Files
carbon-lang/.github/workflows/sync_repos.yaml
T
Jon Ross-Perkins 6786edd6ff Update action versions (#6848)
In addition to the general updates, this switches to a required python
3.10 for pre-commit (3.9 is losing support from black).

Note endpoints for build actions are expanding significantly: see
https://app.stepsecurity.io/github/carbon-language/carbon-lang/actions/runs/22779388360?tab=recommendations&jobId=66080970460
for example, I think just the sources are being increased as a
side-effect of updates (and possibly also things not performing as well
as they should have before).

Similarly allowing sudo in pre-commit because it was actually causing
errors in part of build setup, which used sudo to remove files.

Assisted-by: Google Antigravity with Gemini
2026-03-06 22:19:44 +00:00

41 lines
1.2 KiB
YAML

# Part of the Carbon Language project, under the Apache License v2.0 with LLVM
# Exceptions. See /LICENSE for license information.
# SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
name: Sync repos
on:
push:
branches: [trunk]
paths:
# Minimize where we run this to changes to the top-level files and
# specific trees that we sync to other repositories.
- '*'
- 'utils/**'
# Also run if the action itself is updated.
- '.github/workflows/sync_repos.yaml'
- 'scripts/sync_repos.sh'
# Note the sync script has its own token.
permissions:
contents: read # For actions/checkout.
jobs:
sync-repos:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@58077d3c7e43986b6b15fba718e8ea69e387dfcc # v2.15.1
with:
egress-policy: audit
# Checkout our main repository.
- name: Checkout the main repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# Run the sync script.
- name: Sync to other repositories
env:
API_TOKEN_GITHUB: ${{ secrets.SYNC_REPOS_API_TOKEN_GITHUB }}
run: ./scripts/sync_repos.sh