From 9336dcba488298e6fa3ed32f0fbde6be2c3d17cf Mon Sep 17 00:00:00 2001 From: Patrick Donnelly Date: Wed, 29 Jul 2026 20:18:57 -0400 Subject: [PATCH] .github/workflows: switch to pull_request_target trigger Switch the trigger from `pull_request` to `pull_request_target` so that the workflow definition on `main` is evaluated for PRs targeting active release branches (main, umbrella, tentacle, squid). This allows the check to run cleanly across release branches without requiring workflow file backports to each branch. Additionally: - Update `src/script/verify-qa` to accept an optional target directory argument ($1). - Run the trusted `verify-qa` script from `main` against the checked-out PR directory (`./pull_request`). The concern of exfiltrating secrets is important but not relevant here: we're not using the secrets in the definition and we explicitly downgrade the github token to `read` permission. Signed-off-by: Patrick Donnelly --- .github/workflows/qa-symlink.yml | 10 ++++------ src/script/verify-qa | 6 ++++++ 2 files changed, 10 insertions(+), 6 deletions(-) diff --git a/.github/workflows/qa-symlink.yml b/.github/workflows/qa-symlink.yml index dda2265162d..cafc3c85eb9 100644 --- a/.github/workflows/qa-symlink.yml +++ b/.github/workflows/qa-symlink.yml @@ -1,8 +1,7 @@ --- name: "Check for missing .qa links" on: - pull_request: - # Run CI check only for branches which are active and a target for a PR + pull_request_target: branches: - main - umbrella @@ -11,7 +10,6 @@ on: types: - opened - synchronize - - edited - reopened permissions: contents: read @@ -36,6 +34,6 @@ jobs: ref: ${{ github.event.pull_request.head.sha }} path: pull_request - - name: verify .qa links - run: ../main/src/script/verify-qa - working-directory: pull_request/ + - name: Run verification script + run: | + ./main/src/script/verify-qa ./pull_request diff --git a/src/script/verify-qa b/src/script/verify-qa index 53e796e33d6..39ca5350897 100755 --- a/src/script/verify-qa +++ b/src/script/verify-qa @@ -1,5 +1,11 @@ #!/bin/bash +set -e + +if [[ -n "$1" ]]; then + cd "$1" +fi + printf 'Commit is:\n' >&2 git log -1 >&2