Files
carbon-lang/.github/workflows/proposal_labeled.yaml
T
Jon Ross-Perkins b73387fc84 Update workflows for security hardening. (#4192)
Also a small pass on workflow names.

Note, I'm a little concerned that the test/nightly release/pre-commit
endpoints may be fragile. At the same time, it's also where it may be
most useful, to prevent network access by arbitrary test code. I think
this is imperfect, but maybe we can try it out and see if it's much of
an issue.

Note, the discord wiki action is currently broken, this should fix it.
2024-08-06 23:14:23 +00:00

107 lines
3.3 KiB
YAML

# Part of the Carbon Language project, under the Apache License v2.0 with LLVM
# Exceptions. See /LICENSE for license information.
# SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
# Applies mutual exclusivity between states labels:
# - proposal draft
# - proposal rfc
# - proposal accepted
# - proposal declined
# - proposal deferred
#
# The "proposal" label is always applied in order to make searching for all
# proposals (regardless of state) easy, although it will typically already be
# present.
name: Proposal labeled
on:
pull_request_target:
types:
- labeled
permissions:
pull-requests: write # For gh to edit labels.
jobs:
proposal_labeled:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@17d0e2bd7d51742c71671bd19fa12bdc9d40a3d6 # v2.8.1
with:
disable-sudo: true
egress-policy: block
# prettier-ignore
allowed-endpoints: >
api.github.com:443
- name: draft
if: |
github.event.label.name == 'proposal draft'
run: |
gh pr edit "${PR}" \
--remove-label "proposal rfc" \
--remove-label "proposal accepted" \
--remove-label "proposal declined" \
--remove-label "proposal deferred" \
--add-label "proposal"
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR: ${{ github.event.pull_request.html_url }}
- name: rfc
if: |
github.event.label.name == 'proposal rfc'
run: |
gh pr edit "${PR}" \
--remove-label "proposal draft" \
--remove-label "proposal accepted" \
--remove-label "proposal declined" \
--remove-label "proposal deferred" \
--add-label "proposal"
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR: ${{ github.event.pull_request.html_url }}
- name: accepted
if: |
github.event.label.name == 'proposal accepted'
run: |
gh pr edit "${PR}" \
--remove-label "proposal draft" \
--remove-label "proposal rfc" \
--remove-label "proposal declined" \
--remove-label "proposal deferred" \
--add-label "proposal"
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR: ${{ github.event.pull_request.html_url }}
- name: declined
if: |
github.event.label.name == 'proposal declined'
run: |
gh pr edit "${PR}" \
--remove-label "proposal draft" \
--remove-label "proposal rfc" \
--remove-label "proposal accepted" \
--remove-label "proposal deferred" \
--add-label "proposal"
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR: ${{ github.event.pull_request.html_url }}
- name: deferred
if: |
github.event.label.name == 'proposal deferred'
run: |
gh pr edit "${PR}" \
--remove-label "proposal draft" \
--remove-label "proposal rfc" \
--remove-label "proposal accepted" \
--remove-label "proposal declined" \
--add-label "proposal"
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR: ${{ github.event.pull_request.html_url }}