mirror of
https://github.com/supermemoryai/supermemory.git
synced 2026-09-30 01:51:28 +00:00
fix(ci): gate auto-fix to same-repo human runs (#1663)
## Summary The `workflow_run` auto-fix job has write permissions and checks out the triggering PR branch. It now runs only when all three conditions hold: - the tracked CI workflow failed on a pull request; - the pull request branch belongs to this repository, not a fork; - the triggering actor is not a bot account. The same-repository check closes the privileged fork boundary. The generic `[bot]` suffix check covers Polylane, Graphite, Dependabot, and other GitHub App bot users without maintaining a name list. ## Validation - `go run github.com/rhysd/actionlint/cmd/actionlint@v1.7.12 .github/workflows/claude-auto-fix-ci.yml` - YAML parse with the repository's installed parser - Final diff audit: one workflow, +3/-1, no added comments Human-triggered same-repository pull requests keep the existing auto-fix behavior.
This commit is contained in:
parent
69327ca1c6
commit
bf2db3dc79
1 changed files with 3 additions and 1 deletions
4
.github/workflows/claude-auto-fix-ci.yml
vendored
4
.github/workflows/claude-auto-fix-ci.yml
vendored
|
|
@ -17,7 +17,9 @@ jobs:
|
|||
auto-fix:
|
||||
if: |
|
||||
github.event.workflow_run.conclusion == 'failure' &&
|
||||
github.event.workflow_run.pull_requests[0]
|
||||
github.event.workflow_run.pull_requests[0] &&
|
||||
github.event.workflow_run.head_repository.full_name == github.event.workflow_run.repository.full_name &&
|
||||
!endsWith(github.event.workflow_run.actor.login, '[bot]')
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 30
|
||||
steps:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue