diff --git a/.github/workflows/approvals.yml b/.github/workflows/approvals.yml deleted file mode 100644 index 5cbfbceeedb..00000000000 --- a/.github/workflows/approvals.yml +++ /dev/null @@ -1,49 +0,0 @@ -name: PR Approval Check - -on: - pull_request: - branches: - - "develop" - -jobs: - check-approvals: - runs-on: ubuntu-latest - timeout-minutes: 10 - steps: - - name: Check required approvals - uses: actions/github-script@450193c5abd4cdb17ba9f3ffcfe8f635c4bb6c2a - with: - script: | - const pr = context.payload.pull_request; - const reviews = await github.rest.pulls.listReviews({ - owner: context.repo.owner, - repo: context.repo.repo, - pull_number: pr.number, - }); - - // Determine if PR author is a bot/GitHub Actions - const authorType = pr.user.type; // 'Bot' vs 'User' - const authorLogin = pr.user.login; // e.g. 'github-actions[bot]' - const isBot = authorType === 'Bot' || authorLogin.endsWith('[bot]'); - const oneApprovalBotAuthors = new Set(['renovate[bot]']); - - // Count unique approvals, including bot approvals. - const latestByUser = {}; - for (const review of reviews.data) { - latestByUser[review.user.login] = review.state; - } - const approvalCount = Object.values(latestByUser) - .filter(state => state === 'APPROVED').length; - - const required = isBot && !oneApprovalBotAuthors.has(authorLogin) ? 2 : 1; - - console.log(`PR author: ${authorLogin} (${authorType}), isBot: ${isBot}`); - console.log(`One-approval bot allowlist: ${oneApprovalBotAuthors.has(authorLogin)}`); - console.log(`Approvals: ${approvalCount} / ${required} required`); - - if (isBot && (approvalCount < required)) { - core.setFailed( - `This PR needs ${required} approval(s) but has ${approvalCount}. ` + - `(Author is ${isBot ? 'a bot' : 'human'})` - ); - } diff --git a/.github/workflows/rerun-approvals.yml b/.github/workflows/rerun-approvals.yml deleted file mode 100644 index 4ec40aea4d4..00000000000 --- a/.github/workflows/rerun-approvals.yml +++ /dev/null @@ -1,40 +0,0 @@ -# Re-runs the PR Approval Check workflow when a review is submitted or dismissed. -# Re-running creates a new attempt on the existing approvals.yml workflow run, which -# updates the `check-approvals` check_run in place. This avoids the gate getting stuck -# behind a stale failed check_run from the original `pull_request` event run. - -name: Re-run PR Approval Check on Review - -on: - pull_request_review: - types: [submitted, dismissed] - -permissions: - actions: write - -concurrency: - group: rerun-approvals-${{ github.event.pull_request.head.sha }} - cancel-in-progress: true - -jobs: - rerun: - if: github.event.pull_request.base.ref == 'develop' - runs-on: ubuntu-latest - timeout-minutes: 5 - steps: - - name: Re-run approvals workflow for this PR's head SHA - env: - GH_TOKEN: ${{ github.token }} - REPO: ${{ github.repository }} - HEAD_SHA: ${{ github.event.pull_request.head.sha }} - run: | - set -euo pipefail - run_id=$(gh api \ - "repos/$REPO/actions/workflows/approvals.yml/runs?head_sha=$HEAD_SHA" \ - --jq '.workflow_runs[0].id // empty') - if [ -z "$run_id" ]; then - echo "No approvals.yml run for $HEAD_SHA - nothing to re-run." - exit 0 - fi - echo "Re-running approvals.yml run $run_id" - gh api -X POST "repos/$REPO/actions/runs/$run_id/rerun"