**no more vouching! let's see how it goes for a week :)**

This commit is contained in:
can1357
2026-07-23 02:35:36 +02:00
parent 1f7d2ff9ea
commit bb15939414
13 changed files with 79 additions and 673 deletions
-262
View File
@@ -1,262 +0,0 @@
# The list of vouched (or actively denounced) users for this repository.
#
# Only vouched users can open PRs here; unvouched/denounced PRs are
# auto-closed by .github/workflows/vouch-pr.yml (mitchellh/vouch check-pr).
# Issues are intentionally NOT gated here — robomp triages those.
#
# Write-access collaborators and bots are auto-allowed and need no entry.
# A denounced user ("-handle") is always blocked, even if also listed.
#
# Syntax:
# - One handle per line (without @), sorted alphabetically.
# - Optional platform prefix: `platform:username` (default platform: github).
# - Denounce by prefixing with minus: `-username` / `-platform:username`.
# - Optional free-text reason after a space following the handle.
#
# Maintainers manage this list by commenting `!vouch` / `!denounce [user]`
# on a discussion (see .github/workflows/vouch-manage.yml).
#
# Seed (2026-06-19): authors with >=2 merged PRs in the prior 6 months.
# Audit found 0 denounce-worthy actors; all reverts were maintainer
# technical rollbacks, not abuse. See the PR/commit history for provenance.
0ttik
21307369
35844493
381181295
a-glapinski
adrastopoulos
ak4153
alias8818
alloevil
alvorithm
anasinno
andrew-pynch
antonlvovych
any-victor
apoc
arg3t
art1kz
asafmah
asterisksf
atyrode
audreyt
azais-corentin
aznikline
bannert1337
barisdemirdelen
basedcorp99
baylee4
belchetz
bjin
blockedpath
brainage04
cagedbird043
cexll
chan1103
chrys4lisfag
chuaaron
chuzui
ckumar1
cloudsmithbrandon
codelonesomest
coderredlab
codertcy
comicchang
corrm
courtgpt
cyjaysong
czxtm
daandden
daaximus
danvincent
danzaio
darkphilosophy
defaceroot
deprecatedluke
derekszen
devnewbie1826
dexhunter
disco-trooper
djdembeck
dkeken
dmarsh-gusto
dragonbaba
dylanbohlender
echopi
eggpeat
elikoga
enieuwy
eugenelo
eyycheev
fettpl
flare576
foreveryoungpp
freespace8
fryuni
gareth-rouse
gratefuldave
h4vc
habibpro1999
handlecusion
haosenwang1018
harshav167
hellisotherpeople
heyitsgilbert
hezhiyang2000
hheei
hobostay
hoishing
honsunrise
hpost
iacore
ig0rsky
igasmi
incloon
infernix
inprealpha
insodimension
isaac-sun
itertea
itzrnvr
jaaneek
jaeyeopme
jagravnaik
jasonw22
jchristman
jdavv
jeffscottward
jfblaine
jiwangyihao
jorgoose
joswha
justmao945
jwmacd
kamafozilov
kamijotoma
kenmege
kevcube
khanetor
korenkrita
korri123
kukkerem
lance0
larkinwc
larrygf
ldx
lederniermagicien
lee-si-yoon
lemeb
linqijin
liwuhou
llvm-x86
loftiskg
loneexile
luceat-lux-vestra
lunarecl
luojiyin1987
lyc-aon
m-005
m3ridian-zero
m8than
maatheusgois-dd
makomakogo
masonc15
mastertyko
mathews-tom
mattwilkinsonn
maximhar
maxvisionai
mayask
memvu
metaphorics
mgpai22
mikeei
mmkzer0
mokto
moutazhaq
mouyase
mq1n
mrshu
mumutw
muness
nasko25
nibblebot
niklasschaeffer
nnk97
nszceta
ogrodev
oldschoola
ondrejsojka
panosathdbx
paolomazzitti
paralin
parsifa1
peterrauscher
pgupta-git
phanthh
pidevxplay
piedpiper911
pppobear
qfrtt
ravshansbox
rburketaylor
rcbran
renstillmann
reqx
riverpilot
romanalexander
rysiuwroc
rznmkx
salmonumbrella
samy-mohsen-111
scarthread
segmentationf4u1t
selimsandal
serejaris
serverinspector
shauryaswarup
shoucandanghehe
shyndman
silentknight87
sit
slact
smileynet
sorphwer
sundbp
superhedge22
svankina
szavadsky
tbui17
tc97222
tcf909
tdiant
techdufus
tjboudreaux
tsagi2045
turbomolli
tyrliang
unravl
usr-bin-roygbiv
ve3xone
vincent-huang-2000
vmcall
voidchecksum
voiys
wahidinaji
watzon
will-bogusz will-bogusz
wodenjay
wolfiesch
wonjun3991
wtergan
wuchengzu
xaviergmail
xiue233
xoltus
yashnark
yingliang-zhang
zakhar-kogan
zamorakpds
zekdevs
zommiommy
+4 -6
View File
@@ -3,14 +3,12 @@ name: CI
on:
push:
branches: [main]
