Repository navigation
Add npm-trusted-publishing skill 🤖🤖🤖 #207
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Submission Gate | |
| # Read-only preview for every PR. Waits for the applicable checks listed in | |
| # .github/submission-gate.yml, classifies the PR into a merge-risk tier | |
| # (.github/risk-tiers.yml), and previews the approvals that tier requires. | |
| # This workflow never publishes the required `submission-gate` check: a PR can edit | |
| # pull_request workflows, so the trusted submission-gate-writer.yml recomputes the | |
| # result with default-branch code and publishes that check, the labels, and the | |
| # status comment. See docs/maintainers/submission-gate.md. | |
| on: | |
| pull_request: | |
| # `edited` covers retargeting to another base branch, which changes the applicable checks. | |
| types: [opened, synchronize, reopened, ready_for_review, edited] | |
| pull_request_review: | |
| types: [submitted, edited, dismissed] | |
| permissions: | |
| actions: read | |
| checks: read | |
| contents: read | |
| pull-requests: read | |
| concurrency: | |
| group: submission-gate-${{ github.event.pull_request.number }} | |
| cancel-in-progress: true | |
| jobs: | |
| # Must not be named submission-gate: the writer treats any other check with that name as tampering. | |
| evaluate: | |
| name: evaluate | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 50 | |
| steps: | |
| # Gate logic and policy come from the base commit so a PR cannot change how it is judged. | |
| - name: Checkout trusted base | |
| uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 | |
| with: | |
| ref: ${{ github.event.pull_request.base.sha }} | |
| persist-credentials: false | |
| sparse-checkout: | | |
| .github | |
| eng | |
| package.json | |
| package-lock.json | |
| - name: Check for gate logic on base | |
| id: base | |
| run: | | |
| if [ -f eng/submission-gate.mjs ] && [ -f .github/submission-gate.yml ] && [ -f .github/risk-tiers.yml ]; then | |
| echo "has-gate=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "has-gate=false" >> "$GITHUB_OUTPUT" | |
| fi | |
| # Bootstrap only: the PR that introduces the gate has no base copy of it. This job | |
| # has a read-only token, and such PRs are merge-risk:high by path. | |
| - name: Checkout PR (bootstrap) | |
| if: steps.base.outputs.has-gate != 'true' | |
| uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 | |
| with: | |
| persist-credentials: false | |
| clean: true | |
| - name: Setup Node.js | |
| uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 | |
| with: | |
| node-version: "22" | |
| cache: "npm" | |
| - name: Install dependencies | |
| run: npm ci --ignore-scripts | |
| - name: Evaluate submission | |
| uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7.1.0 | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| BOOTSTRAP: ${{ steps.base.outputs.has-gate != 'true' }} | |
| with: | |
| script: | | |
| const path = require('path'); | |
| const { pathToFileURL } = require('url'); | |
| if (process.env.BOOTSTRAP === 'true') { | |
| core.warning('The base branch has no submission gate yet; evaluating with the gate from this PR.'); | |
| } | |
| const root = process.env.GITHUB_WORKSPACE; | |
| const gate = await import(pathToFileURL(path.join(root, 'eng', 'submission-gate.mjs')).href); | |
| const config = gate.loadGateConfig(root); | |
| const pullNumber = context.payload.pull_request.number; | |
| const evaluation = await gate.evaluateSubmission(github, { | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| pullNumber, | |
| config, | |
| expectedHeadSha: context.payload.pull_request.head.sha, | |
| wait: true, | |
| token: process.env.GH_TOKEN, | |
| log: (message) => core.info(message), | |
| }); | |
| if (evaluation.stale) { | |
| core.info('The PR head changed during evaluation; the run for the new head will report instead.'); | |
| return; | |
| } | |
| const runUrl = `${context.serverUrl}/${context.repo.owner}/${context.repo.repo}/actions/runs/${context.runId}`; | |
| await core.summary.addRaw(gate.renderStatusComment(evaluation, { gateRunUrl: runUrl })).write(); | |
| // Preview only; the writer publishes the authoritative submission-gate check. | |
| core.info(`PR #${pullNumber}: state=${evaluation.state}, risk=${evaluation.risk.tier}`); | |
| for (const line of gate.gateFailureSummary(evaluation)) core.notice(line); |