Skip to content

Synchronising version between ecCodes and ecCodes Python #101

Synchronising version between ecCodes and ecCodes Python

Synchronising version between ecCodes and ecCodes Python #101

name: PR Workflow Check

Check warning on line 1 in ecmwf/workflow-check-action/.github/workflows/pr-workflow-check.yml

View workflow run for this annotation

GitHub Actions / PR Workflow Check

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
on:
pull_request_target: ~
permissions:
contents: read
pull-requests: write
jobs:
check:
if: ${{ github.event.pull_request.head.repo.fork }}
runs-on: ubuntu-latest
steps:
- name: Check changes to .github
id: check
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8
with:
script: |
const files = await github.paginate(github.rest.pulls.listFiles, {
owner: context.repo.owner,
repo: context.repo.repo,
pull_number: context.payload.pull_request.number,
per_page: 100,
});
// Consider both the current and previous path (for renames/deletes)
const changed = new Set();
for (const f of files) {
changed.add(f.filename);
if (f.previous_filename) changed.add(f.previous_filename);
}
core.info("==> Changed files:");
for (const f of changed) core.info(f);
const violations = [...changed].filter(f => f.startsWith(".github/"));
if (violations.length > 0) {
core.info(`==> Found ${violations.length} violations!`);
core.info("==> Violating files");
violations.forEach(v => core.info(v));
core.setOutput("bad", "true");
core.setFailed("PR is trying to change a workflow!");
} else {
core.info("All OK");
core.setOutput("bad", "false");
}
- name: Comment PR
if: ${{ always() && steps.check.outputs.bad == 'true' }}
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8
with:
script: |
github.rest.issues.createComment({
issue_number: context.issue.number,
owner: context.repo.owner,
repo: context.repo.repo,
body: `> [!CAUTION]
> This pull request contains changes to GitHub workflows!
> Proceed with caution and if not sure, contact your GitHub admin.`
})