Commit Graph
4 Commits
Author SHA1 Message Date
Jon Ross-Perkins 21311334cb Switch to pull_request_target (#2014)
https://securitylab.github.com/research/github-actions-preventing-pwn-requests/#:~:text=The%20main%20differences%20between%20the,but%20not%20from%20external%20forks.

I'm hoping I actually have the cause of my issues right this time.
2022-08-12 11:57:25 -07:00
Jon Ross-Perkins efde2dcdd9 Switch token approach (#2013)
According to this run, the attempt to get write permissions failed:
https://github.com/carbon-language/carbon-lang/runs/7811743119?check_suite_focus=true

So I'm switching to an org secret, which I believe I can definitely make work.
2022-08-12 11:42:51 -07:00
Jon Ross-Perkins 767e712b47 Try adjusting permissions to label (#2012)
Context: https://github.com/carbon-language/carbon-lang/runs/7811528469?check_suite_focus=true

Permissions seem to be different from when I was testing, seeing if this is enough.
2022-08-12 11:27:09 -07:00
Jon Ross-Perkins 9b3f80c6d6 Switch proposal process from projects to labels (#1981)
This is being done because Projects v1 requires repo write access, a serious limitation for letting people use it. Projects v2 isn't a great option because it lacks event support. Labels are pretty stable in GitHub, so this switches to that.

Note this assumes we're fine renaming "decision: accepted" -> "proposal accepted", etc. There are two reasons for this:

1) To make it clear that this is a proposal-specific label, versus something like an issue for leads label.
2) Removing the colon because it was causing trouble with yaml syntax.

This also adds the "proposal draft" label, mainly to complete the taxonomy.

I was considering whether this should be a proposal itself, but it feels like maybe it's not necessary because it's a fairly low-key infrastructure change, and I'm not sure how much people were relying on the project board anyways.

I tested this in a personal repo, basically just poking at https://github.com/jonmeow/test/pull/2
2022-08-12 11:11:09 -07:00