Skip to content

Update Gradle to v9.8.0 #28

Update Gradle to v9.8.0

Update Gradle to v9.8.0 #28

Workflow file for this run

# Generated by velnor-workflow. Regenerate; do not hand-edit.

Check warning on line 1 in .github/workflows/ci-policy.yml

View workflow run for this annotation

GitHub Actions / Velnor workflow policy

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
name: Velnor workflow policy
on:
pull_request_target:
types: [opened, synchronize, reopened]
workflow_dispatch:
concurrency:
group: policy-${{ github.repository }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
policy:
name: Policy
runs-on: ubuntu-24.04
timeout-minutes: 20
# Trust invariant: this job runs the base branch's validator against the
# audited tree under pull_request_target. It holds `contents: read` only,
# references no secrets, and its checkout persists no credentials, so
# building and running the tree's declared generator here is no more
# privileged than the pull_request lanes that already build the tree.
permissions:
contents: read
steps:
- name: Checkout repository history
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
path: policy-checkout
fetch-depth: 0
persist-credentials: false
- name: Check out audited head
working-directory: policy-checkout
env:
HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
HEAD_REPOSITORY: ${{ github.event.pull_request.head.repo.full_name || github.repository }}
run: |
set -euo pipefail
if ! git cat-file -e "$HEAD_SHA^{commit}" 2>/dev/null; then
git fetch --no-tags "$GITHUB_SERVER_URL/$HEAD_REPOSITORY" "$HEAD_SHA"
fi
git checkout --quiet --detach "$HEAD_SHA"
- name: Bound the Mr. Boxington store
shell: bash
run: echo "MBX_GC_MAX_SIZE=12GiB" >> "$GITHUB_ENV"
- name: Set up Mr. Boxington
uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0
with:
backend: github
version: 1.11.1
cache-key: velnor-policy-mbx-1.11.1-${{ runner.os }}-${{ runner.arch }}-b9c3156cdb88e63c11b9e595a3e694b02238c09a
restore-keys: |
velnor-policy-mbx-1.11.1-${{ runner.os }}-${{ runner.arch }}-
- name: Install pinned Velnor workflow runtime
env:
CARGO_HOME: ${{ runner.temp }}/velnor-workflow-cargo-home
CARGO_TARGET_DIR: ${{ runner.temp }}/velnor-workflow-cargo-target
VELNOR_WORKFLOW_INSTALL_DIR: ${{ runner.temp }}/velnor-workflow-install
VELNOR_WORKFLOW_ROOT: ${{ runner.temp }}/velnor-workflow
run: |
set -euo pipefail
install -d -m 700 \
"$CARGO_HOME" \
"$CARGO_TARGET_DIR" \
"$VELNOR_WORKFLOW_INSTALL_DIR"
cd "$VELNOR_WORKFLOW_INSTALL_DIR"
env -u RUSTC_WRAPPER -u SCCACHE_GHA_ENABLED -u CARGO_INCREMENTAL -u RUSTFLAGS -u CARGO_ENCODED_RUSTFLAGS \
cargo install \
--locked \
--git https://github.com/tailrocks/velnor \
--rev b9c3156cdb88e63c11b9e595a3e694b02238c09a \
--root "$VELNOR_WORKFLOW_ROOT" \
velnor-workflow \
--bin velnor-workflow
echo "$VELNOR_WORKFLOW_ROOT/bin" >> "$GITHUB_PATH"
- name: Resolve required status checks
env:
GH_TOKEN: ${{ github.token }}
DEFAULT_BRANCH: main
DECLARED_RULESET_CONTEXTS: DCO,Policy,ci-required
run: |
set -euo pipefail
stderr="$(mktemp)"
trap 'rm -f "$stderr"' EXIT
if contexts="$(gh api "repos/$GITHUB_REPOSITORY/rulesets?includes_parents=true" 2>"$stderr" \
| jq -r '.[] | select(.target == "branch" and .enforcement == "active") | .id' \
| while read -r id; do gh api "repos/$GITHUB_REPOSITORY/rulesets/$id"; done \
| jq -r --arg branch "refs/heads/$DEFAULT_BRANCH" 'select(.conditions.ref_name.include | any(. == "~DEFAULT_BRANCH" or . == "~ALL" or . == $branch)) | .rules[] | select(.type == "required_status_checks") | .parameters.required_status_checks[].context' \
| sort -u | paste -sd, -)"; then
:
elif grep -qE '(HTTP 403|Upgrade to GitHub Team)' "$stderr"; then
echo "::warning::rulesets API returned 403; falling back to declared contexts [$DECLARED_RULESET_CONTEXTS]"
contexts="$DECLARED_RULESET_CONTEXTS"
else
cat "$stderr" >&2
exit 1
fi
echo "RULESET_CONTEXTS=$contexts" >> "$GITHUB_ENV"
- name: Enforce workflow policy
env:
WORKFLOW_ROOT: ${{ github.workspace }}/policy-checkout
HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
BASE_SHA: ${{ github.event.pull_request.base.sha || github.sha }}
VELNOR_WORKFLOW_POLICY_REVISION: b9c3156cdb88e63c11b9e595a3e694b02238c09a
run: |
set -euo pipefail
velnor-workflow policy \
--workflow-root "$WORKFLOW_ROOT" \
--head-sha "$HEAD_SHA" \
--base-sha "$BASE_SHA" \
--ruleset-contexts "$RULESET_CONTEXTS"
- name: Set up actionlint
uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
with:
install_args: actionlint@1.7.12
cache: false
- name: Lint caller workflows
working-directory: policy-checkout
run: mise exec actionlint@1.7.12 -- actionlint