ci: add a PR gate for pull requests from outside contributors - #383
Merged
Merged
Conversation
Mass-PR accounts open unrequested one-line pull requests without tests or a changelog fragment. The PR gate closes a pull request from an outside contributor that does not close an issue assigned to its author, and fails with a comment when a change to fastapi_cachex/ lacks a test or a fragment. Maintainers, collaborators and bots are exempt; the skip-pr-gate label waives the check. It runs on pull_request_target so it can comment and close on fork pull requests, and reads the pull request only through the API: no pull request code is checked out or run. CONTRIBUTING (en and zh-TW) documents the rules, and a pull request template points to them.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The repository gets unrequested pull requests from accounts that open hundreds of them a month. #379, for example, was a one-line change with no test and no changelog fragment. This adds a check that filters those out before a maintainer reads them, using the rules in the contributing guide.
What the gate does
It runs only for outside contributors.
OWNER,MEMBERandCOLLABORATORauthors are exempt, and so are bots such as Renovate and Dependabot.Fixes #N,owner/repo#Nor the issue URL)fastapi_cachex/has no test undertests/, or nochangelog.d/<issue>.<section>.mdskip-pr-gatelabel is present<!-- pr-gate -->, and updates it instead of posting again.concurrencygroup serializes runs per pull request.Security
The workflow uses
pull_request_target, so it can comment on and close pull requests from forks. That is safe here only because it never checks out or runs code from the pull request:run:step and no checkout;${{ }}expression inside the script;Permissions are
issues: readandpull-requests: write, withpermissions: {}at the top level. zizmor'sdangerous-triggersfinding is suppressed inline, with that justification.Docs
docs/CONTRIBUTING.mdand the zh-TW mirror gain a "Before You Open a Pull Request" section: claim the issue, wait for assignment, then open the PR. It also covers what the gate does and how a maintainer overrides it..github/pull_request_template.mdpoints to that section.Testing
github/context/corein 15 scenarios, covering:#N,owner/repo#Nand URL forms, andsuffixes #3not matching;skip-pr-gatelabel has been created.