Skip to content

diff: add dy_d_best — reconciled dy.d_ (dy.dx step + NNS.stack on X*) #54

diff: add dy_d_best — reconciled dy.d_ (dy.dx step + NNS.stack on X*)

diff: add dy_d_best — reconciled dy.d_ (dy.dx step + NNS.stack on X*) #54

name: Protect workflow baseline
on:
pull_request_target:
types:
- opened
- synchronize
- reopened
- labeled
- unlabeled
permissions:
contents: write
pull-requests: write
concurrency:
group: workflow-baseline-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
restore-canonical-workflows:
name: Restore canonical workflow files
if: >-
github.event.pull_request.head.repo.full_name == github.repository &&
!contains(github.event.pull_request.labels.*.name, 'workflow-change-approved')
runs-on: ubuntu-latest
steps:
- name: Check out pull-request branch
uses: actions/checkout@v4
with:
repository: ${{ github.event.pull_request.head.repo.full_name }}
ref: ${{ github.event.pull_request.head.ref }}
fetch-depth: 0
token: ${{ secrets.OVVO_SYNC_TOKEN || github.token }}
- name: Restore workflow baseline from default branch
shell: bash
env:
BASE_REF: ${{ github.event.repository.default_branch }}
HEAD_REF: ${{ github.event.pull_request.head.ref }}
run: |
set -euo pipefail
git fetch origin \
"${BASE_REF}:refs/remotes/origin/${BASE_REF}" \
--force
protected_workflows=(
".github/workflows/workflow-baseline.yml"
".github/workflows/native-backend-ci.yml"
".github/workflows/inspect-r-api-update.yml"
".github/workflows/docs.yml"
".github/workflows/release.yml"
)
mkdir -p .github/workflows
for path in "${protected_workflows[@]}"; do
git show "origin/${BASE_REF}:${path}" > "${path}"
done
while IFS= read -r -d '' path; do
case "${path}" in
".github/workflows/workflow-baseline.yml"|\
".github/workflows/native-backend-ci.yml"|\
".github/workflows/inspect-r-api-update.yml"|\
".github/workflows/docs.yml"|\
".github/workflows/release.yml")
;;
*)
echo "Removing non-baseline workflow: ${path}"
rm -f "${path}"
;;
esac
done < <(
find .github/workflows \
-maxdepth 1 \
-type f \
\( -name '*.yml' -o -name '*.yaml' \) \
-print0
)
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add -A .github/workflows
if git diff --cached --quiet; then
echo "Workflow files already match the canonical baseline."
exit 0
fi
git commit -m "Restore protected workflow baseline"
git push origin "HEAD:${HEAD_REF}"
- name: Record enforcement result
if: always()
shell: bash
run: |
{
echo "## Workflow baseline enforcement"
echo
echo "The default branch is the source of truth for GitHub Actions."
echo "Normal fix PRs cannot add, delete, or modify workflow YAML."
echo
echo "Apply the \`workflow-change-approved\` label only for an intentional workflow change."
} >> "${GITHUB_STEP_SUMMARY}"