Skip to content

Update ip-allow-lists-which-resources-are-protected.md #16369

Update ip-allow-lists-which-resources-are-protected.md

Update ip-allow-lists-which-resources-are-protected.md #16369

name: Close bad repo-sync PRs

Check warning on line 1 in .github/workflows/close-bad-repo-sync-prs.yml

View workflow run for this annotation

GitHub Actions / Close bad repo-sync PRs

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
# Closes public PRs from the repo-sync source branch unless the event actor is a GitHub employee.
on:
# pull_request_target lets the workflow close forked PRs from the repo-sync source branch.
pull_request_target:
permissions:
contents: write
pull-requests: write
jobs:
close-invalid-repo-sync-pr:
if: ${{ github.repository == 'github/docs' && github.event.pull_request.base.ref == 'main' && github.event.pull_request.head.ref == 'repo-sync' }}
name: Close if invalid repo-sync PR author
runs-on: ubuntu-latest
steps:
- name: Close pull request if unwanted
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3
with:
github-token: ${{ secrets.DOCS_BOT_PAT_BASE }}
script: |
const { owner, repo } = context.repo
const prCreator = context.actor
const prNumber = context.issue.number
try {
await github.rest.teams.getMembershipForUserInOrg({
org: 'github',
team_slug: 'employees',
username: prCreator
})
// Skip GitHub employees because the event actor may own legitimate repo-sync work.
console.log("PR creator is a GitHub employee")
return
} catch (err) {
// The membership lookup throws for non-employees, so fall through and close the PR.
}
await github.rest.issues.update({
owner,
repo,
issue_number: prNumber,
labels: ['invalid'],
state: 'closed'
})
await github.rest.issues.createComment({
owner,
repo,
issue_number: prNumber,
body: "Please leave this `repo-sync` branch to the robots!\n\nI'm going to close this pull request now, but feel free to open a new issue in the repository!"
})