Repository navigation
Make agent branch preparation authenticated, offline, and evidence-driven #87
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Merge Steward Reconcile | ||
|
Check warning on line 1 in .github/workflows/merge-steward-reconcile.yml
|
||
| on: | ||
| pull_request_target: | ||
| branches: [main] | ||
| types: [opened, reopened, synchronize, ready_for_review, converted_to_draft, labeled, unlabeled, edited] | ||
| workflow_run: | ||
| workflows: [CI] | ||
| types: [completed] | ||
| schedule: | ||
| - cron: '17,47 * * * *' | ||
| workflow_dispatch: | ||
| inputs: | ||
| pull_request_number: | ||
| description: Pull request number (empty reconciles all open PRs to main) | ||
| required: false | ||
| type: string | ||
| expected_head_sha: | ||
| description: Optional expected head SHA | ||
| required: false | ||
| type: string | ||
| observe_only: | ||
| description: Preview plans without performing actions | ||
| required: false | ||
| type: boolean | ||
| default: false | ||
| permissions: | ||
| contents: read | ||
| jobs: | ||
| resolve: | ||
| name: Resolve pull requests | ||
| if: github.event_name != 'workflow_dispatch' || github.ref == format('refs/heads/{0}', github.event.repository.default_branch) | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 3 | ||
| permissions: | ||
| contents: read | ||
| pull-requests: read | ||
| outputs: | ||
| matrix: ${{ steps.resolve.outputs.matrix }} | ||
| count: ${{ steps.resolve.outputs.count }} | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
| with: | ||
| ref: ${{ github.event.repository.default_branch }} | ||
| fetch-depth: 0 | ||
| persist-credentials: false | ||
| - id: resolve | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| run: node .github/merge-steward/reconcile.mjs --resolve | ||
| reconcile: | ||
| name: Reconcile PR ${{ matrix.number }} | ||
| needs: resolve | ||
| if: needs.resolve.outputs.count != '0' | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: ${{ fromJSON(needs.resolve.outputs.matrix) }} | ||
| concurrency: | ||
| group: merge-steward-${{ github.repository }}-${{ matrix.number }} | ||
| cancel-in-progress: false | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 5 | ||
| permissions: | ||
| actions: write | ||
| contents: read | ||
| pull-requests: read | ||
| steps: | ||
| - name: Check out trusted default branch | ||
| uses: actions/checkout@v4 | ||
| with: | ||
| ref: ${{ github.event.repository.default_branch }} | ||
| fetch-depth: 0 | ||
| persist-credentials: false | ||
| - name: Reconcile current candidate | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| PR_NUMBER: ${{ matrix.number }} | ||
| EXPECTED_HEAD_SHA: ${{ matrix.head }} | ||
| MERGE_STEWARD_APPLY: ${{ !(github.event_name == 'workflow_dispatch' && inputs.observe_only) }} | ||
| run: node .github/merge-steward/reconcile.mjs | ||