From: Patrick Donnelly Date: Thu, 30 Jul 2026 00:18:57 +0000 (-0400) Subject: .github/workflows: switch to pull_request_target trigger X-Git-Url: http://git-server-git.apps.pok.os.sepia.ceph.com/?a=commitdiff_plain;h=9336dcba488298e6fa3ed32f0fbde6be2c3d17cf;p=ceph.git .github/workflows: switch to pull_request_target trigger Switch the trigger from `pull_request` to `pull_request_target` so that the workflow definition on `main` is evaluated for PRs targeting active release branches (main, umbrella, tentacle, squid). This allows the check to run cleanly across release branches without requiring workflow file backports to each branch. Additionally: - Update `src/script/verify-qa` to accept an optional target directory argument ($1). - Run the trusted `verify-qa` script from `main` against the checked-out PR directory (`./pull_request`). The concern of exfiltrating secrets is important but not relevant here: we're not using the secrets in the definition and we explicitly downgrade the github token to `read` permission. Signed-off-by: Patrick Donnelly --- diff --git a/.github/workflows/qa-symlink.yml b/.github/workflows/qa-symlink.yml index dda2265162d8..cafc3c85eb97 100644 --- a/.github/workflows/qa-symlink.yml +++ b/.github/workflows/qa-symlink.yml @@ -1,8 +1,7 @@ --- name: "Check for missing .qa links" on: - pull_request: - # Run CI check only for branches which are active and a target for a PR + pull_request_target: branches: - main - umbrella @@ -11,7 +10,6 @@ on: types: - opened - synchronize - - edited - reopened permissions: contents: read @@ -36,6 +34,6 @@ jobs: ref: ${{ github.event.pull_request.head.sha }} path: pull_request - - name: verify .qa links - run: ../main/src/script/verify-qa - working-directory: pull_request/ + - name: Run verification script + run: | + ./main/src/script/verify-qa ./pull_request diff --git a/src/script/verify-qa b/src/script/verify-qa index 53e796e33d62..39ca53508977 100755 --- a/src/script/verify-qa +++ b/src/script/verify-qa @@ -1,5 +1,11 @@ #!/bin/bash +set -e + +if [[ -n "$1" ]]; then + cd "$1" +fi + printf 'Commit is:\n' >&2 git log -1 >&2