Skip to content

fix(reflect): use framed summaries for reliable condensation #136

fix(reflect): use framed summaries for reliable condensation

fix(reflect): use framed summaries for reliable condensation #136

Workflow file for this run

name: Update contributors

Check warning on line 1 in .github/workflows/contributors.yml

View workflow run for this annotation

GitHub Actions / Update contributors

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
# Anyone with a merged pull request is a contributor, and this keeps the list
# honest without anyone having to remember. It regenerates from the merged PRs
# themselves rather than from commit metadata, because GitHub's own contributors
# graph keys on the commit author email and silently drops anyone whose git
# email is not attached to their GitHub account.
#
# main requires status checks, so a push from Actions is rejected (GH006). A
# changed list goes to the bot/contributors branch and one pull request, which
# later runs refresh in place. Pull requests opened by Actions do not trigger
# other workflows, so the required checks never report on it: a maintainer
# reviews the diff and merges it as admin.
on:
pull_request_target:
types: [closed]
branches: [main]
schedule:
- cron: '23 5 * * 1'
workflow_dispatch:
permissions:
contents: write
pull-requests: write
concurrency:
group: contributors
cancel-in-progress: false
jobs:
update:
# Only when something actually merged.
if: github.event_name != 'pull_request_target' || github.event.pull_request.merged == true
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
with:
ref: main
- uses: actions/setup-node@v4
with:
node-version: 20
- name: Regenerate CONTRIBUTORS.md
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: node scripts/generate-contributors.mjs
- name: Open or refresh the contributors pull request
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
BRANCH: bot/contributors
run: |
set -euo pipefail
if git diff --quiet -- CONTRIBUTORS.md; then
echo "CONTRIBUTORS.md on main is current."
exit 0
fi
# Nothing to push when the branch already carries this exact list.
if git fetch --quiet --depth 1 origin "$BRANCH" 2>/dev/null \
&& git diff --quiet FETCH_HEAD -- CONTRIBUTORS.md; then
echo "$BRANCH already has this list."
else
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git checkout -B "$BRANCH"
git add CONTRIBUTORS.md
git commit -m "docs: update contributors"
git push --force origin "$BRANCH"
fi
if [ -n "$(gh pr list --head "$BRANCH" --state open --json number --jq '.[0].number // empty')" ]; then
echo "The pull request on $BRANCH is open and current."
exit 0
fi
gh pr create --base main --head "$BRANCH" \
--title "docs: update contributors" \
--label no-visual-change \
--body "Regenerated by the Update contributors workflow from merged pull requests. Pull requests opened by GitHub Actions do not trigger other workflows, so the required checks will not report here. Review the diff, then merge as admin."