You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: .github/ACTIONS.md
+2-12Lines changed: 2 additions & 12 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -31,15 +31,8 @@ Currently, we have both GitHub-hosted and self-hosted runners for running the Gi
31
31
* Ubuntu 24.04 self-hosted runner: `[self-hosted, ubuntu-24.04, main]` (also `small`, `highmem`, or `highmem22` pool labels as needed)
32
32
* Windows Server 2019 self-hosted runner: `[self-hosted, windows-server-2019]`
33
33
* MacOS GitHub-hosted runner: `macos-latest`
34
-
* Every workflow that tests the source code, needs to have the workflow trigger`pull_request_target` instead of`pull_request`.
34
+
* Every workflow that tests the source code needs to have the workflow trigger `pull_request`.
35
35
* The workflow must have set read permissions for all the available scopes and jobs: `permissions: read-all`. It must be set at the top of the `jobs` directive.
36
-
* For those workflows that have the `pull_request_target` trigger, in the checkout step must be added a ref to `${{ github.event.pull_request.head.sha }}`
37
-
```yaml
38
-
- name: Checkout code
39
-
uses: actions/checkout@v#
40
-
with:
41
-
ref: ${{ github.event.pull_request.head.sha }}
42
-
```
43
36
* If your workflow runs successfully in a GitHub-hosted runner but not in the self-hosted runner, it might need a new installation step.
44
37
```yaml
45
38
- name: Setup Node
@@ -55,7 +48,7 @@ Currently, we have both GitHub-hosted and self-hosted runners for running the Gi
55
48
```yaml
56
49
name: GitHub Actions Example
57
50
on:
58
-
pull_request_target:
51
+
pull_request:
59
52
branches: ['master']
60
53
permissions: read-all
61
54
jobs:
@@ -64,8 +57,6 @@ jobs:
64
57
steps:
65
58
- name: Check out repository code
66
59
uses: actions/checkout@v2
67
-
with:
68
-
ref: ${{ github.event.pull_request.head.sha }}
69
60
- run: echo "This job is now running on a ubuntu server hosted by Apache Beam!"
70
61
- name: Setup Node
71
62
uses: actions/setup-node@v3
@@ -85,7 +76,6 @@ jobs:
85
76
* A **detailed review** for changes in the workflows is needed due to important **security concerns**.
86
77
* **DO NOT** Approve and Run changes in the workflows in the PR Conversation tab, under "Workflow(s) awaiting approval".
87
78
* For approving the updates in the workflows, you should go to the Repository Actions and filter All Workflows by `action_required`. The search will display the workflows that need to be reviewed before running. **Please make sure reviewing the file that is referenced by the workflow.**
88
-
* Seed job will be emulated using the `Approve and Run` built-in feature of GitHub Actions, since the workflows will use the `pull_request_target` directive; no modifications would be allowed either for new or existent jobs unless a committer explicitly approves the job from GitHub Actions UI.
89
79
90
80
#### Issue Management
91
81
Phrases self-assign, close, or manage labels on an issue:
Copy file name to clipboardExpand all lines: .github/workflows/README.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -44,7 +44,7 @@ If you would like to manually trigger a job, you have 2 options:
44
44
45
45
1) Trigger Phrases: Some jobs have trigger phrases associated with them (e.g. `Run XYZ PreCommit`). These will appear in statuses of previous PR runs of that check. You can trigger the job on any PR by commenting that trigger phrase in the PR.
46
46
47
-
**Note:** this approach is found not scalable ([#28909](https://github.com/apache/beam/issues/28909)) and currently only enabled for PreCommit workflows. For PostCommit jobs, it is currently replaced by a temporary approach: test suites are configured to trigger whenever a particular trigger file is modified. Test [workflows](https://github.com/apache/beam/tree/master/.github/workflows) have [pull_request_target paths](https://github.com/apache/beam/blob/e33dec69c7cfd01c0b827538e1dad8567e3ff95e/.github/workflows/beam_PreCommit_Whitespace.yml#L25), which include a trigger file. Whenever a trigger file is modified, the test suite will trigger on the pull request. Make any change to this file to trigger the job. The trigger file looks like the following: `.github/trigger_files/<workflow_file_name.json>`.
47
+
**Note:** this approach is found not scalable ([#28909](https://github.com/apache/beam/issues/28909)) and currently only enabled for PreCommit workflows. For PostCommit jobs, it is currently replaced by a temporary approach: test suites are configured to trigger whenever a particular trigger file is modified. Test [workflows](https://github.com/apache/beam/tree/master/.github/workflows) have [pull_request paths](https://github.com/apache/beam/blob/e33dec69c7cfd01c0b827538e1dad8567e3ff95e/.github/workflows/beam_PreCommit_Whitespace.yml#L25), which include a trigger file. Whenever a trigger file is modified, the test suite will trigger on the pull request. Make any change to this file to trigger the job. The trigger file looks like the following: `.github/trigger_files/<workflow_file_name.json>`.
48
48
49
49
2)**Committers only** - Manual triggering: Any committer can start any job with a [workflow_dispatch](https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#workflow_dispatch) trigger defined (all jobs should have these). To do so, navigate to the [Actions tab](https://github.com/apache/beam/actions), click on your desired workflow in the left navigation bar, and then click `Run Workflow`.
@@ -124,16 +124,16 @@ GitHub allows workflows to define a set of triggers that dictate when a job shou
124
124
For the purposes of Beam, each CI workflow should define the following triggers:
125
125
126
126
1) A `push` trigger
127
-
2) A `pull_request_target` trigger
127
+
2) A `pull_request` trigger
128
128
3) An issue_comment trigger (for issue created). This is needed for comment triggering support (see section below).
129
129
4) A scheduled trigger
130
130
5) A workflow_dispatch trigger
131
131
132
-
The `push`/`pull_request_target` triggers should only run when appropriate paths are modified. See https://github.com/apache/beam/blob/master/.github/workflows/beam_PreCommit_Go.yml#L4 for an example (you can copy and paste this into your workflow, you just need to change the paths).
132
+
The `push`/`pull_request` triggers should only run when appropriate paths are modified. See https://github.com/apache/beam/blob/master/.github/workflows/beam_PreCommit_Go.yml#L4 for an example (you can copy and paste this into your workflow, you just need to change the paths).
133
133
134
134
## Checkout step
135
135
136
-
Because we use the `pull_request_target` trigger instead of `pull_request`, we need an explicit checkout of the correct commit. This can be done as a step that uses the `setup-action` action in your workflow. See https://github.com/apache/beam/blob/0ee2dc73ec6f555a5bf1a643dffd37f4927be67e/.github/workflows/beam_PreCommit_Go.yml#L65-L70 for an example (you can copy and paste this into your workflow). Please make sure that you checkout the code before using the composite action.
136
+
For comment triggering support, we need an explicit checkout of the correct commit. This can be done as a step that uses the `setup-action` action in your workflow. See https://github.com/apache/beam/blob/0ee2dc73ec6f555a5bf1a643dffd37f4927be67e/.github/workflows/beam_PreCommit_Go.yml#L65-L70 for an example (you can copy and paste this into your workflow). Please make sure that you checkout the code before using the composite action.
0 commit comments