chore(main): release patchloom 0.8.0 #144
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Post-merge CI trigger | |
| on: | |
| pull_request: | |
| types: [closed] | |
| workflow_dispatch: | |
| permissions: {} | |
| concurrency: | |
| group: post-merge-${{ github.event.pull_request.number || github.run_id }} | |
| cancel-in-progress: true | |
| jobs: | |
| trigger: | |
| name: Trigger CI on main | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| if: github.event.pull_request.merged == true | |
| permissions: | |
| actions: write | |
| contents: write | |
| steps: | |
| - name: Harden runner | |
| uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1 | |
| with: | |
| egress-policy: audit | |
| # Recipe A: do not dispatch ci.yml or security.yml on a green squash. | |
| # The feature PR (or merge_group) already ran those. A second matrix | |
| # is waste. Scorecard wants a default-branch run; keep that dispatch. | |
| # Do not set require-up-to-date to justify dropping this file (#156). | |
| - name: Trigger Scorecard on main | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| gh workflow run scorecard.yml --ref main --repo "${{ github.repository }}" | |
| - name: Auto-update open PR branches | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| gh pr list --base main --state open --json number --jq '.[].number' \ | |
| --repo "${{ github.repository }}" | while read -r pr; do | |
| echo "Updating PR #$pr" | |
| gh pr update-branch "$pr" --repo "${{ github.repository }}" || true | |
| done |