Skip to content

Embed YouTube without cookies and show focus on navigation menu links #118

Embed YouTube without cookies and show focus on navigation menu links

Embed YouTube without cookies and show focus on navigation menu links #118

name: Check
# Required on every pull request in the organization through the "Merge policy" ruleset.
# Runs the repository's own `check` script. A pull request fails when it removes package.json,
# pnpm-lock.yaml, or the `check` script from a base branch that has all three. Repositories
# that are not pnpm projects with a check script on the base branch pass with a notice.
on:
pull_request:
permissions:
contents: read
concurrency:
group: check-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
check:
name: Check
runs-on: ubuntu-latest
timeout-minutes: 15
# Nested pnpm installs in a check script get the same protection as the install below.
env:
pnpm_config_ignore_scripts: "true"
pnpm_config_ignore_pnpmfile: "true"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# Also fetches the parents of the pull request's merge commit, so the next step can read the base branch.
fetch-depth: 2
# The base branch decides whether a repository must run its check, because a pull
# request cannot change it. Once the base branch has package.json, pnpm-lock.yaml,
# and a `check` script, a pull request that removes any of them fails.
- name: Find the check script
id: scripts
run: |
# Prints what a commit lacks to be a pnpm project with a check script.
missing() {
git cat-file -e "$1:package.json" 2>/dev/null || echo "package.json"
git cat-file -e "$1:pnpm-lock.yaml" 2>/dev/null || echo "pnpm-lock.yaml"
git show "$1:package.json" 2>/dev/null |
node -e 'process.exit(JSON.parse(require("fs").readFileSync(0, "utf8")).scripts?.check ? 0 : 1)' 2>/dev/null ||
echo "a check script in package.json"
}
# A pull request is checked out as a merge commit: the base branch, then the pull request.
if ! git rev-parse --verify --quiet HEAD^2 >/dev/null; then
echo "::error::Expected a pull request merge commit with the base branch as its first parent."
exit 1
fi
head_missing=$(missing HEAD)
base_missing=$(missing HEAD^1)
if [ -z "$head_missing" ]; then
echo "run=true" >> "$GITHUB_OUTPUT"
elif [ -z "$base_missing" ]; then
echo "::error::$GITHUB_BASE_REF is a pnpm project with a check script, but this pull request removes: $(echo "$head_missing" | paste -sd, - | sed 's/,/, /g'). Restore it so the check can run."
exit 1
else
echo "No pnpm project with a check script on $GITHUB_BASE_REF or in this pull request. Nothing to run."
fi
- if: steps.scripts.outputs.run == 'true'
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
# Corepack starts the pnpm version from `packageManager` faster than pnpm/action-setup.
- if: steps.scripts.outputs.run == 'true'
run: corepack enable
# Caches downloaded packages only. The install below always runs, so every run
# checks the lockfile against the repository's pnpm settings and the registry.
- if: steps.scripts.outputs.run == 'true'
id: store
run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
- if: steps.scripts.outputs.run == 'true'
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: ${{ steps.store.outputs.path }}
key: pnpm-store-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}
restore-keys: pnpm-store-${{ runner.os }}-
- if: steps.scripts.outputs.run == 'true'
run: pnpm install --frozen-lockfile --ignore-scripts --ignore-pnpmfile
- if: steps.scripts.outputs.run == 'true'
run: pnpm check
# Temporary, for the CloudCannon setup only: merges a CloudCannon publication
# (preview into main) once all required checks pass. Remove when the sites
# move to the new CMS.
cloudcannon-auto-merge:
name: CloudCannon auto-merge
needs: check
if: github.event.pull_request.user.login == 'cloudcannon[bot]' && github.head_ref == 'preview' && github.base_ref == 'main'
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
steps:
- run: gh pr merge "$PR" --repo "$REPO" --auto --squash
env:
GH_TOKEN: ${{ github.token }}
PR: ${{ github.event.pull_request.number }}
REPO: ${{ github.repository }}