Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.3 to 2.20.0. - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](https://github.com/step-security/harden-runner/compare/ab7a9404c0f3da075243ca237b5fac12c98deaa5...bf7454d06d71f1098171f2acdf0cd4708d7b5920) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.19.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
95 lines
3.4 KiB
YAML
95 lines
3.4 KiB
YAML
name: _runner-pick
|
|
|
|
# Tiny reusable workflow that classifies the trigger as either a "fork PR
|
|
# from an untrusted contributor" or a "trusted commit" so downstream jobs
|
|
# can pick a runner class without each one duplicating the 200-char gate
|
|
# expression in their own `runs-on:`.
|
|
#
|
|
# It also owns the single Depot kill-switch (use_depot). Depot is currently
|
|
# disabled repo-wide; downstream jobs gate their Depot runner/build usage on
|
|
# use_depot so nothing has to be deleted to turn Depot off. Flip DEPOT_ENABLED
|
|
# in the decide step to switch Depot back on.
|
|
#
|
|
# Caller pattern:
|
|
#
|
|
# jobs:
|
|
# pick:
|
|
# uses: ./.github/workflows/_runner-pick.yml
|
|
#
|
|
# real-work:
|
|
# needs: pick
|
|
# runs-on: ${{ needs.pick.outputs.use_depot == 'true' && 'depot-ubuntu-24.04-8' || 'ubuntu-latest' }}
|
|
# steps: [...]
|
|
#
|
|
# Outputs:
|
|
# is_fork: "true" when the trigger is a pull_request from a fork or an
|
|
# untrusted author_association, "false" otherwise. Use this for
|
|
# trust gating (skipping secret-dependent jobs on forks).
|
|
# use_depot: "true" when downstream jobs should use Depot runners/builders.
|
|
# Currently forced "false" (Depot disabled repo-wide).
|
|
|
|
on:
|
|
workflow_call:
|
|
outputs:
|
|
is_fork:
|
|
description: '"true" if the trigger is an untrusted fork PR.'
|
|
value: ${{ jobs.pick.outputs.is_fork }}
|
|
use_depot:
|
|
description: '"true" when downstream jobs should use Depot. Currently forced off.'
|
|
value: ${{ jobs.pick.outputs.use_depot }}
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
pick:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 1
|
|
outputs:
|
|
is_fork: ${{ steps.decide.outputs.is_fork }}
|
|
use_depot: ${{ steps.decide.outputs.use_depot }}
|
|
steps:
|
|
- name: Harden the runner (Audit all outbound calls)
|
|
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Classify the trigger
|
|
id: decide
|
|
env:
|
|
PR_NUMBER: ${{ github.event.pull_request.number }}
|
|
HEAD_REPO_FORK: ${{ github.event.pull_request.head.repo.fork }}
|
|
AUTHOR_ASSOC: ${{ github.event.pull_request.author_association }}
|
|
run: |
|
|
set -eu
|
|
|
|
# Depot kill-switch. Depot is disabled repo-wide: no job uses Depot
|
|
# runners or the Depot build actions while this is false. All the
|
|
# Depot wiring is left in place - set DEPOT_ENABLED=true to switch it
|
|
# back on (it then activates on trusted, non-fork triggers as before).
|
|
DEPOT_ENABLED=false
|
|
|
|
if [ -z "${PR_NUMBER:-}" ]; then
|
|
# Not a pull_request event at all (push, schedule, workflow_dispatch,
|
|
# workflow_call from a non-PR trigger) -> trusted by default.
|
|
is_fork=false
|
|
elif [ "${HEAD_REPO_FORK}" = "true" ]; then
|
|
is_fork=true
|
|
else
|
|
case "${AUTHOR_ASSOC}" in
|
|
OWNER|MEMBER|COLLABORATOR) is_fork=false ;;
|
|
*) is_fork=true ;;
|
|
esac
|
|
fi
|
|
|
|
# Depot only ever ran on trusted triggers, so gate it on both the
|
|
# kill-switch and is_fork.
|
|
if [ "${DEPOT_ENABLED}" = "true" ] && [ "${is_fork}" = "false" ]; then
|
|
use_depot=true
|
|
else
|
|
use_depot=false
|
|
fi
|
|
|
|
echo "is_fork=${is_fork}" >> "$GITHUB_OUTPUT"
|
|
echo "use_depot=${use_depot}" >> "$GITHUB_OUTPUT"
|