Files
oh-my-pi/.github/workflows/vouch-manage.yml
T
can1357 aca5d5f48a feat(python): implemented pull request vouching and gated review system
- Introduced a vouching mechanism to manage PR authorization via a tracked user list and discussion-based management workflows.
- Added automated PR gatekeeping workflows to close contributions from unvouched users and require specific labels for review.
- Refactored PR event handling to support label-based review deferral and enforce authorization checks for labelers.
- Added comprehensive test coverage for vouch-gate logic, including label activation and unauthorized access scenarios.
2026-06-19 03:24:04 +02:00

54 lines
1.9 KiB
YAML

name: Vouch (manage)
# Let maintainers vouch/denounce/unvouch by commenting on a Discussion:
# !vouch vouch the discussion author
# !vouch @user [reason] vouch a specific user
# !denounce [@user] [reason]
# !unvouch [@user]
# Only collaborators with admin/maintain/write are honored (triage EXCLUDED;
# upstream's default `roles` includes triage, which we override below).
# The action commits the VOUCHED.td change back to the default branch.
on:
discussion_comment:
types: [created]
# Serialize writes to VOUCHED.td so concurrent vouches don't clobber.
concurrency:
group: vouch-manage
cancel-in-progress: false
# The job carries its own identity via the App token below, so the
# workflow itself needs no permissions.
permissions: {}
jobs:
manage:
runs-on: ubuntu-latest
steps:
# A GitHub App identity is required only if the default branch is
# protected (the stock GITHUB_TOKEN cannot bypass branch protection).
# No branch protection? Delete this step, drop the checkout `token:`,
# set `permissions: { contents: write, discussions: write }`, and use
# `GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}` below.
- uses: actions/create-github-app-token@v2
id: app-token
with:
app-id: ${{ secrets.VOUCH_ID }}
private-key: ${{ secrets.VOUCH_PRIVATE_KEY }}
- uses: actions/checkout@v4
with:
token: ${{ steps.app-token.outputs.token }}
- uses: mitchellh/vouch/action/manage-by-discussion@v1
with:
discussion-number: ${{ github.event.discussion.number }}
comment-node-id: ${{ github.event.comment.node_id }}
vouch-keyword: "!vouch"
denounce-keyword: "!denounce"
unvouch-keyword: "!unvouch"
roles: admin,maintain,write
env:
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}