Bump brace-expansion from 1.1.18 to 1.1.21 in the npm_and_yarn group across 1 directory #2401
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Add engineering PRs to review board | |
| # Routes non-draft engineering PRs to the Docs & Blog Engineering PR Reviews board for triage. | |
| # Labels each PR, so later pushes skip board work unless the PR reopens. | |
| on: | |
| pull_request: | |
| types: | |
| - edited | |
| - opened | |
| - ready_for_review | |
| - reopened | |
| - synchronize | |
| paths: | |
| - '**.ts' | |
| - '**.tsx' | |
| - '**.scss' | |
| - 'src/**' | |
| - '!src/**.json' # Docs Engineering does not triage automated pipeline data PRs. | |
| - '!src/**.yml' # Docs Engineering does not triage automated pipeline data PRs. | |
| - '!src/**.sha' # Docs Engineering does not triage automated pipeline data PRs. | |
| - '.github/**' | |
| - 'config/**' | |
| - '.devcontainer/**' | |
| - '**Dockerfile' | |
| - 'package*.json' | |
| - .github/workflows/reviewers-docs-engineering.yml | |
| permissions: | |
| contents: read | |
| pull-requests: write | |
| repository-projects: read | |
| jobs: | |
| reviewers-docs-engineering: | |
| if: >- | |
| ${{ github.repository == 'github/docs-internal' && | |
| !github.event.pull_request.draft && | |
| (github.event.action == 'reopened' || | |
| !contains(github.event.pull_request.labels.*.name, 'reviewers-docs-engineering')) && | |
| !contains(github.event.pull_request.labels.*.name, 'lockfile-churn-only') && | |
| github.event.pull_request.head.ref != 'repo-sync' }} | |
| runs-on: ubuntu-latest | |
| env: | |
| PR: ${{ github.event.pull_request.html_url }} | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| # Detect PRs that only changed package-lock.json (no engineering source files). | |
| # These are usually cross-platform `npm install` churn from contributors | |
| # editing content. We comment with reset instructions instead of adding | |
| # them to the engineering review board. | |
| # | |
| # Dependabot is exempt. Its security updates for transitive dependencies | |
| # change only the lockfile, because the dependency is not in package.json. | |
| # Those PRs are intentional, so the reset instructions are wrong and | |
| # keeping them off the board leaves them without engineering triage. | |
| - name: Detect lockfile-only churn | |
| id: detect | |
| env: | |
| GH_TOKEN: ${{ secrets.DOCS_BOT_PAT_BASE }} | |
| PR_AUTHOR: ${{ github.event.pull_request.user.login }} | |
| run: | | |
| if [ "$PR_AUTHOR" = "dependabot[bot]" ]; then | |
| echo "Author is Dependabot; skipping lockfile churn detection." | |
| echo "lockfile_only=false" >> "$GITHUB_OUTPUT" | |
| exit 0 | |
| fi | |
| changed=$(gh pr diff "$PR" --name-only) | |
| echo "Changed files:" | |
| echo "$changed" | |
| lockfile=$(echo "$changed" | grep -c '^package-lock\.json$' || true) | |
| other_eng=$(echo "$changed" | grep -cE '(\.tsx?$|\.scss$|^src/|^package\.json$|^\.github/|^config/|^\.devcontainer/|Dockerfile)' || true) | |
| if [ "$lockfile" -gt 0 ] && [ "$other_eng" -eq 0 ]; then | |
| echo "lockfile_only=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "lockfile_only=false" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Comment and label lockfile-only PRs | |
| if: steps.detect.outputs.lockfile_only == 'true' | |
| env: | |
| GH_TOKEN: ${{ secrets.DOCS_BOT_PAT_BASE }} | |
| run: | | |
| cat > /tmp/lockfile-churn-body.md <<'EOF' | |
| _Posted by Copilot on behalf of docs-engineering._ | |
| This PR includes `package-lock.json` changes but no engineering files. Please reset the lockfile: | |
| ``` | |
| git checkout origin/main -- package-lock.json | |
| git commit -m "Reset package-lock.json" | |
| git push | |
| ``` | |
| If the lockfile change is intentional, remove the `lockfile-churn-only` label and push or reopen the PR so this workflow sends it to the engineering review board. | |
| EOF | |
| gh pr comment "$PR" --body-file /tmp/lockfile-churn-body.md | |
| gh pr edit "$PR" --add-label lockfile-churn-only | |
| - name: Add PR to board and label | |
| if: steps.detect.outputs.lockfile_only != 'true' | |
| env: | |
| GH_TOKEN: ${{ secrets.DOCS_BOT_PAT_BASE }} | |
| REPO: ${{ github.repository }} | |
| PR_NUMBER: ${{ github.event.pull_request.number }} | |
| uses: ./.github/actions/retry-command | |
| with: | |
| command: >- | |
| gh project item-add 25672 --owner github --url "$PR" && | |
| gh api "repos/$REPO/issues/$PR_NUMBER/labels" -f 'labels[]=reviewers-docs-engineering' --silent |