mirror of
https://github.com/carbon-language/carbon-lang.git
synced 2026-09-28 20:34:53 +01:00
In addition to the general updates, this switches to a required python 3.10 for pre-commit (3.9 is losing support from black). Note endpoints for build actions are expanding significantly: see https://app.stepsecurity.io/github/carbon-language/carbon-lang/actions/runs/22779388360?tab=recommendations&jobId=66080970460 for example, I think just the sources are being increased as a side-effect of updates (and possibly also things not performing as well as they should have before). Similarly allowing sudo in pre-commit because it was actually causing errors in part of build setup, which used sudo to remove files. Assisted-by: Google Antigravity with Gemini
41 lines
1.2 KiB
YAML
41 lines
1.2 KiB
YAML
# Part of the Carbon Language project, under the Apache License v2.0 with LLVM
|
|
# Exceptions. See /LICENSE for license information.
|
|
# SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
|
|
|
|
name: Sync repos
|
|
|
|
on:
|
|
push:
|
|
branches: [trunk]
|
|
paths:
|
|
# Minimize where we run this to changes to the top-level files and
|
|
# specific trees that we sync to other repositories.
|
|
- '*'
|
|
- 'utils/**'
|
|
# Also run if the action itself is updated.
|
|
- '.github/workflows/sync_repos.yaml'
|
|
- 'scripts/sync_repos.sh'
|
|
|
|
# Note the sync script has its own token.
|
|
permissions:
|
|
contents: read # For actions/checkout.
|
|
|
|
jobs:
|
|
sync-repos:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@58077d3c7e43986b6b15fba718e8ea69e387dfcc # v2.15.1
|
|
with:
|
|
egress-policy: audit
|
|
|
|
# Checkout our main repository.
|
|
- name: Checkout the main repository
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
# Run the sync script.
|
|
- name: Sync to other repositories
|
|
env:
|
|
API_TOKEN_GITHUB: ${{ secrets.SYNC_REPOS_API_TOKEN_GITHUB }}
|
|
run: ./scripts/sync_repos.sh
|