Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
123 changes: 123 additions & 0 deletions .github/workflows/fleet-status.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,123 @@
# Posts fleet review-lane commit statuses for pull requests.
# Reads labels, comments, reviews and checks; writes statuses. Runs the default branch's script.
# self-test runs the script's tests on the PR's own code, read-only.
# backfill (manual) posts them on every open PR, e.g. once they become required.
# No concurrency group: a cancelled run rolls up as a failed check on the PR. The script
# re-reads after posting and corrects what differs, so the last run to act leaves current statuses.
name: Fleet status

on:
workflow_dispatch:
pull_request:
types: [opened, synchronize, reopened, ready_for_review, labeled, unlabeled]
pull_request_review:
types: [submitted, edited, dismissed]
issue_comment:
types: [created, edited, deleted]
workflow_run:
workflows: [CI, CodeQL, Image, labels]
types: [completed]

permissions: {}

jobs:
status:
# Fork PRs are not reviewed by the fleet, and their events carry a read-only token anyway.
# issue_comment fires for issues too; only PR comments matter. The script re-checks both.
if: >-
(github.event_name == 'issue_comment' && github.event.issue.pull_request != null) ||
(github.event_name == 'workflow_run' && github.event.workflow_run.event == 'pull_request' &&
github.event.workflow_run.head_repository.full_name == github.repository &&
github.event.workflow_run.pull_requests[0] != null) ||
(github.event_name != 'issue_comment' && github.event_name != 'workflow_run' &&
github.event.pull_request.head.repo.full_name == github.repository)
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
contents: read
pull-requests: read
issues: read
checks: read
statuses: write
steps:
- uses: askalf/checkout-with-retry@115a6407547e9711edbc2e915838d495cad9583f # v1.1.0
with:
ref: ${{ github.event.repository.default_branch }}
sparse-checkout: scripts/fleet-status.mjs
sparse-checkout-cone-mode: false
persist-credentials: false

- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22

- name: Post the lane statuses
if: hashFiles('scripts/fleet-status.mjs') != ''
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
REPO: ${{ github.repository }}
PR: ${{ github.event.pull_request.number || github.event.issue.number || github.event.workflow_run.pull_requests[0].number }}
TARGET_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
run: node scripts/fleet-status.mjs

self-test:
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
contents: read
steps:
- uses: askalf/checkout-with-retry@115a6407547e9711edbc2e915838d495cad9583f # v1.1.0
with:
persist-credentials: false

- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22

- name: Test the lane rules
run: node scripts/fleet-status.test.mjs

backfill:
# Manual: post the lane statuses on every open same-repo PR. Run it right after
# the fleet/* contexts become required checks, so PRs opened before that report.
if: github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
pull-requests: read
issues: read
checks: read
statuses: write
steps:
- uses: askalf/checkout-with-retry@115a6407547e9711edbc2e915838d495cad9583f # v1.1.0
with:
ref: ${{ github.event.repository.default_branch }}
sparse-checkout: scripts/fleet-status.mjs
sparse-checkout-cone-mode: false
persist-credentials: false

- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22

- name: Post the lane statuses on every open PR
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
REPO: ${{ github.repository }}
TARGET_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
run: |
set -euo pipefail
# gh pages past 100 on its own; at the cap, fail rather than skip PRs silently.
all="$(gh pr list --repo "$REPO" --state open --limit 1000 --json number,isCrossRepository)"
if [ "$(printf '%s' "$all" | jq 'length')" -ge 1000 ]; then
echo "::error::1000 or more open PRs; raise the backfill limit"
exit 1
fi
prs="$(printf '%s' "$all" | jq -r '.[] | select(.isCrossRepository | not) | .number')"
for pr in $prs; do
echo "== #$pr"
PR="$pr" node scripts/fleet-status.mjs
done
Loading
Loading