.github/workflows: switch to pull_request_target trigger

Switch the trigger from `pull_request` to `pull_request_target` so that
the workflow definition on `main` is evaluated for PRs targeting active
release branches (main, umbrella, tentacle, squid). This allows the check
to run cleanly across release branches without requiring workflow file
backports to each branch.

Additionally:
- Update `src/script/verify-qa` to accept an optional target directory argument ($1).
- Run the trusted `verify-qa` script from `main` against the checked-out PR directory (`./pull_request`).

The concern of exfiltrating secrets is important but not relevant here:
we're not using the secrets in the definition and we explicitly
downgrade the github token to `read` permission.

Signed-off-by: Patrick Donnelly <pdonnell@ibm.com>
This commit is contained in:
Patrick Donnelly 2026-07-29 20:18:57 -04:00
parent e82ccd0873
commit 9336dcba48
No known key found for this signature in database
GPG Key ID: 053758C0A8A3CE2F
2 changed files with 10 additions and 6 deletions

View File

@ -1,8 +1,7 @@
---
name: "Check for missing .qa links"
on:
pull_request:
# Run CI check only for branches which are active and a target for a PR
pull_request_target:
branches:
- main
- umbrella
@ -11,7 +10,6 @@ on:
types:
- opened
- synchronize
- edited
- reopened
permissions:
contents: read
@ -36,6 +34,6 @@ jobs:
ref: ${{ github.event.pull_request.head.sha }}
path: pull_request
- name: verify .qa links
run: ../main/src/script/verify-qa
working-directory: pull_request/
- name: Run verification script
run: |
./main/src/script/verify-qa ./pull_request

View File

@ -1,5 +1,11 @@
#!/bin/bash
set -e
if [[ -n "$1" ]]; then
cd "$1"
fi
printf 'Commit is:\n' >&2
git log -1 >&2