mirror of
https://github.com/carbon-language/carbon-lang.git
synced 2026-09-29 18:05:02 +01:00
This disables the autoassign action so that the codeowners approach can be tested without interference. Trying this out because it might be a path for vacation handling. See [GitHub docs](https://docs.github.com/en/organizations/organizing-members-into-teams/managing-code-review-settings-for-your-team) and [#infra](https://discord.com/channels/655572317891461132/707150492370862090/1422985757311635620) --------- Co-authored-by: Dana Jansens <danakj@orodu.net>
Workflows
Hardening
Workflows are hardened using Step Security tool. Findings for the "Harden Runner" steps are available online.
Allowed endpoints
Most jobs only have a few endpoints, but due to tools which do downloads, a few have significantly more. These are:
- pre_commit.yaml (Bazel, pre-commit)
- nightly_release.yaml (Bazel)
- tests.yaml (Bazel)
When updating one of these, consider updating all of them.
We try to keep allowed-endpoints with one per line. Prettier wants to wrap
them, which we fix this with prettier-ignore.
Testing
We keep around an action-test branch in carbon-lang, which can be used to test
triggers with push: configurations. For example:
on:
push:
branches: [action-test]