Skip to content

fix(kubernetes): recover BatchSandbox after same-pod failures #4689

fix(kubernetes): recover BatchSandbox after same-pod failures

fix(kubernetes): recover BatchSandbox after same-pod failures #4689

Workflow file for this run

name: Verify License Headers

Check warning on line 1 in .github/workflows/verify-license.yml

View workflow run for this annotation

GitHub Actions / Verify License Headers

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
# pull_request_target runs the workflow definition from the base branch, so
# fork PRs and first-time contributors trigger it without manual approval.
# Safety: only this trusted script from the base branch is executed. The PR
# tree is checked out into a separate directory and scanned as data; nothing
# from the PR is ever executed.
on:
pull_request_target:
types: [opened, reopened, synchronize]
branches: [main]
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
verify-license:
name: Verify license headers
runs-on: ubuntu-latest
steps:
- name: Checkout base branch (trusted verification script)
uses: actions/checkout@v6
- name: Checkout pull request tree (scanned as data, never executed)
uses: actions/checkout@v6
with:
ref: refs/pull/${{ github.event.pull_request.number }}/merge
path: pr
allow-unsafe-pr-checkout: true
- name: Run license verification
run: |
chmod +x scripts/verify-license.sh
./scripts/verify-license.sh pr