N4 cross-project probe #32861
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Confirm internal staff meant to post in public | |
| # Asks GitHub staff to confirm public issues and PRs belong in github/docs. | |
| on: | |
| issues: | |
| types: | |
| - opened | |
| - transferred | |
| # pull_request_target lets the workflow check org membership for forked PR authors. | |
| pull_request_target: | |
| types: | |
| - opened | |
| permissions: | |
| contents: read | |
| jobs: | |
| check-team-membership: | |
| runs-on: ubuntu-latest | |
| continue-on-error: true | |
| if: github.repository == 'github/docs' && github.actor != 'docs-bot' | |
| steps: | |
| - id: membership_check | |
| uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 | |
| env: | |
| TEAM_CONTENT_REPO: ${{ secrets.TEAM_CONTENT_REPO }} | |
| with: | |
| github-token: ${{ secrets.DOCS_BOT_PAT_BASE }} | |
| script: | | |
| // Only GitHub employees need confirmation before public posts stay public. | |
| try { | |
| await github.rest.teams.getMembershipForUserInOrg({ | |
| org: 'github', | |
| team_slug: 'employees', | |
| username: context.payload.sender.login, | |
| }); | |
| } catch(err) { | |
| // The employee membership lookup throws for non-employees, so skip confirmation. | |
| return | |
| } | |
| // Docs team members can intentionally work in github/docs. | |
| try { | |
| // 9919 is the github org and 325922 the docs team; numeric IDs survive renames. | |
| await github.request('GET /organizations/{org_id}/team/{team_id}/memberships/{username}', { | |
| org_id: 9919, | |
| team_id: 325922, | |
| username: context.payload.sender.login, | |
| }); | |
| return | |
| } catch(err) { | |
| // The docs team membership lookup throws for non-members, who need an internal confirmation issue. | |
| } | |
| const issueNo = context.number || context.issue.number | |
| await github.rest.issues.create({ | |
| owner: 'github', | |
| repo: process.env.TEAM_CONTENT_REPO, | |
| title: `@${context.payload.sender.login} confirm that \#${issueNo} should be in the public github/docs repo`, | |
| body: `@${context.payload.sender.login} opened https://github.com/github/docs/issues/${issueNo} publicly in the github/docs repo, instead of the private github/${process.env.TEAM_CONTENT_REPO} repo.\n\n@${context.payload.sender.login}, please confirm that this belongs in the public repo and that no sensitive information was disclosed by commenting below and closing the issue.\n\nIf this was not intentional and sensitive information was shared, please delete https://github.com/github/docs/issues/${issueNo} and notify us in the \#docs-open-source channel.\n\nThanks!`, | |
| labels: ['OS confirmation', 'skip FR board'], | |
| }); | |
| core.setOutput('did_warn', 'true') | |
| - name: Send Slack notification if a GitHub employee who isn't on the Technical Content team opens an issue in public | |
| if: ${{ steps.membership_check.outputs.did_warn && github.repository == 'github/docs' }} | |
| uses: slackapi/slack-github-action@dcb1066f776dd043e64d0e8ba94ca15cc7e1875d # v4.0.0 | |
| env: | |
| SLACK_MESSAGE: <@${{ github.actor }}> opened https://github.com/github/docs/issues/${{ github.event.number || github.event.issue.number }} publicly on the github/docs repo instead of a private repo. They have been notified via a new issue in the private repo to confirm this was intentional. | |
| SLACK_CHANNEL_ID: ${{ secrets.DOCS_OPEN_SOURCE_SLACK_CHANNEL_ID }} | |
| with: | |
| method: chat.postMessage | |
| token: ${{ secrets.SLACK_DOCS_BOT_TOKEN }} | |
| errors: true | |
| payload: | | |
| channel: ${{ toJSON(env.SLACK_CHANNEL_ID) }} | |
| text: ${{ toJSON(env.SLACK_MESSAGE) }} | |
| - name: Check out repo | |
| if: ${{ failure() && github.event_name != 'pull_request_target' }} | |
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - uses: ./.github/actions/slack-alert | |
| if: ${{ failure() && github.event_name != 'pull_request_target' }} | |
| with: | |
| slack_token: ${{ secrets.SLACK_DOCS_BOT_TOKEN }} |