Skip to content

chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 #19

chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0

chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 #19

Workflow file for this run

# Runs the e2e tests on fork PRs after a maintainer adds the "safe-to-test" label.
# This uses pull_request_target so repository secrets are available (fork PRs cannot
# access secrets via the regular pull_request trigger). The label gate ensures untrusted
# code is reviewed before it runs with access to secrets.
#
# Security: Only the "labeled" event triggers this workflow. New pushes to the fork do NOT
# re-trigger tests — see remove-safe-to-test-label.yml which strips the label on new commits,
# forcing a maintainer to re-review and re-label.
#
# Scope: only the e2e job lives here. It is irreducibly privileged — it exists to run the
# fork's own action code against the LaunchDarkly API, so it needs both the untrusted
# checkout and LD_ACCESS_TOKEN_WRITER. Unit tests need no secrets and therefore run under
# the unprivileged `pull_request` trigger in main.yml instead of here.
name: "Test (Fork PRs)"
on:
pull_request_target:
types: [labeled]
permissions:
contents: read
jobs:
e2e-tests:
if: >-
github.event.label.name == 'safe-to-test'
&& github.event.pull_request.head.repo.full_name != github.repository
runs-on: ubuntu-latest
permissions:
pull-requests: write
contents: read
steps:
- name: Checkout
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8
with:
ref: ${{ github.event.pull_request.head.sha }}
# Untrusted fork code runs in this job. Keep the workflow token out of
# .git/config so poisoned code cannot reuse it.
persist-credentials: false
- name: Find LaunchDarkly feature flags in diff
uses: ./ # Uses an action in the root directory
id: find-flags
with:
project-key: developer-toolbar-sandbox
environment-key: test
access-token: ${{ secrets.LD_ACCESS_TOKEN_WRITER }}
repo-token: ${{ secrets.GITHUB_TOKEN }}
base-uri: https://app.launchdarkly.com
max-flags: 200
create-flag-links: true
- name: Find flags summary
run: |
echo "flags addded or modified ${{ steps.find-flags.outputs.modified-flags-count }}"
echo "flags removed ${{ steps.find-flags.outputs.removed-flags-count }}"
- name: Added or modified flags
if: steps.find-flags.outputs.any-modified == 'true'
run: |
for flag in ${{ steps.find-flags.outputs.modified-flags }}; do
echo "$flag was added or modified"
done
- name: Removed flags
if: steps.find-flags.outputs.any-removed == 'true'
run: |
for flag in ${{ steps.find-flags.outputs.removed-flags }}; do
echo "$flag was removed"
done
- name: Add label
if: ${{ steps.find-flags.outputs.any-changed == 'true' && github.actor != 'dependabot[bot]' }}
run: gh pr edit $PR_NUMBER --add-label ld-flags
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_NUMBER: ${{ github.event.pull_request.number }}
- name: Remove label
if: ${{ steps.find-flags.outputs.any-changed == 'false' && github.actor != 'dependabot[bot]' }}
run: gh pr edit $PR_NUMBER --remove-label ld-flags
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_NUMBER: ${{ github.event.pull_request.number }}
check-success:
name: "Check Success (Fork)"
needs:
- e2e-tests
if: always()
runs-on: ubuntu-latest
steps:
- name: Evaluate results
run: |
if printf '${{ toJSON(needs) }}' | grep --quiet --extended-regexp --ignore-case '"result": "(failure|cancelled)"'; then
printf "Tests failed or workflow cancelled:\n\n${{ toJSON(needs) }}"
exit 1
fi