Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,13 +7,23 @@ on:
- main
- dev

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
verify:
runs-on: ubuntu-latest
timeout-minutes: 15

steps:
- name: Checkout code
uses: actions/checkout@v4
with:
persist-credentials: false

- name: Setup Node.js
uses: actions/setup-node@v4
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/lab-reject-pr-to-main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,16 @@ on:
pull_request:
branches: [main]

permissions: {}

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
reject:
runs-on: ubuntu-latest
timeout-minutes: 2
steps:
- name: Explain
run: |
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/lab-sync-upstream-main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,20 +5,20 @@ name: lab — sync main from upstream
on:
schedule:
- cron: "17 6 * * *"
push:
branches: [main]
workflow_dispatch:

concurrency:
group: lab-sync-upstream-main
cancel-in-progress: true
# A newer request must not interrupt an in-flight branch update.
cancel-in-progress: false

permissions:
contents: read

jobs:
sync:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Check out main over SSH
uses: actions/checkout@v4
Expand Down
7 changes: 6 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,13 @@ on:
tags:
- 'v*'

permissions:
contents: read

jobs:
build-and-release:
runs-on: ubuntu-latest
timeout-minutes: 15

permissions:
contents: write
Expand All @@ -16,6 +20,7 @@ jobs:
- name: Checkout code
uses: actions/checkout@v4
with:
persist-credentials: false
fetch-depth: 0
fetch-tags: true

Expand Down Expand Up @@ -58,7 +63,7 @@ jobs:
git log --pretty=format:"- %h %s" "${range}" >> release-notes.md

- name: Create Release
uses: softprops/action-gh-release@v1
uses: softprops/action-gh-release@v2
with:
files: dist/management.html
body_path: release-notes.md
Expand Down
3 changes: 2 additions & 1 deletion LAB.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,8 @@ GitHub enforces that:
- `.github/workflows/lab-reject-pr-to-main.yml` fails any PR that
targets `main`.
- `.github/workflows/lab-sync-upstream-main.yml` resets `main` to
`upstream/main` daily, on push, and via workflow_dispatch.
`upstream/main` daily and via workflow_dispatch. A push from the sync
deploy key does not schedule another redundant sync.

PR #1 was merged into `main` by accident and then undone. The ruleset
is there so that cannot stick again.
Expand Down
Loading