Repository navigation
chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 #19
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Runs the e2e tests on fork PRs after a maintainer adds the "safe-to-test" label. | |
| # This uses pull_request_target so repository secrets are available (fork PRs cannot | |
| # access secrets via the regular pull_request trigger). The label gate ensures untrusted | |
| # code is reviewed before it runs with access to secrets. | |
| # | |
| # Security: Only the "labeled" event triggers this workflow. New pushes to the fork do NOT | |
| # re-trigger tests — see remove-safe-to-test-label.yml which strips the label on new commits, | |
| # forcing a maintainer to re-review and re-label. | |
| # | |
| # Scope: only the e2e job lives here. It is irreducibly privileged — it exists to run the | |
| # fork's own action code against the LaunchDarkly API, so it needs both the untrusted | |
| # checkout and LD_ACCESS_TOKEN_WRITER. Unit tests need no secrets and therefore run under | |
| # the unprivileged `pull_request` trigger in main.yml instead of here. | |
| name: "Test (Fork PRs)" | |
| on: | |
| pull_request_target: | |
| types: [labeled] | |
| permissions: | |
| contents: read | |
| jobs: | |
| e2e-tests: | |
| if: >- | |
| github.event.label.name == 'safe-to-test' | |
| && github.event.pull_request.head.repo.full_name != github.repository | |
| runs-on: ubuntu-latest | |
| permissions: | |
| pull-requests: write | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 | |
| with: | |
| ref: ${{ github.event.pull_request.head.sha }} | |
| # Untrusted fork code runs in this job. Keep the workflow token out of | |
| # .git/config so poisoned code cannot reuse it. | |
| persist-credentials: false | |
| - name: Find LaunchDarkly feature flags in diff | |
| uses: ./ # Uses an action in the root directory | |
| id: find-flags | |
| with: | |
| project-key: developer-toolbar-sandbox | |
| environment-key: test | |
| access-token: ${{ secrets.LD_ACCESS_TOKEN_WRITER }} | |
| repo-token: ${{ secrets.GITHUB_TOKEN }} | |
| base-uri: https://app.launchdarkly.com | |
| max-flags: 200 | |
| create-flag-links: true | |
| - name: Find flags summary | |
| run: | | |
| echo "flags addded or modified ${{ steps.find-flags.outputs.modified-flags-count }}" | |
| echo "flags removed ${{ steps.find-flags.outputs.removed-flags-count }}" | |
| - name: Added or modified flags | |
| if: steps.find-flags.outputs.any-modified == 'true' | |
| run: | | |
| for flag in ${{ steps.find-flags.outputs.modified-flags }}; do | |
| echo "$flag was added or modified" | |
| done | |
| - name: Removed flags | |
| if: steps.find-flags.outputs.any-removed == 'true' | |
| run: | | |
| for flag in ${{ steps.find-flags.outputs.removed-flags }}; do | |
| echo "$flag was removed" | |
| done | |
| - name: Add label | |
| if: ${{ steps.find-flags.outputs.any-changed == 'true' && github.actor != 'dependabot[bot]' }} | |
| run: gh pr edit $PR_NUMBER --add-label ld-flags | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| PR_NUMBER: ${{ github.event.pull_request.number }} | |
| - name: Remove label | |
| if: ${{ steps.find-flags.outputs.any-changed == 'false' && github.actor != 'dependabot[bot]' }} | |
| run: gh pr edit $PR_NUMBER --remove-label ld-flags | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| PR_NUMBER: ${{ github.event.pull_request.number }} | |
| check-success: | |
| name: "Check Success (Fork)" | |
| needs: | |
| - e2e-tests | |
| if: always() | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Evaluate results | |
| run: | | |
| if printf '${{ toJSON(needs) }}' | grep --quiet --extended-regexp --ignore-case '"result": "(failure|cancelled)"'; then | |
| printf "Tests failed or workflow cancelled:\n\n${{ toJSON(needs) }}" | |
| exit 1 | |
| fi |