Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 24 additions & 9 deletions .github/workflows/no-mistakes-required.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,18 +3,31 @@ run-name: "PR #${{ github.event.pull_request.number }} body compliance - ${{ git

on:
pull_request:
# The gate validates the head SHA recorded in pull_request.body. The
# pipeline pushes first, then rewrites that attestation, so the edited event
# checks the final body against the new head. A synchronize run would judge
# the old body in between and leave a same-named failure beside the later
# success. This check is not required by a ruleset or branch protection, so
# omitting synchronize cannot leave an expected check pending.
types: [opened, edited, reopened]
# T2: opened, edited, synchronize, reopened. #773 dropped synchronize
# because a pipeline push pinned a FAILURE check run to the new head
# before the PR step rewrote the body, and GitHub kept that failure
# next to the later edited SUCCESS. Since the pre-push attestation
# change (#994), synchronize is the event that judges a pipeline-pushed
# head, so it is restored.
types: [opened, edited, synchronize, reopened]
branches:
- main
# Never create a run for a release-please PR. The job-level author exemption
# below cannot do this: it is evaluated inside a run, and a GITHUB_TOKEN PR's
# run is created in action_required and never starts.
paths-ignore:
- .release-please-manifest.json
- CHANGELOG.md
Comment thread
greptile-apps[bot] marked this conversation as resolved.
- package.json

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 security Package manifest bypasses gate

Adding package.json to paths-ignore suppresses this workflow for every package.json-only PR, not just release-please PRs. A non-exempt author can therefore change scripts, engine constraints, or other manifest settings without the require-no-mistakes action validating the PR body and head-SHA attestation, contrary to the repository policy that human PRs must pass this gate. Restrict the exemption to release automation rather than using a path filter that also applies to human-authored PRs.

How this was verified: The pull-request path filter applies before the job-level author conditions, while package.json contains ordinary developer-editable configuration and the repository identifies this workflow as the enforcement point for head-SHA-bound attestations.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Keeping package.json in this paths-ignore.

That matches the repo's other release ignore lists (ci.yml and guard-generated-files.yml). A human pull request that only touches package.json skipping this gate is accepted: release-please node releases always bump the manifest, so omitting it would still create the GITHUB_TOKEN action_required run this filter is meant to prevent.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That context resolves the concern. Keeping package.json is an intentional repository-wide policy choice, consistent with ci.yml and guard-generated-files.yml: release-please Node releases modify it, and omitting it would recreate the action_required run this filter is intended to prevent. I’ll consider this acceptable and won’t block the PR on that path filter, with the acknowledged trade-off that human PRs touching only package.json also skip this gate.

Tip: You can customize Greptile's behavior for this repo with .greptile/rules.md and .greptile/config.json.


permissions:
contents: read
# Lets require-no-mistakes read this PR's LIVE body/head SHA instead of the
# workflow's own cached event payload, which a job rerun replays verbatim
# from its original trigger. Without this the gate fails closed rather than
# certifying from the possibly-stale event payload. See
# .github/actions/require-no-mistakes/README.md.
pull-requests: read

# GitHub concurrency groups retain at most one pending run, replacing older
# pending runs even when cancel-in-progress is false. Give body-bearing events
Expand All @@ -31,6 +44,7 @@ jobs:
# Known automation accounts are exempt so automation keeps working:
# - github-actions[bot] opens PRs via GITHUB_TOKEN (release-please)
# - dependabot[bot] opens dependency update PRs
# - release-please[bot] opens the release PR when it uses its own app token
# Other authors (human or bot) must raise PRs through `git push no-mistakes`.
#
# These stay job-level rather than moving to the action's `exempt-authors`
Expand All @@ -40,7 +54,8 @@ jobs:
# repository's gate already produces for those authors.
if: >-
github.event.pull_request.user.login != 'github-actions[bot]' &&
github.event.pull_request.user.login != 'dependabot[bot]'
github.event.pull_request.user.login != 'dependabot[bot]' &&
github.event.pull_request.user.login != 'release-please[bot]'
steps:
# The enforcement itself lives in the shared composite action in the
# no-mistakes repository, so this repository no longer carries its own
Expand All @@ -50,4 +65,4 @@ jobs:
# pull request this gate is judging. Bumping the pin is a separate,
# deliberate pull request.
- name: Verify no-mistakes signature and pipeline attestation in PR body
uses: kunchenguid/no-mistakes/.github/actions/require-no-mistakes@32d396ac0f29135daf7fcb9964aba9d5f4e796d6 # post-v1.57.1, untagged (action added in #819)
uses: kunchenguid/no-mistakes/.github/actions/require-no-mistakes@f6441c96c352a18b9cadcaef6b6c7017e9ac3970 # v1.80.1
Loading