mirror of
https://github.com/ceph/ceph
synced 2026-08-02 07:03:18 +00:00
.github/workflows: switch to pull_request_target trigger
Switch the trigger from `pull_request` to `pull_request_target` so that the workflow definition on `main` is evaluated for PRs targeting active release branches (main, umbrella, tentacle, squid). This allows the check to run cleanly across release branches without requiring workflow file backports to each branch. Additionally: - Update `src/script/verify-qa` to accept an optional target directory argument ($1). - Run the trusted `verify-qa` script from `main` against the checked-out PR directory (`./pull_request`). The concern of exfiltrating secrets is important but not relevant here: we're not using the secrets in the definition and we explicitly downgrade the github token to `read` permission. Signed-off-by: Patrick Donnelly <pdonnell@ibm.com>
This commit is contained in:
parent
e82ccd0873
commit
9336dcba48
10
.github/workflows/qa-symlink.yml
vendored
10
.github/workflows/qa-symlink.yml
vendored
@ -1,8 +1,7 @@
|
||||
---
|
||||
name: "Check for missing .qa links"
|
||||
on:
|
||||
pull_request:
|
||||
# Run CI check only for branches which are active and a target for a PR
|
||||
pull_request_target:
|
||||
branches:
|
||||
- main
|
||||
- umbrella
|
||||
@ -11,7 +10,6 @@ on:
|
||||
types:
|
||||
- opened
|
||||
- synchronize
|
||||
- edited
|
||||
- reopened
|
||||
permissions:
|
||||
contents: read
|
||||
@ -36,6 +34,6 @@ jobs:
|
||||
ref: ${{ github.event.pull_request.head.sha }}
|
||||
path: pull_request
|
||||
|
||||
- name: verify .qa links
|
||||
run: ../main/src/script/verify-qa
|
||||
working-directory: pull_request/
|
||||
- name: Run verification script
|
||||
run: |
|
||||
./main/src/script/verify-qa ./pull_request
|
||||
|
||||
@ -1,5 +1,11 @@
|
||||
#!/bin/bash
|
||||
|
||||
set -e
|
||||
|
||||
if [[ -n "$1" ]]; then
|
||||
cd "$1"
|
||||
fi
|
||||
|
||||
printf 'Commit is:\n' >&2
|
||||
git log -1 >&2
|
||||
|
||||
|
||||
Loading…
Reference in New Issue
Block a user