📤 Emit⇗⇗⇗ create event. Origin: dependabot/docker/build/tdx-qgs/docker-tdx-qgs-2eaa808662 - ID: 260-1 - by dependabot[bot]
#260
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Route branch events to external dispatcher (if any) | |
| # This action only runs on repositories which are named EXTENSION_THIS_REPO_NAME and have the extension dispatcher defined. | |
| # Its purpose is to kick-off any auxiliary GHA tasks that are NOT on the target branch, but may be required by repo/fork policy. | |
| # Set workflow-level permissions to an empty map (deny-by-default for all scopes). | |
| # GitHub implicitly grants metadata: read regardless of this setting. | |
| permissions: {} | |
| on: | |
| create: | |
| merge_group: | |
| types: [checks_requested] | |
| pull_request_target: # Caution: This will trigger this from across forks, with access to this repo secrets. | |
| types: [ opened, reopened, edited, auto_merge_enabled, synchronize, converted_to_draft, locked, unlocked, ready_for_review, review_requested, review_request_removed, auto_merge_disabled, labeled, unlabeled ] | |
| branches: | |
| - '**' | |
| pull_request_review: | |
| types: [submitted, edited] | |
| push: | |
| branches: | |
| - 'main*' | |
| - 'platform/**' | |
| - 'release*' | |
| tags: | |
| - 'DCAP_*' | |
| - 'dcap_*' | |
| - 'sgx_*' | |
| workflow_dispatch: | |
| jobs: | |
| publish_branch_event_to_extensions: | |
| name: "On branch action: emit an event for external handler, if any [ignore me, I'm not a real check]" | |
| runs-on: ${{vars.EXTENSION_RUNNER_ID}} | |
| # Explicitly declare all permission scopes for this job. Only `actions: write` is needed | |
| # (for createWorkflowDispatch). All other scopes are set to none to enforce least-privilege. | |
| permissions: | |
| actions: write | |
| contents: none # Dropping all non-required permissions (incl. code checkout) to harden, esp. given pull_request_target is one of the triggers. Only `actions: write` is granted - for createWorkflowDispatch() | |
| checks: none | |
| deployments: none | |
| models: none | |
| id-token: none | |
| issues: none | |
| discussions: none | |
| packages: none | |
| pages: none | |
| pull-requests: none | |
| repository-projects: none | |
| security-events: none | |
| statuses: none | |
| artifact-metadata: none | |
| attestations: none | |
| # Conditions: only run if in the designated repo and not auto-triggered by Copilot actions | |
| # Reacts on all trigger events listed above ('on:' section), except labeling events, which are filtered to only react to: | |
| # - "skip-" labels (both adding and removing) | |
| # - "refresh-" labels (only adding) | |
| if: | | |
| github.repository == vars.EXTENSION_THIS_REPO_NAME && github.actor != 'Copilot' && ( | |
| github.event_name != 'pull_request_target' || | |
| (github.event_name == 'pull_request_target' && github.event.action != 'unlabeled' && github.event.action != 'labeled') || ( | |
| contains(github.event.label.name, 'skip-') || | |
| (github.event.action == 'labeled' && contains(github.event.label.name, 'refresh-')) | |
| ) | |
| ) | |
| steps: | |
| - name: Trigger Extension Workflow | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 | |
| env: | |
| EXTENSION_DISPATCHER_WORKFLOW_NAME: ${{vars.EXTENSION_DISPATCHER_WORKFLOW_NAME}} | |
| EXTENSION_BRANCH_NAME: ${{vars.EXTENSION_BRANCH_NAME}} | |
| REF_NAME: ${{ github.ref_name }} | |
| with: | |
| retries: 3 | |
| script: | | |
| const wf_inputs = { | |
| triggering_event_name: context.eventName, | |
| triggering_branch_name: context.ref, | |
| triggering_branch_name_short: process.env.REF_NAME, | |
| triggering_sha: context.sha, | |
| triggering_action: context.payload ? context.payload.action : undefined, | |
| triggering_context: JSON.stringify({ | |
| actor: context.actor, | |
| payload: { | |
| action: context.payload?.action, | |
| number: context.payload?.number, | |
| requested_reviewer: { login: context.payload?.requested_reviewer?.login }, | |
| label: { name: context.payload?.label?.name }, | |
| pull_request: { | |
| number: context.payload?.pull_request?.number, | |
| head: { | |
| ref: context.payload?.pull_request?.head?.ref, | |
| sha: context.payload?.pull_request?.head?.sha, | |
| }, | |
| base: { ref: context.payload?.pull_request?.base?.ref }, | |
| user: { | |
| login: context.payload?.pull_request?.user?.login, | |
| type: context.payload?.pull_request?.user?.type, | |
| }, | |
| }, | |
| }, | |
| }), | |
| triggering_run_id: String(context.runId), | |
| triggering_run_number: String(context.runNumber) + '-' + String(context.runAttempt || 1) | |
| }; | |
| if ( core.isDebug() ) { | |
| core.startGroup('Triggering context debug info'); | |
| console.debug('Workflow dispatch inputs:', JSON.stringify(wf_inputs, null, 4)); | |
| core.endGroup(); | |
| } | |
| await github.rest.actions.createWorkflowDispatch({ | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| workflow_id: process.env.EXTENSION_DISPATCHER_WORKFLOW_NAME, | |
| ref: process.env.EXTENSION_BRANCH_NAME, | |
| inputs: wf_inputs | |
| }); | |
| run-name: | | |
| :outbox_tray: Emit⇗⇗⇗ `${{ github.event.action && format('{0}[{1}]', github.event_name, github.event.action) || github.event_name }}` event. Origin: ${{ github.event_name == 'pull_request_target' && format('`{0}`[←`{1}`]', github.ref_name, github.event.pull_request.head.label) || format('`{0}`', github.ref_name) }} - ID: ${{ github.run_number }}-${{ github.run_attempt }} - ${{ github.actor != 'Copilot' && format('by `{0}`', github.actor) || 'by `Copilot` (ignored)' }} |