Skip to content

The app's examples, as community projects #7

The app's examples, as community projects

The app's examples, as community projects #7

Workflow file for this run

name: Check

Check warning on line 1 in .github/workflows/check.yml

View workflow run for this annotation

GitHub Actions / Check

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
# pull_request_target, so the workflow and community.py are the base branch's: a pull request
# cannot change what checks it. Its files are only read, never run, and the token can only read.
on:
pull_request_target:
types: [opened, synchronize, reopened]
permissions:
contents: read
pull-requests: read # its list of files
jobs:
check:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v4
with:
repository: ${{ github.event.pull_request.head.repo.full_name }}
ref: ${{ github.event.pull_request.head.sha }}
path: pr
persist-credentials: false
- uses: astral-sh/setup-uv@v6
# The `sp` that checks a package is the app's. SP_REF, a repository variable, pins another
# branch or tag of it; without one it is main's.
- run: uv tool install "super-prototyping-tools @ git+https://github.com/ReScienceLab/super-prototyping@${SP_REF}#subdirectory=tools"
env:
SP_REF: ${{ vars.SP_REF || 'main' }}
- run: python3 .github/community.py check pr "$OPENER" "$OPENER_ID"
env:
OPENER: ${{ github.event.pull_request.user.login }}
OPENER_ID: ${{ github.event.pull_request.user.id }}
PR: ${{ github.event.pull_request.number }}
CHANGED_FILES: ${{ github.event.pull_request.changed_files }}
GH_TOKEN: ${{ github.token }}