.');
|
|
}
|
|
const { data: pr } = await github.rest.pulls.get({ ...context.repo, pull_number: number });
|
|
const repository = `${context.repo.owner}/${context.repo.repo}`;
|
|
if (pr.user?.login !== BOT || pr.head.repo?.full_name !== repository ||
|
|
pr.base.repo?.full_name !== repository || pr.head.ref !== branch) {
|
|
throw new Error(`PR #${number} is not ${BOT}'s ${branch} PR in ${repository}; refusing to approve.`);
|
|
}
|
|
if (pr.state !== 'open' || pr.head.sha !== headSha) {
|
|
core.info(`PR #${number} is closed or has moved past ${headSha}; nothing to approve.`);
|
|
return;
|
|
}
|
|
if (!pr.labels.some(label => label.name === 'build-approved')) {
|
|
core.info(`PR #${number} has no build-approved label; its runs stay held.`);
|
|
return;
|
|
}
|
|
await approve({ github, context, core, vouchStatus: 'bot', pullRequest: pr,
|
|
action: 'synchronize', since, ...options });
|
|
};
|