Skip to content

📤 Emit⇗⇗⇗ pull_request_target[labeled] event. Origin: main[←intel:dependabot/docker/build/tdx-qgs/docker-tdx-qgs-2eaa808662] - ID: 264-1 - by dependabot[bot] #264

📤 Emit⇗⇗⇗ pull_request_target[labeled] event. Origin: main[←intel:dependabot/docker/build/tdx-qgs/docker-tdx-qgs-2eaa808662] - ID: 264-1 - by dependabot[bot]

📤 Emit⇗⇗⇗ pull_request_target[labeled] event. Origin: main[←intel:dependabot/docker/build/tdx-qgs/docker-tdx-qgs-2eaa808662] - ID: 264-1 - by dependabot[bot] #264

name: Route branch events to external dispatcher (if any)
# This action only runs on repositories which are named EXTENSION_THIS_REPO_NAME and have the extension dispatcher defined.
# Its purpose is to kick-off any auxiliary GHA tasks that are NOT on the target branch, but may be required by repo/fork policy.
# Set workflow-level permissions to an empty map (deny-by-default for all scopes).
# GitHub implicitly grants metadata: read regardless of this setting.
permissions: {}
on:
create:
merge_group:
types: [checks_requested]
pull_request_target: # Caution: This will trigger this from across forks, with access to this repo secrets.
types: [ opened, reopened, edited, auto_merge_enabled, synchronize, converted_to_draft, locked, unlocked, ready_for_review, review_requested, review_request_removed, auto_merge_disabled, labeled, unlabeled ]
branches:
- '**'
pull_request_review:
types: [submitted, edited]
push:
branches:
- 'main*'
- 'platform/**'
- 'release*'
tags:
- 'DCAP_*'
- 'dcap_*'
- 'sgx_*'
workflow_dispatch:
jobs:
publish_branch_event_to_extensions:
name: "On branch action: emit an event for external handler, if any [ignore me, I'm not a real check]"
runs-on: ${{vars.EXTENSION_RUNNER_ID}}
# Explicitly declare all permission scopes for this job. Only `actions: write` is needed
# (for createWorkflowDispatch). All other scopes are set to none to enforce least-privilege.
permissions:
actions: write
contents: none # Dropping all non-required permissions (incl. code checkout) to harden, esp. given pull_request_target is one of the triggers. Only `actions: write` is granted - for createWorkflowDispatch()
checks: none
deployments: none
models: none
id-token: none
issues: none
discussions: none
packages: none
pages: none
pull-requests: none
repository-projects: none
security-events: none
statuses: none
artifact-metadata: none
attestations: none
# Conditions: only run if in the designated repo and not auto-triggered by Copilot actions
# Reacts on all trigger events listed above ('on:' section), except labeling events, which are filtered to only react to:
# - "skip-" labels (both adding and removing)
# - "refresh-" labels (only adding)
if: |
github.repository == vars.EXTENSION_THIS_REPO_NAME && github.actor != 'Copilot' && (
github.event_name != 'pull_request_target' ||
(github.event_name == 'pull_request_target' && github.event.action != 'unlabeled' && github.event.action != 'labeled') || (
contains(github.event.label.name, 'skip-') ||
(github.event.action == 'labeled' && contains(github.event.label.name, 'refresh-'))
)
)
steps:
- name: Trigger Extension Workflow
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
env:
EXTENSION_DISPATCHER_WORKFLOW_NAME: ${{vars.EXTENSION_DISPATCHER_WORKFLOW_NAME}}
EXTENSION_BRANCH_NAME: ${{vars.EXTENSION_BRANCH_NAME}}
REF_NAME: ${{ github.ref_name }}
with:
retries: 3
script: |
const wf_inputs = {
triggering_event_name: context.eventName,
triggering_branch_name: context.ref,
triggering_branch_name_short: process.env.REF_NAME,
triggering_sha: context.sha,
triggering_action: context.payload ? context.payload.action : undefined,
triggering_context: JSON.stringify({
actor: context.actor,
payload: {
action: context.payload?.action,
number: context.payload?.number,
requested_reviewer: { login: context.payload?.requested_reviewer?.login },
label: { name: context.payload?.label?.name },
pull_request: {
number: context.payload?.pull_request?.number,
head: {
ref: context.payload?.pull_request?.head?.ref,
sha: context.payload?.pull_request?.head?.sha,
},
base: { ref: context.payload?.pull_request?.base?.ref },
user: {
login: context.payload?.pull_request?.user?.login,
type: context.payload?.pull_request?.user?.type,
},
},
},
}),
triggering_run_id: String(context.runId),
triggering_run_number: String(context.runNumber) + '-' + String(context.runAttempt || 1)
};
if ( core.isDebug() ) {
core.startGroup('Triggering context debug info');
console.debug('Workflow dispatch inputs:', JSON.stringify(wf_inputs, null, 4));
core.endGroup();
}
await github.rest.actions.createWorkflowDispatch({
owner: context.repo.owner,
repo: context.repo.repo,
workflow_id: process.env.EXTENSION_DISPATCHER_WORKFLOW_NAME,
ref: process.env.EXTENSION_BRANCH_NAME,
inputs: wf_inputs
});
run-name: |
:outbox_tray: Emit⇗⇗⇗ `${{ github.event.action && format('{0}[{1}]', github.event_name, github.event.action) || github.event_name }}` event. Origin: ${{ github.event_name == 'pull_request_target' && format('`{0}`[←`{1}`]', github.ref_name, github.event.pull_request.head.label) || format('`{0}`', github.ref_name) }} - ID: ${{ github.run_number }}-${{ github.run_attempt }} - ${{ github.actor != 'Copilot' && format('by `{0}`', github.actor) || 'by `Copilot` (ignored)' }}