fix(kubernetes): recover BatchSandbox after same-pod failures #4689
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Verify License Headers | ||
|
Check warning on line 1 in .github/workflows/verify-license.yml
|
||
| # pull_request_target runs the workflow definition from the base branch, so | ||
| # fork PRs and first-time contributors trigger it without manual approval. | ||
| # Safety: only this trusted script from the base branch is executed. The PR | ||
| # tree is checked out into a separate directory and scanned as data; nothing | ||
| # from the PR is ever executed. | ||
| on: | ||
| pull_request_target: | ||
| types: [opened, reopened, synchronize] | ||
| branches: [main] | ||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | ||
| cancel-in-progress: true | ||
| permissions: | ||
| contents: read | ||
| jobs: | ||
| verify-license: | ||
| name: Verify license headers | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout base branch (trusted verification script) | ||
| uses: actions/checkout@v6 | ||
| - name: Checkout pull request tree (scanned as data, never executed) | ||
| uses: actions/checkout@v6 | ||
| with: | ||
| ref: refs/pull/${{ github.event.pull_request.number }}/merge | ||
| path: pr | ||
| allow-unsafe-pr-checkout: true | ||
| - name: Run license verification | ||
| run: | | ||
| chmod +x scripts/verify-license.sh | ||
| ./scripts/verify-license.sh pr | ||