diff --git a/.github/workflows/examples/only-PR-comments.yml b/.github/workflows/examples/only-PR-comments.yml index d4771330..22505633 100644 --- a/.github/workflows/examples/only-PR-comments.yml +++ b/.github/workflows/examples/only-PR-comments.yml @@ -13,7 +13,7 @@ jobs: permissions: # (1)! pull-requests: write steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 # ... optionally setup build env to create a compilation database diff --git a/.github/workflows/examples/only-clang-format.yml b/.github/workflows/examples/only-clang-format.yml index c7450d82..24c0d4c9 100644 --- a/.github/workflows/examples/only-clang-format.yml +++ b/.github/workflows/examples/only-clang-format.yml @@ -11,7 +11,7 @@ jobs: cpp-linter: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 # ... optionally setup build env to create a compilation database diff --git a/.github/workflows/examples/only-clang-tidy.yml b/.github/workflows/examples/only-clang-tidy.yml index e673e44b..136cc561 100644 --- a/.github/workflows/examples/only-clang-tidy.yml +++ b/.github/workflows/examples/only-clang-tidy.yml @@ -11,7 +11,7 @@ jobs: cpp-linter: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 # ... optionally setup build env to create a compilation database diff --git a/README.md b/README.md index 2ffe562f..94ce7525 100644 --- a/README.md +++ b/README.md @@ -10,6 +10,7 @@ [recipes-doc]: https://cpp-linter.github.io/cpp-linter-action/examples [permissions-doc]: https://cpp-linter.github.io/cpp-linter-action/permissions [app-token-doc]: https://cpp-linter.github.io/cpp-linter-action/permissions/#github-app-token +[skip-doc]: https://docs.github.com/en/actions/how-tos/manage-workflow-runs/skip-workflow-runs [format-annotations-preview]: https://raw.githubusercontent.com/cpp-linter/cpp-linter-action/main/docs/images/annotations-clang-format.png [tidy-annotations-preview]: https://raw.githubusercontent.com/cpp-linter/cpp-linter-action/main/docs/images/annotations-clang-tidy.png @@ -48,8 +49,17 @@ Create a new GitHub Actions workflow in your project, e.g. at [.github/workflows The content of the file should be in the following format. ```yaml +name: cpp-linter +on: pull_request + +jobs: + cpp-linter: + runs-on: ubuntu-latest + permissions: + contents: read + pull-requests: write # to post the thread comment steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - uses: cpp-linter/cpp-linter-action@v2 id: linter env: @@ -58,7 +68,8 @@ The content of the file should be in the following format. style: 'file' # Use .clang-format config file tidy-checks: '' # Use .clang-tidy config file # only 'update' a single comment in a pull request thread. - thread-comments: ${{ github.event_name == 'pull_request' && 'update' }} + # Pull requests from forks get a read-only token, so skip the comment there. + thread-comments: ${{ github.event.pull_request.head.repo.full_name == github.repository && 'update' }} - name: Fail fast?! if: steps.linter.outputs.checks-failed > 0 run: exit 1 @@ -92,14 +103,13 @@ the workspace to the pull request's head commit before it lints and commits. > [!TIP] > Commits pushed with the default `GITHUB_TOKEN` do not start new workflow runs, > so CI does not re-check the auto-fix commit. To change that, check out and run -> the action with a [GitHub App token][app-token-doc]. To keep a particular -> auto-fix commit from re-running CI, add `[skip ci]` to its message: +> the action with a [GitHub App token][app-token-doc]. > -> ```yaml -> with: -> auto-fix: 'true' -> auto-fix-commit-msg: 'style: apply clang-format fixes [skip ci]' -> ``` +> Do not add `[skip ci]` or any other [skip instruction][skip-doc] to +> `auto-fix-commit-msg`. The auto-fix commit becomes the head of the pull request, +> so its required checks skipped for `push` or `pull_request` events would stay +> pending and may cause a gap in quality control. A squash merge can also carry +> the instruction into your default branch. > > See [our documented permissions][permissions-doc] for the required scopes. @@ -116,38 +126,29 @@ See [GitHub App token][app-token-doc] for the setup steps. ## Used By

- Microsoft - Microsoft   Apache Apache   - NASA - NASA   Samsung Samsung   - TheAlgorithms - TheAlgorithms   + Bloomberg + Bloomberg   + Qualcomm + Qualcomm   + Nextcloud + Nextcloud   CachyOS CachyOS  
- Nextcloud - Nextcloud   Jupyter Jupyter   NNStreamer NNStreamer   - imgproxy - imgproxy   Zondax Zondax   AppNeta AppNeta   -
Chocolate Doom - Chocolate Doom - Bloomberg - Bloomberg - Qualcomm - Qualcomm + Chocolate Doom   and many more.

diff --git a/docs/permissions.md b/docs/permissions.md index b50c373a..b6a54791 100644 --- a/docs/permissions.md +++ b/docs/permissions.md @@ -106,9 +106,12 @@ in addition to any other permissions needed for other features: Commits pushed with the default `GITHUB_TOKEN` do not start new workflow runs, so CI does not re-check the auto-fix commit. To change that, push with a [GitHub App token](#github-app-token) or a personal access token - that has `contents: write`; add `[skip ci]` to - [`auto-fix-commit-msg`](./inputs-outputs.md#auto-fix-commit-msg) if a - particular auto-fix commit should not start a run. + that has `contents: write`. Do not add `[skip ci]` or any other + [skip instruction](https://docs.github.com/en/actions/how-tos/manage-workflow-runs/skip-workflow-runs) + to [`auto-fix-commit-msg`](./inputs-outputs.md#auto-fix-commit-msg): the + auto-fix commit becomes the head of the pull request, so its required + checks skipped for `push` or `pull_request` events would stay + pending and may cause a gap in quality control. Pull requests from forks are skipped with a warning: `GITHUB_TOKEN` cannot push to the fork's branch, and fork pull requests receive no secrets, so an