Repository navigation
Embed YouTube without cookies and show focus on navigation menu links #118
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Check | |
| # Required on every pull request in the organization through the "Merge policy" ruleset. | |
| # Runs the repository's own `check` script. A pull request fails when it removes package.json, | |
| # pnpm-lock.yaml, or the `check` script from a base branch that has all three. Repositories | |
| # that are not pnpm projects with a check script on the base branch pass with a notice. | |
| on: | |
| pull_request: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: check-${{ github.event.pull_request.number }} | |
| cancel-in-progress: true | |
| jobs: | |
| check: | |
| name: Check | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| # Nested pnpm installs in a check script get the same protection as the install below. | |
| env: | |
| pnpm_config_ignore_scripts: "true" | |
| pnpm_config_ignore_pnpmfile: "true" | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| # Also fetches the parents of the pull request's merge commit, so the next step can read the base branch. | |
| fetch-depth: 2 | |
| # The base branch decides whether a repository must run its check, because a pull | |
| # request cannot change it. Once the base branch has package.json, pnpm-lock.yaml, | |
| # and a `check` script, a pull request that removes any of them fails. | |
| - name: Find the check script | |
| id: scripts | |
| run: | | |
| # Prints what a commit lacks to be a pnpm project with a check script. | |
| missing() { | |
| git cat-file -e "$1:package.json" 2>/dev/null || echo "package.json" | |
| git cat-file -e "$1:pnpm-lock.yaml" 2>/dev/null || echo "pnpm-lock.yaml" | |
| git show "$1:package.json" 2>/dev/null | | |
| node -e 'process.exit(JSON.parse(require("fs").readFileSync(0, "utf8")).scripts?.check ? 0 : 1)' 2>/dev/null || | |
| echo "a check script in package.json" | |
| } | |
| # A pull request is checked out as a merge commit: the base branch, then the pull request. | |
| if ! git rev-parse --verify --quiet HEAD^2 >/dev/null; then | |
| echo "::error::Expected a pull request merge commit with the base branch as its first parent." | |
| exit 1 | |
| fi | |
| head_missing=$(missing HEAD) | |
| base_missing=$(missing HEAD^1) | |
| if [ -z "$head_missing" ]; then | |
| echo "run=true" >> "$GITHUB_OUTPUT" | |
| elif [ -z "$base_missing" ]; then | |
| echo "::error::$GITHUB_BASE_REF is a pnpm project with a check script, but this pull request removes: $(echo "$head_missing" | paste -sd, - | sed 's/,/, /g'). Restore it so the check can run." | |
| exit 1 | |
| else | |
| echo "No pnpm project with a check script on $GITHUB_BASE_REF or in this pull request. Nothing to run." | |
| fi | |
| - if: steps.scripts.outputs.run == 'true' | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 24 | |
| # Corepack starts the pnpm version from `packageManager` faster than pnpm/action-setup. | |
| - if: steps.scripts.outputs.run == 'true' | |
| run: corepack enable | |
| # Caches downloaded packages only. The install below always runs, so every run | |
| # checks the lockfile against the repository's pnpm settings and the registry. | |
| - if: steps.scripts.outputs.run == 'true' | |
| id: store | |
| run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT" | |
| - if: steps.scripts.outputs.run == 'true' | |
| uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| with: | |
| path: ${{ steps.store.outputs.path }} | |
| key: pnpm-store-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }} | |
| restore-keys: pnpm-store-${{ runner.os }}- | |
| - if: steps.scripts.outputs.run == 'true' | |
| run: pnpm install --frozen-lockfile --ignore-scripts --ignore-pnpmfile | |
| - if: steps.scripts.outputs.run == 'true' | |
| run: pnpm check | |
| # Temporary, for the CloudCannon setup only: merges a CloudCannon publication | |
| # (preview into main) once all required checks pass. Remove when the sites | |
| # move to the new CMS. | |
| cloudcannon-auto-merge: | |
| name: CloudCannon auto-merge | |
| needs: check | |
| if: github.event.pull_request.user.login == 'cloudcannon[bot]' && github.head_ref == 'preview' && github.base_ref == 'main' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| steps: | |
| - run: gh pr merge "$PR" --repo "$REPO" --auto --squash | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| PR: ${{ github.event.pull_request.number }} | |
| REPO: ${{ github.repository }} |