Skip to content

sync with open source how #5732

sync with open source how

sync with open source how #5732

# Licensed to the Apache Software Foundation (ASF) under one or more

Check warning on line 1 in .github/workflows/pr-bot-pr-updates.yml

View workflow run for this annotation

GitHub Actions / pr-bot-pr-updates

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
# contributor license agreements. See the NOTICE file distributed with
# this work for additional information regarding copyright ownership.
# The ASF licenses this file to You under the Apache License, Version 2.0
# (the "License"); you may not use this file except in compliance with
# the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
name: pr-bot-pr-updates
on:
pull_request_target:
types: ["synchronize", "converted_to_draft", "ready_for_review"]
issue_comment:
types: [created]
permissions: read-all
concurrency:
group: pr-bot-labels-${{ github.event.pull_request.number || github.event.issue.number }}
cancel-in-progress: false
jobs:
process-pr-update:
# Give GITHUB_TOKEN permissions to write pull request comments and to the state branch, and read PR related info
permissions:
contents: write
pull-requests: write
checks: read
issues: read
statuses: read
# Don't run on forks or non-PR issue comments
if: github.repository == 'apache/beam' && (github.event_name != 'issue_comment' || github.event.issue.pull_request)
runs-on: ubuntu-latest
steps:
# Pin to master so users can't do anything malicious on their own branch and run it here.
- uses: actions/checkout@v7
with:
ref: 'master'
persist-credentials: true
- name: Setup Node
uses: actions/setup-node@v7
with:
node-version: 16
- name: Install pr-bot npm dependencies
run: npm ci
working-directory: 'scripts/ci/pr-bot'
# Runs a set of commands using the runners shell
- run: npm run processPrUpdate
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
working-directory: 'scripts/ci/pr-bot'