Three items #47 absorbed from #46, held back so a dead badge would not sit
beside an unresolved r-universe one. Both resolve now that v0.4.0 is tagged.
- R-CMD-check badge pointing at the GitHub mirror's workflow, where the
4-platform matrix actually runs.
- A pull_request_target workflow explaining the mirror flow on every incoming
PR. A PR here is landed on Gitea and syncs back, and because the merge
preserves the contributor's commits at their original SHAs, GitHub marks the
PR 'Merged' with nobody visibly clicking Merge. To a first-time contributor
that reads as rejection. Say so before it happens.
pull_request_target rather than pull_request because a fork PR's token is
read-only under the latter -- it could not comment, which is the entire job.
That is only safe because this never checks out or runs contributor code; the
file says so and says not to add a checkout.
- CONTRIBUTING's release checklist now spells out that the tag goes on Gitea and
the mirror carries it, and that r-universe does NOT pick up a release until
packages.json's branch pin is edited. '*release' would automate it but needs a
GitHub Release object, and the mirror pushes tags only -- so it would silently
never update. Learned while doing this release.