Repository object · automation
Approve Open Docket Promotion
Accepted automation in the public catalog.
- Media type
application/yaml- Object ID
em:automation:sha256:b2ea18b24eb739f090e795b4adc15e8c57c716a2df903a9dd63bec115f9941c7- Content digest
023cb94e8dc9ae3d702f9432e9192775234aff938b802c1e9161fb281f1504c9
Source content
name: attest-open-docket-promotion
on:
workflow_run:
workflows: [validate]
types: [completed]
permissions: {}
concurrency:
group: attest-open-docket-${{ github.event.workflow_run.id }}
cancel-in-progress: false
jobs:
attest:
if: >-
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'pull_request' &&
github.event.workflow_run.pull_requests[0].number != null
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
with:
ref: ${{ github.event.repository.default_branch }}
persist-credentials: false
- name: Confirm exact accepted-base promotion shape
env:
GH_TOKEN: ${{ github.token }}
PR_NUMBER: ${{ github.event.workflow_run.pull_requests[0].number }}
REVIEWED_HEAD: ${{ github.event.workflow_run.head_sha }}
shell: bash
run: |
set -euo pipefail
actual_head="$(gh api "repos/${GITHUB_REPOSITORY}/pulls/${PR_NUMBER}" --jq .head.sha)"
[[ "$actual_head" == "$REVIEWED_HEAD" ]]
mapfile -t paths < <(gh api --paginate "repos/${GITHUB_REPOSITORY}/pulls/${PR_NUMBER}/files?per_page=100" --jq '.[].filename')
[[ ${#paths[@]} -eq 5 ]]
parent=""
for path in "${paths[@]}"; do
[[ "$path" =~ ^research/open-dockets/[^/]+/(controller-attestation\.json|intake\.json|proposal\.json|promotion-receipt\.json|review\.json)$ ]]
current_parent="${path%/*}"
if [[ -z "$parent" ]]; then
parent="$current_parent"
else
[[ "$parent" == "$current_parent" ]]
fi
done
- name: Create short-lived review-gate App token
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
app-id: ${{ vars.REVIEW_GATE_APP_ID }}
private-key: ${{ secrets.REVIEW_GATE_APP_PRIVATE_KEY }}
permission-checks: write
permission-contents: read
permission-pull-requests: read
- name: Sign the exact promotion receipt head
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
REVIEWED_HEAD: ${{ github.event.workflow_run.head_sha }}
PR_NUMBER: ${{ github.event.workflow_run.pull_requests[0].number }}
shell: bash
run: |
set -euo pipefail
gh api --method POST "repos/${GITHUB_REPOSITORY}/check-runs" \
-f name='independent-review' \
-f head_sha="$REVIEWED_HEAD" \
-f status='completed' \
-f conclusion='success' \
-f 'output[title]=Accepted-base promotion receipt validated' \
-f "output[summary]=Promotion PR #${PR_NUMBER} passed accepted-base validation at exact receipt head ${REVIEWED_HEAD}. The App did not review evidence, write contents, or merge."
Build receipt
Reproduce this projection
- Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d- Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf- Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9- Epistemic policy
commons-balanced-v0.1- Disclosure policy
public-noninterference-v0.1- Compiler
epistemedia/0.2.0