close-external-prs.yml 2.7 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364
  1. name: Close External PRs
  2. on:
  3. pull_request_target:
  4. types: [opened]
  5. permissions:
  6. pull-requests: write
  7. issues: write
  8. contents: read
  9. jobs:
  10. check-membership:
  11. if: vars.DISABLE_EXTERNAL_PR_CHECK != 'true'
  12. runs-on: ubuntu-latest
  13. steps:
  14. # pull_request_target: checks out the BASE repo (trusted), so the allowlist + shared
  15. # script below are this repo's versions, never the fork's.
  16. - uses: actions/checkout@v4
  17. - name: Close PR unless author is a member or the PR is an in-scope external contribution
  18. uses: actions/github-script@v7
  19. with:
  20. script: |
  21. const author = context.payload.pull_request.user.login;
  22. const { data } = await github.rest.repos.getCollaboratorPermissionLevel({
  23. owner: context.repo.owner,
  24. repo: context.repo.repo,
  25. username: author
  26. });
  27. if (['admin', 'write'].includes(data.permission)) {
  28. console.log(`${author} has ${data.permission} access, allowing PR`);
  29. return;
  30. }
  31. // Non-member: allow the PR to stay open ONLY if it is an in-scope external
  32. // contribution — it adds marketplace.json entries whose source repo ALREADY backs
  33. // a live plugin here, and changes nothing else. (No maintained allowlist: the set
  34. // of allowed repos is derived from the live marketplace.) This grants only the
  35. // right to open a reviewable PR; the External PR Scope Guard required check and a
  36. // maintainer approval still gate the merge.
  37. const { evaluate } = require(`${process.env.GITHUB_WORKSPACE}/.github/scripts/external-pr-scope.js`);
  38. const result = await evaluate({ github, context });
  39. if (result.ok && result.added.length > 0) {
  40. console.log(`In-scope external contribution (adds: ${result.added.join(', ')}) — allowing PR.`);
  41. return;
  42. }
  43. console.log(`Closing PR from ${author}: ${result.problems.join('; ') || 'out of scope'}`);
  44. await github.rest.issues.createComment({
  45. owner: context.repo.owner,
  46. repo: context.repo.repo,
  47. issue_number: context.payload.pull_request.number,
  48. body: `Thanks for your interest! This repo only accepts contributions from Anthropic team members. If you'd like to submit a plugin to the marketplace, please submit your plugin [here](https://clau.de/plugin-directory-submission).`
  49. });
  50. await github.rest.pulls.update({
  51. owner: context.repo.owner,
  52. repo: context.repo.repo,
  53. pull_number: context.payload.pull_request.number,
  54. state: 'closed'
  55. });