issue-policy.yml 2.2 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758
  1. name: Issue policy
  2. on:
  3. pull_request:
  4. types: [opened, edited, synchronize, reopened, labeled, unlabeled, ready_for_review, review_requested]
  5. pull_request_review:
  6. types: [submitted]
  7. permissions:
  8. contents: read
  9. issues: read
  10. pull-requests: read
  11. jobs:
  12. policy:
  13. name: Issue policy
  14. runs-on: ubuntu-latest
  15. steps:
  16. - name: Check out trusted policy
  17. uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
  18. with:
  19. ref: ${{ github.event.repository.default_branch }}
  20. persist-credentials: false
  21. - name: Determine policy eligibility
  22. id: preflight
  23. env:
  24. GITHUB_TOKEN: ${{ github.token }}
  25. shell: bash
  26. run: |
  27. if [ -f .github/issue-management/selective-preflight.json ]; then
  28. node .github/issue-management/policy.mjs pr-preflight
  29. else
  30. node --input-type=module <<'NODE'
  31. import fs from 'node:fs'
  32. const event = JSON.parse(fs.readFileSync(process.env.GITHUB_EVENT_PATH, 'utf8'))
  33. const automated = ['Bot', 'App'].includes(event.pull_request.user.type)
  34. fs.appendFileSync(process.env.GITHUB_OUTPUT, `legacy-automated=${automated}\nneeds-project=${!automated}\n`)
  35. console.log('Trusted policy has no selective preflight; preserving legacy policy enforcement.')
  36. NODE
  37. fi
  38. - name: Create Project read token
  39. id: app-token
  40. if: ${{ steps.preflight.outputs.needs-project == 'true' }}
  41. uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1
  42. with:
  43. client-id: ${{ vars.DSH_ISSUE_APP_CLIENT_ID }}
  44. private-key: ${{ secrets.DSH_ISSUE_APP_PRIVATE_KEY }}
  45. owner: deepseek-harness
  46. repositories: deepseek-harness
  47. permission-issues: read
  48. permission-organization-projects: read
  49. # Re-read current state even after an exempt preflight; never replace a failure with an edit skip.
  50. - name: Validate pull request
  51. if: ${{ steps.preflight.outputs.legacy-automated != 'true' }}
  52. env:
  53. GITHUB_TOKEN: ${{ github.token }}
  54. PROJECT_TOKEN: ${{ steps.app-token.outputs.token }}
  55. run: node .github/issue-management/policy.mjs pr