chore: CI badge, mirror PR explainer, and the tag-pin release step (#47)
Three items #47 absorbed from #46, held back so a dead badge would not sit beside an unresolved r-universe one. Both resolve now that v0.4.0 is tagged. - R-CMD-check badge pointing at the GitHub mirror's workflow, where the 4-platform matrix actually runs. - A pull_request_target workflow explaining the mirror flow on every incoming PR. A PR here is landed on Gitea and syncs back, and because the merge preserves the contributor's commits at their original SHAs, GitHub marks the PR 'Merged' with nobody visibly clicking Merge. To a first-time contributor that reads as rejection. Say so before it happens. pull_request_target rather than pull_request because a fork PR's token is read-only under the latter -- it could not comment, which is the entire job. That is only safe because this never checks out or runs contributor code; the file says so and says not to add a checkout. - CONTRIBUTING's release checklist now spells out that the tag goes on Gitea and the mirror carries it, and that r-universe does NOT pick up a release until packages.json's branch pin is edited. '*release' would automate it but needs a GitHub Release object, and the mirror pushes tags only -- so it would silently never update. Learned while doing this release.
This commit is contained in:
@@ -0,0 +1,64 @@
|
||||
# Explain the mirror contribution flow on every incoming pull request.
|
||||
#
|
||||
# This repository is a MIRROR. A PR opened here is landed on the canonical Gitea
|
||||
# repository and syncs back; because the merge preserves the contributor's
|
||||
# commits at their original SHAs, GitHub marks the PR "Merged" on its own as
|
||||
# soon as the mirror syncs -- with nobody visibly clicking Merge.
|
||||
#
|
||||
# Without this comment, that reads as a rejection: the contributor sees their PR
|
||||
# close with no review, no merge button pressed, and no explanation. It is
|
||||
# actually the successful outcome. Say so up front, before it happens.
|
||||
#
|
||||
# WHY pull_request_target AND NOT pull_request:
|
||||
# a `pull_request` run from a fork gets a read-only token, so it cannot post a
|
||||
# comment -- which is exactly the case this workflow exists to serve.
|
||||
# `pull_request_target` runs in the context of the BASE repo and gets a writable
|
||||
# token. That is only safe because this job never checks out or executes the
|
||||
# contributor's code; it posts a fixed string. Do not add a checkout of
|
||||
# `github.event.pull_request.head.sha` here -- that combination is the standard
|
||||
# pull_request_target privilege-escalation hole.
|
||||
name: Explain the mirror flow
|
||||
|
||||
on:
|
||||
pull_request_target:
|
||||
types: [opened]
|
||||
|
||||
permissions:
|
||||
pull-requests: write
|
||||
|
||||
jobs:
|
||||
comment:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Post the contribution-flow explainer
|
||||
uses: actions/github-script@v7
|
||||
with:
|
||||
script: |
|
||||
const body = [
|
||||
"Thanks for this — and one thing worth knowing before it happens.",
|
||||
"",
|
||||
"**This repository is a mirror.** Development happens on Gitea at",
|
||||
"`gitea.civilytics.org/Civilytics/uscogdata`. Your pull request will be fetched",
|
||||
"from here, landed there, and synced back.",
|
||||
"",
|
||||
"Because that merge preserves your commits at their original SHAs, **GitHub will",
|
||||
"mark this pull request \"Merged\" on its own** — without anyone visibly clicking",
|
||||
"the Merge button, and possibly without a review comment on this page first.",
|
||||
"",
|
||||
"> If your pull request closes as \"Merged\" and nobody appears to have merged it,",
|
||||
"> that is the normal, successful outcome — not a rejection.",
|
||||
"",
|
||||
"If it is *not* going to be merged, you will get an actual reply saying so.",
|
||||
"",
|
||||
"Substantial contributions get a `ctb` entry in `DESCRIPTION`, which surfaces in",
|
||||
"`citation(\"uscogdata\")`. There is no CLA and no DCO sign-off.",
|
||||
"",
|
||||
"Full details: [CONTRIBUTING.md](https://github.com/civilytics/uscogdata/blob/main/CONTRIBUTING.md).",
|
||||
].join("\n");
|
||||
|
||||
await github.rest.issues.createComment({
|
||||
owner: context.repo.owner,
|
||||
repo: context.repo.repo,
|
||||
issue_number: context.payload.pull_request.number,
|
||||
body,
|
||||
});
|
||||
+10
-2
@@ -101,5 +101,13 @@ but "usually" is not a release gate.
|
||||
variables set. This is the only check that catches a
|
||||
corpus-unreachable defect, and its absence is why 0.3.0 needed fixing.
|
||||
8. Bump `Version` and add a `NEWS.md` section.
|
||||
9. Tag, then update the r-universe registry pin at
|
||||
`github.com/civilytics/civilytics.r-universe.dev`.
|
||||
9. Tag on **Gitea** (`git tag -a vX.Y.Z && git push origin vX.Y.Z`). The mirror
|
||||
workflow carries tags to GitHub on its own — confirm the tag appears at
|
||||
`github.com/civilytics/uscogdata/tags` before continuing.
|
||||
10. Update the r-universe registry pin at
|
||||
`github.com/civilytics/civilytics.r-universe.dev` — edit `packages.json`'s
|
||||
`branch` to the new tag. **r-universe will not pick up a release until this
|
||||
is edited**: the pin is a tag, deliberately, so a mid-refactor `main` is
|
||||
never published as a release. `"branch": "*release"` would track releases
|
||||
automatically, but it needs a GitHub *Release* object and the mirror pushes
|
||||
tags only — so it would silently never update.
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
# uscogdata
|
||||
|
||||
<!-- badges: start -->
|
||||
[](https://github.com/civilytics/uscogdata/actions/workflows/R-CMD-check.yaml)
|
||||
[](https://civilytics.r-universe.dev/uscogdata)
|
||||
[](LICENSE.md)
|
||||
<!-- badges: end -->
|
||||
|
||||
Reference in New Issue
Block a user