# Vouch bookkeeping commits (mitchellh/vouch writes VOUCHED.td back to
# main on !vouch/!denounce/!unvouch) only edit the vouch list and need no
# build. Skip CI when a main push changes nothing but the vouch file; a
# push that also touches anything else still runs the full matrix.
paths-ignore:
- .github/VOUCHED.td
paths:
- "packages/**"
pull_request:
branches: [main]
paths:
- "packages/**"
workflow_dispatch:
inputs:
skip_npm:
-44
View File
@@ -1,44 +0,0 @@
name: Vouch (manage)
# Let maintainers vouch/denounce/unvouch by commenting on a Discussion:
# !vouch vouch the discussion author
# !vouch @user [reason] vouch a specific user
# !denounce [@user] [reason]
# !unvouch [@user]
# Only collaborators with admin/maintain/write are honored (triage EXCLUDED;
# upstream's default `roles` includes triage, which we override below).
#
# Commits the VOUCHED.td change back to the default branch using the stock
# GITHUB_TOKEN (no GitHub App needed). NOTE: this works only while the default
# branch is UNPROTECTED — GITHUB_TOKEN cannot bypass branch protection. If you
# protect the branch later, switch back to a GitHub App token on a bypass list.
on:
discussion_comment:
types: [created]
# Serialize writes to VOUCHED.td so concurrent vouches don't clobber.
concurrency:
group: vouch-manage
cancel-in-progress: false
permissions:
contents: write # commit VOUCHED.td
discussions: write # read the comment / acknowledge
jobs:
manage:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: mitchellh/vouch/action/manage-by-discussion@v1
with:
discussion-number: ${{ github.event.discussion.number }}
comment-node-id: ${{ github.event.comment.node_id }}
vouch-keyword: "!vouch"
denounce-keyword: "!denounce"
unvouch-keyword: "!unvouch"
roles: admin,maintain,write
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
-51
View File
@@ -1,51 +0,0 @@
name: Vouch (PR gate)
# Auto-close PRs from unvouched or denounced users. Issues are left alone
# (robomp triages those). Runs under `pull_request_target` so the token can
# act on fork PRs; this job does NO checkout and runs NO PR code — it only
# reads .github/VOUCHED.td from the base repo and calls the GitHub API.
on:
pull_request_target:
types: [opened, reopened, ready_for_review]
permissions:
contents: read # read VOUCHED.td from the base branch
pull-requests: write # close + comment
issues: write # add the `vouched` label (labels use the Issues API)
concurrency:
group: vouch-pr-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
check:
runs-on: ubuntu-latest
steps:
- id: vouch
uses: mitchellh/vouch/action/check-pr@v1
with:
pr-number: ${{ github.event.pull_request.number }}
auto-close: true
require-vouch: true # block unvouched, not only denounced
# vouched-file: .github/VOUCHED.td (default)
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Survivors of the gate (vouched, or auto-allowed collaborators/bots) get
# a FRESH `vouched` label on every (re)open / ready-for-review. robomp
# reviews ONLY on that label event (ROBOMP_PR_REVIEW_TRIGGER=vouched_label),
# so review is always triggered by a just-validated PR, never a stale label.
- name: Label vouched PRs for robomp review
if: ${{ steps.vouch.outputs.status == 'vouched' || steps.vouch.outputs.status == 'allowed' }}
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
REPO: ${{ github.repository }}
PR: ${{ github.event.pull_request.number }}
run: |
gh label create vouched --repo "$REPO" --color 2da44e --description "Passed the vouch gate" --force
# remove+add so a fresh `labeled` event fires even when the label
# persisted across close/reopen (re-adding an existing label emits no
# event). The check above just re-validated, so trust is never stale.
gh pr edit "$PR" --repo "$REPO" --remove-label vouched || true
gh pr edit "$PR" --repo "$REPO" --add-label vouched