Repository navigation
ci: pin no-mistakes required-check to v1.80.1 #142
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -3,18 +3,31 @@ run-name: "PR #${{ github.event.pull_request.number }} body compliance - ${{ git | |
|
|
||
| on: | ||
| pull_request: | ||
| # The gate validates the head SHA recorded in pull_request.body. The | ||
| # pipeline pushes first, then rewrites that attestation, so the edited event | ||
| # checks the final body against the new head. A synchronize run would judge | ||
| # the old body in between and leave a same-named failure beside the later | ||
| # success. This check is not required by a ruleset or branch protection, so | ||
| # omitting synchronize cannot leave an expected check pending. | ||
| types: [opened, edited, reopened] | ||
| # T2: opened, edited, synchronize, reopened. #773 dropped synchronize | ||
| # because a pipeline push pinned a FAILURE check run to the new head | ||
| # before the PR step rewrote the body, and GitHub kept that failure | ||
| # next to the later edited SUCCESS. Since the pre-push attestation | ||
| # change (#994), synchronize is the event that judges a pipeline-pushed | ||
| # head, so it is restored. | ||
| types: [opened, edited, synchronize, reopened] | ||
| branches: | ||
| - main | ||
| # Never create a run for a release-please PR. The job-level author exemption | ||
| # below cannot do this: it is evaluated inside a run, and a GITHUB_TOKEN PR's | ||
| # run is created in action_required and never starts. | ||
| paths-ignore: | ||
| - .release-please-manifest.json | ||
| - CHANGELOG.md | ||
| - package.json | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Adding How this was verified: The pull-request path filter applies before the job-level author conditions, while
Owner
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Keeping That matches the repo's other release ignore lists ( There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. That context resolves the concern. Keeping Tip: You can customize Greptile's behavior for this repo with |
||
|
|
||
| permissions: | ||
| contents: read | ||
| # Lets require-no-mistakes read this PR's LIVE body/head SHA instead of the | ||
| # workflow's own cached event payload, which a job rerun replays verbatim | ||
| # from its original trigger. Without this the gate fails closed rather than | ||
| # certifying from the possibly-stale event payload. See | ||
| # .github/actions/require-no-mistakes/README.md. | ||
| pull-requests: read | ||
|
|
||
| # GitHub concurrency groups retain at most one pending run, replacing older | ||
| # pending runs even when cancel-in-progress is false. Give body-bearing events | ||
|
|
@@ -31,6 +44,7 @@ jobs: | |
| # Known automation accounts are exempt so automation keeps working: | ||
| # - github-actions[bot] opens PRs via GITHUB_TOKEN (release-please) | ||
| # - dependabot[bot] opens dependency update PRs | ||
| # - release-please[bot] opens the release PR when it uses its own app token | ||
| # Other authors (human or bot) must raise PRs through `git push no-mistakes`. | ||
| # | ||
| # These stay job-level rather than moving to the action's `exempt-authors` | ||
|
|
@@ -40,7 +54,8 @@ jobs: | |
| # repository's gate already produces for those authors. | ||
| if: >- | ||
| github.event.pull_request.user.login != 'github-actions[bot]' && | ||
| github.event.pull_request.user.login != 'dependabot[bot]' | ||
| github.event.pull_request.user.login != 'dependabot[bot]' && | ||
| github.event.pull_request.user.login != 'release-please[bot]' | ||
| steps: | ||
| # The enforcement itself lives in the shared composite action in the | ||
| # no-mistakes repository, so this repository no longer carries its own | ||
|
|
@@ -50,4 +65,4 @@ jobs: | |
| # pull request this gate is judging. Bumping the pin is a separate, | ||
| # deliberate pull request. | ||
| - name: Verify no-mistakes signature and pipeline attestation in PR body | ||
| uses: kunchenguid/no-mistakes/.github/actions/require-no-mistakes@32d396ac0f29135daf7fcb9964aba9d5f4e796d6 # post-v1.57.1, untagged (action added in #819) | ||
| uses: kunchenguid/no-mistakes/.github/actions/require-no-mistakes@f6441c96c352a18b9cadcaef6b6c7017e9ac3970 # v1.80.1 | ||
Uh oh!
There was an error while loading. Please reload this page.