Repository object · automation

Approve Open Docket Promotion

Accepted automation in the public catalog.

Source path
.github/workflows/approve-open-docket-promotion.yml
Media type
application/yaml
Object ID
em:automation:sha256:b2ea18b24eb739f090e795b4adc15e8c57c716a2df903a9dd63bec115f9941c7
Content digest
023cb94e8dc9ae3d702f9432e9192775234aff938b802c1e9161fb281f1504c9

Source content

name: attest-open-docket-promotion

on:

workflow_run:

workflows: [validate]

types: [completed]

permissions: {}

concurrency:

group: attest-open-docket-${{ github.event.workflow_run.id }}

cancel-in-progress: false

jobs:

attest:

if: >-

github.event.workflow_run.conclusion == 'success' &&

github.event.workflow_run.event == 'pull_request' &&

github.event.workflow_run.pull_requests[0].number != null

runs-on: ubuntu-latest

permissions:

contents: read

pull-requests: read

steps:

- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6

with:

ref: ${{ github.event.repository.default_branch }}

persist-credentials: false

- name: Confirm exact accepted-base promotion shape

env:

GH_TOKEN: ${{ github.token }}

PR_NUMBER: ${{ github.event.workflow_run.pull_requests[0].number }}

REVIEWED_HEAD: ${{ github.event.workflow_run.head_sha }}

shell: bash

run: |

set -euo pipefail

actual_head="$(gh api "repos/${GITHUB_REPOSITORY}/pulls/${PR_NUMBER}" --jq .head.sha)"

[[ "$actual_head" == "$REVIEWED_HEAD" ]]

mapfile -t paths < <(gh api --paginate "repos/${GITHUB_REPOSITORY}/pulls/${PR_NUMBER}/files?per_page=100" --jq '.[].filename')

[[ ${#paths[@]} -eq 5 ]]

parent=""

for path in "${paths[@]}"; do

[[ "$path" =~ ^research/open-dockets/[^/]+/(controller-attestation\.json|intake\.json|proposal\.json|promotion-receipt\.json|review\.json)$ ]]

current_parent="${path%/*}"

if [[ -z "$parent" ]]; then

parent="$current_parent"

else

[[ "$parent" == "$current_parent" ]]

fi

done

- name: Create short-lived review-gate App token

id: app-token

uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0

with:

app-id: ${{ vars.REVIEW_GATE_APP_ID }}

private-key: ${{ secrets.REVIEW_GATE_APP_PRIVATE_KEY }}

permission-checks: write

permission-contents: read

permission-pull-requests: read

- name: Sign the exact promotion receipt head

env:

GH_TOKEN: ${{ steps.app-token.outputs.token }}

REVIEWED_HEAD: ${{ github.event.workflow_run.head_sha }}

PR_NUMBER: ${{ github.event.workflow_run.pull_requests[0].number }}

shell: bash

run: |

set -euo pipefail

gh api --method POST "repos/${GITHUB_REPOSITORY}/check-runs" \

-f name='independent-review' \

-f head_sha="$REVIEWED_HEAD" \

-f status='completed' \

-f conclusion='success' \

-f 'output[title]=Accepted-base promotion receipt validated' \

-f "output[summary]=Promotion PR #${PR_NUMBER} passed accepted-base validation at exact receipt head ${REVIEWED_HEAD}. The App did not review evidence, write contents, or merge."

Build receipt

Reproduce this projection

Reproducible projection
Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d
Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf
Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9
Epistemic policy
commons-balanced-v0.1
Disclosure policy
public-noninterference-v0.1
Compiler
epistemedia/0.2.0