Merge pull request #535 from open-gsd/ci/maintainer-pr-policy-skips

ci(#534): skip maintainer PR policy gates
This commit is contained in:
Jeremy McSpadden
2026-05-31 07:49:37 -05:00
committed by GitHub
3 changed files with 44 additions and 1 deletions

View File

@@ -14,7 +14,10 @@ permissions:
jobs:
close-if-draft:
name: Reject draft PRs
if: github.event.pull_request.draft == true
# Maintainers may use draft PRs for internal coordination.
if: >-
github.event.pull_request.draft == true &&
contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.pull_request.author_association) == false
runs-on: ubuntu-latest
steps:
- name: Comment and close draft PR

View File

@@ -22,6 +22,9 @@ permissions:
jobs:
validate-target:
# Maintainers may open internal release/backport coordination PRs against main.
if: >-
contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.pull_request.author_association) == false
runs-on: ubuntu-latest
timeout-minutes: 2
env:

View File

@@ -0,0 +1,37 @@
// allow-test-rule: source-text-is-the-product
// These workflow files are deployed policy; the tests lock the maintainer
// carve-out so future edits do not accidentally re-enable enforcement.
'use strict';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const MAINTAINER_SKIP_EXPR = 'contains(fromJSON(\'["OWNER","MEMBER","COLLABORATOR"]\'), github.event.pull_request.author_association) == false';
function readWorkflow(relativePath) {
return fs.readFileSync(path.join(process.cwd(), relativePath), 'utf8');
}
function assertMaintainerSkip(source) {
assert.ok(
source.includes(MAINTAINER_SKIP_EXPR),
`Expected workflow to include maintainer skip expression: ${MAINTAINER_SKIP_EXPR}`
);
}
describe('PR policy workflow maintainer carve-outs', () => {
test('draft PR auto-close does not run for maintainer-authored PRs', () => {
const workflow = readWorkflow('.github/workflows/close-draft-prs.yml');
assert.match(workflow, /github\.event\.pull_request\.draft == true/);
assertMaintainerSkip(workflow);
});
test('PR target validator does not run for maintainer-authored PRs', () => {
const workflow = readWorkflow('.github/workflows/pr-target-validator.yml');
assertMaintainerSkip(workflow);
});
});