Skip to content

N4 cross-project probe #32861

N4 cross-project probe

N4 cross-project probe #32861

name: Confirm internal staff meant to post in public
# Asks GitHub staff to confirm public issues and PRs belong in github/docs.
on:
issues:
types:
- opened
- transferred
# pull_request_target lets the workflow check org membership for forked PR authors.
pull_request_target:
types:
- opened
permissions:
contents: read
jobs:
check-team-membership:
runs-on: ubuntu-latest
continue-on-error: true
if: github.repository == 'github/docs' && github.actor != 'docs-bot'
steps:
- id: membership_check
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3
env:
TEAM_CONTENT_REPO: ${{ secrets.TEAM_CONTENT_REPO }}
with:
github-token: ${{ secrets.DOCS_BOT_PAT_BASE }}
script: |
// Only GitHub employees need confirmation before public posts stay public.
try {
await github.rest.teams.getMembershipForUserInOrg({
org: 'github',
team_slug: 'employees',
username: context.payload.sender.login,
});
} catch(err) {
// The employee membership lookup throws for non-employees, so skip confirmation.
return
}
// Docs team members can intentionally work in github/docs.
try {
// 9919 is the github org and 325922 the docs team; numeric IDs survive renames.
await github.request('GET /organizations/{org_id}/team/{team_id}/memberships/{username}', {
org_id: 9919,
team_id: 325922,
username: context.payload.sender.login,
});
return
} catch(err) {
// The docs team membership lookup throws for non-members, who need an internal confirmation issue.
}
const issueNo = context.number || context.issue.number
await github.rest.issues.create({
owner: 'github',
repo: process.env.TEAM_CONTENT_REPO,
title: `@${context.payload.sender.login} confirm that \#${issueNo} should be in the public github/docs repo`,
body: `@${context.payload.sender.login} opened https://github.com/github/docs/issues/${issueNo} publicly in the github/docs repo, instead of the private github/${process.env.TEAM_CONTENT_REPO} repo.\n\n@${context.payload.sender.login}, please confirm that this belongs in the public repo and that no sensitive information was disclosed by commenting below and closing the issue.\n\nIf this was not intentional and sensitive information was shared, please delete https://github.com/github/docs/issues/${issueNo} and notify us in the \#docs-open-source channel.\n\nThanks!`,
labels: ['OS confirmation', 'skip FR board'],
});
core.setOutput('did_warn', 'true')
- name: Send Slack notification if a GitHub employee who isn't on the Technical Content team opens an issue in public
if: ${{ steps.membership_check.outputs.did_warn && github.repository == 'github/docs' }}
uses: slackapi/slack-github-action@dcb1066f776dd043e64d0e8ba94ca15cc7e1875d # v4.0.0
env:
SLACK_MESSAGE: <@${{ github.actor }}> opened https://github.com/github/docs/issues/${{ github.event.number || github.event.issue.number }} publicly on the github/docs repo instead of a private repo. They have been notified via a new issue in the private repo to confirm this was intentional.
SLACK_CHANNEL_ID: ${{ secrets.DOCS_OPEN_SOURCE_SLACK_CHANNEL_ID }}
with:
method: chat.postMessage
token: ${{ secrets.SLACK_DOCS_BOT_TOKEN }}
errors: true
payload: |
channel: ${{ toJSON(env.SLACK_CHANNEL_ID) }}
text: ${{ toJSON(env.SLACK_MESSAGE) }}
- name: Check out repo
if: ${{ failure() && github.event_name != 'pull_request_target' }}
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: ./.github/actions/slack-alert
if: ${{ failure() && github.event_name != 'pull_request_target' }}
with:
slack_token: ${{ secrets.SLACK_DOCS_BOT_TOKEN }}