# Approve Open Docket Promotion

- Object ID: `em:automation:sha256:b2ea18b24eb739f090e795b4adc15e8c57c716a2df903a9dd63bec115f9941c7`
- Kind: `automation`
- Repository path: [`.github/workflows/approve-open-docket-promotion.yml`](https://github.com/yoheinakajima/epistemedia/blob/f92846570180dfa4511263f8ba98ecd18f7772c9/.github/workflows/approve-open-docket-promotion.yml)
- Content digest: `023cb94e8dc9ae3d702f9432e9192775234aff938b802c1e9161fb281f1504c9`

**Also filed under:** [Agent Operations](https://epistemedia.org/topics/agent-operations/), [Human and Agent Interfaces](https://epistemedia.org/topics/public-interfaces/), [Releases and Reproducibility](https://epistemedia.org/topics/releases/)

## Source content

name: attest-open-docket-promotion

on:
  workflow_run:
    workflows: [validate]
    types: [completed]

permissions: {}

concurrency:
  group: attest-open-docket-${{ github.event.workflow_run.id }}
  cancel-in-progress: false

jobs:
  attest:
    if: >-
      github.event.workflow_run.conclusion == 'success' &&
      github.event.workflow_run.event == 'pull_request' &&
      github.event.workflow_run.pull_requests[0].number != null
    runs-on: ubuntu-latest
    permissions:
      contents: read
      pull-requests: read
    steps:
      - uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
        with:
          ref: ${{ github.event.repository.default_branch }}
          persist-credentials: false
      - name: Confirm exact accepted-base promotion shape
        env:
          GH_TOKEN: ${{ github.token }}
          PR_NUMBER: ${{ github.event.workflow_run.pull_requests[0].number }}
          REVIEWED_HEAD: ${{ github.event.workflow_run.head_sha }}
        shell: bash
        run: |
          set -euo pipefail
          actual_head="$(gh api "repos/${GITHUB_REPOSITORY}/pulls/${PR_NUMBER}" --jq .head.sha)"
          [[ "$actual_head" == "$REVIEWED_HEAD" ]]
          mapfile -t paths < <(gh api --paginate "repos/${GITHUB_REPOSITORY}/pulls/${PR_NUMBER}/files?per_page=100" --jq '.[].filename')
          [[ ${#paths[@]} -eq 5 ]]
          parent=""
          for path in "${paths[@]}"; do
            [[ "$path" =~ ^research/open-dockets/[^/]+/(controller-attestation\.json|intake\.json|proposal\.json|promotion-receipt\.json|review\.json)$ ]]
            current_parent="${path%/*}"
            if [[ -z "$parent" ]]; then
              parent="$current_parent"
            else
              [[ "$parent" == "$current_parent" ]]
            fi
          done
      - name: Create short-lived review-gate App token
        id: app-token
        uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
        with:
          app-id: ${{ vars.REVIEW_GATE_APP_ID }}
          private-key: ${{ secrets.REVIEW_GATE_APP_PRIVATE_KEY }}
          permission-checks: write
          permission-contents: read
          permission-pull-requests: read
      - name: Sign the exact promotion receipt head
        env:
          GH_TOKEN: ${{ steps.app-token.outputs.token }}
          REVIEWED_HEAD: ${{ github.event.workflow_run.head_sha }}
          PR_NUMBER: ${{ github.event.workflow_run.pull_requests[0].number }}
        shell: bash
        run: |
          set -euo pipefail
          gh api --method POST "repos/${GITHUB_REPOSITORY}/check-runs" \
            -f name='independent-review' \
            -f head_sha="$REVIEWED_HEAD" \
            -f status='completed' \
            -f conclusion='success' \
            -f 'output[title]=Accepted-base promotion receipt validated' \
            -f "output[summary]=Promotion PR #${PR_NUMBER} passed accepted-base validation at exact receipt head ${REVIEWED_HEAD}. The App did not review evidence, write contents, or merge."
