From c64f87a68497962b47e5e035b709f2cc31caf0a2 Mon Sep 17 00:00:00 2001 From: Mrugesh Mohapatra <1884376+raisedadead@users.noreply.github.com> Date: Wed, 8 Nov 2023 07:19:02 +0530 Subject: [PATCH] feat(actions): warnings for use of GitHub web UI (#52243) --- .github/workflows/github-no-web-commits.yml | 59 +++++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 .github/workflows/github-no-web-commits.yml diff --git a/.github/workflows/github-no-web-commits.yml b/.github/workflows/github-no-web-commits.yml new file mode 100644 index 00000000000..a89ae123e94 --- /dev/null +++ b/.github/workflows/github-no-web-commits.yml @@ -0,0 +1,59 @@ +name: GitHub - No Commits on GitHub Web +on: + pull_request_target: + types: + - opened + - reopened + # The "synchronize" type may not be used because code review commits, + # from GitHub UI might be acceptable. Enable this if you want to block + # all commits from GitHub UI. + # + # - synchronize + +jobs: + has-web-commits: + runs-on: ubuntu-22.04 + steps: + - name: Check if commits are made on GitHub Web UI + id: check-commits + run: | + PR_NUMBER=$(jq --raw-output .pull_request.number "$GITHUB_EVENT_PATH") + COMMITS_URL="https://api.github.com/repos/$GITHUB_REPOSITORY/pulls/$PR_NUMBER/commits" + + IS_GITHUB_COMMIT=$(curl --header "Authorization: Bearer ${{ secrets.GITHUB_TOKEN }}" "$COMMITS_URL" | jq '[.[] | .commit.committer.name] | any(.[]; . == "GitHub")') + + if [ "$IS_GITHUB_COMMIT" = "true" ]; then + # Set variable for next task + echo "IS_GITHUB_COMMIT=true" >> $GITHUB_ENV + fi + + - name: Add comment on PR if commits are made on GitHub Web UI + uses: actions/github-script@d7906e4ad0b1822421a7e6a35d5ca353c962f410 # v6 + if: env.IS_GITHUB_COMMIT == 'true' + with: + github-token: ${{ secrets.GITHUB_TOKEN }} + script: | + const isDev = await github.rest.teams.getMembershipForUserInOrg({ + org: "freeCodeCamp", + team_slug: "dev-team", + username: context.payload.pull_request.user.login + }).catch(() => ({status: 404})); + const isMod = await github.rest.teams.getMembershipForUserInOrg({ + org: "freeCodeCamp", + team_slug: "moderators", + username: context.payload.pull_request.user.login + }).catch(() => ({status: 404})); + if ( + isDev.status !== 200 && + isMod.status !== 200 + ) { + core.setFailed("Please do not add commits via the GitHub Web UI."); + github.rest.issues.createComment({ + issue_number: context.issue.number, + owner: context.repo.owner, + repo: context.repo.repo, + body: "Thanks for your pull request.\n\n**Please do not add commits via the GitHub Web UI.**\n\nIt generally means you have yet to test these changes in a development setup or complete any prerequisites. We need you to follow the guides mentioned in the checklist. Please revalidate these changes in a developer environment and confirm how you validated your changes.\n\nHappy contributing!\n\n---\n_**Note:** This message was automatically generated by a bot. If you feel this message is in error or would like help resolving it, feel free to reach us [in our contributor chat](https://discord.gg/PRyKn3Vbay)._" + }); + } else if (isDev.status === 200 || isMod.status === 200) { + core.notice('This PR adds commits made on GitHub Web UI by a member of staff or mod.'); + }