47 lines
1.6 KiB
YAML
47 lines
1.6 KiB
YAML
name: Approve PR workflows
|
|
|
|
# A pull_request workflow cannot approve itself: GitHub can hold it before
|
|
# any job starts. This workflow only runs trusted default-branch code and
|
|
# releases the ordinary, unprivileged PR workflows after build approval.
|
|
on:
|
|
pull_request_target:
|
|
types: [opened, synchronize, reopened, labeled]
|
|
|
|
permissions:
|
|
contents: read
|
|
pull-requests: read
|
|
actions: write
|
|
|
|
concurrency:
|
|
group: approve-pr-${{ github.event.pull_request.number }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
approve:
|
|
# Match build-pr.yml's events, including other labels applied while this
|
|
# PR still carries build-approved: each labeled event creates a build.
|
|
if: contains(github.event.pull_request.labels.*.name, 'build-approved')
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
steps:
|
|
# Never check out the PR head or its merge ref with this write token.
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
ref: ${{ github.event.repository.default_branch }}
|
|
persist-credentials: false
|
|
- id: vouch
|
|
uses: mitchellh/vouch/action/check-user@f23dbb5e745334f97414ec70463ce7301071a661 # v1
|
|
with:
|
|
user: ${{ github.event.pull_request.user.login }}
|
|
allow-fail: true
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
- name: Approve this PR's pending build and test runs
|
|
uses: actions/github-script@v7
|
|
env:
|
|
VOUCH_STATUS: ${{ steps.vouch.outputs.status }}
|
|
with:
|
|
script: |
|
|
const approve = require('./.github/scripts/approve-pr-workflows.cjs');
|
|
await approve({ github, context, core, vouchStatus: process.env.VOUCH_STATUS });
|