Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .github/workflows/merge-conflict-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,8 +12,14 @@ on:
- synchronize
- reopened

# Permissions should be configured at the job level.
permissions: {}

jobs:
check-prs:
permissions:
pull-requests: write # To add and remove labels and comments on a PR.

if: github.repository_owner == 'Yoast'

name: Check PRs for merge conflicts
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/qa.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,8 +7,14 @@ on:
# Allow manually triggering the workflow.
workflow_dispatch:

# Permissions should be configured at the job level.
permissions: {}

jobs:
actionlint:
permissions:
contents: read # To clone the repo.

name: 'Lint GH Action workflows'
uses: ./.github/workflows/reusable-actionlint.yml
with:
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/reusable-actionlint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,8 +19,14 @@ on:
required: false
default: ''

# Permissions should be configured at the job level.
permissions: {}

jobs:
actionlint:
permissions:
contents: read # To clone the repo.

name: 'Actionlint'
runs-on: ubuntu-latest

Expand Down
11 changes: 5 additions & 6 deletions .github/workflows/reusable-merge-conflict-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -37,23 +37,22 @@ on:
required: false
default: true

# Default to no permissions at all; the job below opts in to only what it needs.
# Permissions should be configured at the job level.
permissions: {}

jobs:
check-prs:
name: Merge conflict check
permissions:
issues: write # Needed to create the dirty label.
pull-requests: write # To add and remove labels and comments on a PR.

name: Merge conflict check
runs-on: ubuntu-latest

# Safety net: the merge conflict check retries for at most ~10 minutes
# (retryAfter 120s * retryMax 5), so anything beyond this is a runaway job.
timeout-minutes: 20

permissions:
issues: write # Needed to create the dirty label and to add/remove labels on PRs.
pull-requests: write # Needed to comment and to mark those comments as resolved.

steps:
- name: "Create label if it doesn't exist"
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
Expand Down
13 changes: 11 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,13 +18,17 @@ Aside from the community health files, this repository also offers a number of r
### Available re-usable workflows

The following re-usable workflows are available:
* [`reusable-actionlint.yml`][reusable-actionlint] which runs a [static analysis check][actionlint] on GitHub Actions workflow files only.
* [`reusable-actionlint.yml`][reusable-actionlint] which runs a [static analysis check][actionlint] on GitHub Actions workflow files only.
**Inputs**:
- `shellcheck`: Optional. Whether to enable shellcheck. Defaults to 'true'.
- `pyflakes`: Optional. Whether to enable pyflakes. Defaults to 'true'.
- `args`: Optional. Command line arguments to pass to the actionlint command. Defaults to no arguments.

* [`reusable-merge-conflict-check.yml`][reusable-mergeconflict] to check whether open PRs are in a merge conflict state.
**Permissions**:
The `reusable-actionlint` workflow needs the following GH Action permissions - these should be set at "job" level:
- `contents: read # To clone the repo.`

* [`reusable-merge-conflict-check.yml`][reusable-mergeconflict] to check whether open PRs are in a merge conflict state.
**Inputs**:
- `dirtyLabel`: Optional. Name of the label which indicates that the branch is dirty. Defaults to 'merge conflict'.
- `removeOnDirtyLabel`: Optional. Name of the label which should be removed. Defaults to none.
Expand All @@ -38,6 +42,11 @@ The following re-usable workflows are available:
Note that changing `commentOnDirty` will leave already posted comments unmatched, so those will stay visible
instead of being collapsed.

**Permissions**:
The `reusable-merge-conflict-check` workflow needs the following GH Action permissions - these should be set at "job" level:
- `issues: write # Needed to create the dirty label.` (only needed if the `dirtyLabel` may not exist on a repo)
- `pull-requests: write # To add and remove labels and comments on a PR.`


## A .github repository with versioning ?

Expand Down
Loading