diff --git a/.github/workflows/pr-welcome.yaml b/.github/workflows/pr-welcome.yaml new file mode 100644 index 0000000..e508c4a --- /dev/null +++ b/.github/workflows/pr-welcome.yaml @@ -0,0 +1,64 @@ +# Explain the mirror contribution flow on every incoming pull request. +# +# This repository is a MIRROR. A PR opened here is landed on the canonical Gitea +# repository and syncs back; because the merge preserves the contributor's +# commits at their original SHAs, GitHub marks the PR "Merged" on its own as +# soon as the mirror syncs -- with nobody visibly clicking Merge. +# +# Without this comment, that reads as a rejection: the contributor sees their PR +# close with no review, no merge button pressed, and no explanation. It is +# actually the successful outcome. Say so up front, before it happens. +# +# WHY pull_request_target AND NOT pull_request: +# a `pull_request` run from a fork gets a read-only token, so it cannot post a +# comment -- which is exactly the case this workflow exists to serve. +# `pull_request_target` runs in the context of the BASE repo and gets a writable +# token. That is only safe because this job never checks out or executes the +# contributor's code; it posts a fixed string. Do not add a checkout of +# `github.event.pull_request.head.sha` here -- that combination is the standard +# pull_request_target privilege-escalation hole. +name: Explain the mirror flow + +on: + pull_request_target: + types: [opened] + +permissions: + pull-requests: write + +jobs: + comment: + runs-on: ubuntu-latest + steps: + - name: Post the contribution-flow explainer + uses: actions/github-script@v7 + with: + script: | + const body = [ + "Thanks for this — and one thing worth knowing before it happens.", + "", + "**This repository is a mirror.** Development happens on Gitea at", + "`gitea.civilytics.org/Civilytics/uscogdata`. Your pull request will be fetched", + "from here, landed there, and synced back.", + "", + "Because that merge preserves your commits at their original SHAs, **GitHub will", + "mark this pull request \"Merged\" on its own** — without anyone visibly clicking", + "the Merge button, and possibly without a review comment on this page first.", + "", + "> If your pull request closes as \"Merged\" and nobody appears to have merged it,", + "> that is the normal, successful outcome — not a rejection.", + "", + "If it is *not* going to be merged, you will get an actual reply saying so.", + "", + "Substantial contributions get a `ctb` entry in `DESCRIPTION`, which surfaces in", + "`citation(\"uscogdata\")`. There is no CLA and no DCO sign-off.", + "", + "Full details: [CONTRIBUTING.md](https://github.com/civilytics/uscogdata/blob/main/CONTRIBUTING.md).", + ].join("\n"); + + await github.rest.issues.createComment({ + owner: context.repo.owner, + repo: context.repo.repo, + issue_number: context.payload.pull_request.number, + body, + }); diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index f296d70..bb02716 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -101,5 +101,13 @@ but "usually" is not a release gate. variables set. This is the only check that catches a corpus-unreachable defect, and its absence is why 0.3.0 needed fixing. 8. Bump `Version` and add a `NEWS.md` section. -9. Tag, then update the r-universe registry pin at - `github.com/civilytics/civilytics.r-universe.dev`. +9. Tag on **Gitea** (`git tag -a vX.Y.Z && git push origin vX.Y.Z`). The mirror + workflow carries tags to GitHub on its own — confirm the tag appears at + `github.com/civilytics/uscogdata/tags` before continuing. +10. Update the r-universe registry pin at + `github.com/civilytics/civilytics.r-universe.dev` — edit `packages.json`'s + `branch` to the new tag. **r-universe will not pick up a release until this + is edited**: the pin is a tag, deliberately, so a mid-refactor `main` is + never published as a release. `"branch": "*release"` would track releases + automatically, but it needs a GitHub *Release* object and the mirror pushes + tags only — so it would silently never update. diff --git a/README.md b/README.md index a6ac34b..c265eb8 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,7 @@ # uscogdata +[![R-CMD-check](https://github.com/civilytics/uscogdata/actions/workflows/R-CMD-check.yaml/badge.svg)](https://github.com/civilytics/uscogdata/actions/workflows/R-CMD-check.yaml) [![r-universe](https://civilytics.r-universe.dev/badges/uscogdata)](https://civilytics.r-universe.dev/uscogdata) [![License: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE.md)