Skip to content

audit-ecosystems: file E16 (#814, #815), E38 (#816), add E60 #95

audit-ecosystems: file E16 (#814, #815), E38 (#816), add E60

audit-ecosystems: file E16 (#814, #815), E38 (#816), add E60 #95

name: arch audit ledger to discussion
on:
push:
branches: [arch-audit/ledger]
workflow_dispatch:
permissions:
contents: read
discussions: write
issues: read
pull-requests: read
jobs:
mirror:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
persist-credentials: false
# No concurrency group: GitHub cancels a queued run when a newer one
# arrives, which would drop that push's entries. Each run posts only the
# entries its own push added, and renders from the latest branch tip.
- name: Post entries and render the register and living document
env:
GH_TOKEN: ${{ github.token }}
BEFORE: ${{ github.event.before }}
AFTER: ${{ github.sha }}
run: |
set -euo pipefail
git fetch --quiet origin arch-audit/ledger
git show FETCH_HEAD:tools/mirror.py > "$RUNNER_TEMP/mirror.py"
if [ "${{ github.event_name }}" = push ]; then
python3 "$RUNNER_TEMP/mirror.py" --ref FETCH_HEAD --entries "$BEFORE" "$AFTER"
else
python3 "$RUNNER_TEMP/mirror.py" --ref FETCH_HEAD
fi