|
| 1 | +# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. |
| 2 | +# SPDX-License-Identifier: Apache-2.0 |
| 3 | + |
| 4 | +name: Maintainers Change Alert |
| 5 | + |
| 6 | +on: |
| 7 | + pull_request_target: |
| 8 | + types: [opened, reopened, synchronize] |
| 9 | + paths: |
| 10 | + - MAINTAINERS.md |
| 11 | + |
| 12 | +permissions: |
| 13 | + contents: read |
| 14 | + pull-requests: write |
| 15 | + |
| 16 | +concurrency: |
| 17 | + group: ${{ github.workflow }}-${{ github.event.pull_request.number }} |
| 18 | + cancel-in-progress: true |
| 19 | + |
| 20 | +jobs: |
| 21 | + describe-change: |
| 22 | + name: Comment on the approver set change if MAINTAINERS.md has changed |
| 23 | + if: github.repository_owner == 'NVIDIA' |
| 24 | + runs-on: ubuntu-latest |
| 25 | + timeout-minutes: 10 |
| 26 | + steps: |
| 27 | + # Default branch only. The helper must be the reviewed version, not |
| 28 | + # whatever the pull request happens to contain. |
| 29 | + - name: Check out the change-alert helper |
| 30 | + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
| 31 | + with: |
| 32 | + ref: main |
| 33 | + sparse-checkout: tasks/scripts/alert_maintainer_change.py |
| 34 | + sparse-checkout-cone-mode: false |
| 35 | + persist-credentials: false |
| 36 | + |
| 37 | + - name: Post the maintainer delta |
| 38 | + env: |
| 39 | + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} |
| 40 | + GH_REPO: ${{ github.repository }} |
| 41 | + PR_NUMBER: ${{ github.event.pull_request.number }} |
| 42 | + BASE_SHA: ${{ github.event.pull_request.base.sha }} |
| 43 | + HEAD_SHA: ${{ github.event.pull_request.head.sha }} |
| 44 | + # Single source of truth for the comment marker: the script emits |
| 45 | + # it as the first line of the body, the lookup below matches on it. |
| 46 | + COMMENT_MARKER: "<!-- maintainer-approval-delta -->" |
| 47 | + shell: bash |
| 48 | + run: | |
| 49 | + set -euo pipefail |
| 50 | +
|
| 51 | + # Fetching file contents is reading data, not executing it. The head |
| 52 | + # revision is never checked out or run. |
| 53 | + # |
| 54 | + # A 404 means the file genuinely does not exist at that revision — a |
| 55 | + # pull request that adds or deletes MAINTAINERS.md — and yields an |
| 56 | + # empty side of the comparison. Every other failure is fatal: an empty |
| 57 | + # file from a rate limit or a 5xx would render as "every maintainer |
| 58 | + # was just added" or "nothing changed", both of which mislead the |
| 59 | + # reviewer about who can merge code. |
| 60 | + fetch_maintainers() { |
| 61 | + local ref="$1" out="$2" err |
| 62 | + err="$(mktemp)" |
| 63 | + if gh api -H "Accept: application/vnd.github.raw" \ |
| 64 | + "repos/$GH_REPO/contents/MAINTAINERS.md?ref=$ref" > "$out" 2>"$err"; then |
| 65 | + rm -f "$err" |
| 66 | + return 0 |
| 67 | + fi |
| 68 | + if grep -q 'HTTP 404' "$err"; then |
| 69 | + rm -f "$err" |
| 70 | + : > "$out" |
| 71 | + return 0 |
| 72 | + fi |
| 73 | + echo "::error::Could not fetch MAINTAINERS.md at $ref" |
| 74 | + cat "$err" >&2 |
| 75 | + rm -f "$err" |
| 76 | + return 1 |
| 77 | + } |
| 78 | +
|
| 79 | + fetch_maintainers "$BASE_SHA" before.md |
| 80 | + fetch_maintainers "$HEAD_SHA" after.md |
| 81 | +
|
| 82 | + # An unparseable result exits non-zero, but the comment explaining |
| 83 | + # why still has to be posted before this job fails. |
| 84 | + status=0 |
| 85 | + python3 tasks/scripts/alert_maintainer_change.py \ |
| 86 | + --before before.md --after after.md > body.md || status=$? |
| 87 | +
|
| 88 | + # No output means the approver set did not change. A comment saying |
| 89 | + # so is noise, so post nothing. |
| 90 | + if [ -s body.md ]; then |
| 91 | + cat body.md >> "$GITHUB_STEP_SUMMARY" |
| 92 | +
|
| 93 | + # Update the existing comment rather than stacking one per push. |
| 94 | + COMMENT_ID=$(gh api --paginate "repos/$GH_REPO/issues/$PR_NUMBER/comments" \ |
| 95 | + --jq '.[] | select(.body | startswith($ENV.COMMENT_MARKER)) | .id' \ |
| 96 | + | head -n 1) |
| 97 | +
|
| 98 | + if [ -n "$COMMENT_ID" ]; then |
| 99 | + gh api --method PATCH "repos/$GH_REPO/issues/comments/$COMMENT_ID" \ |
| 100 | + -F "body=@body.md" >/dev/null |
| 101 | + else |
| 102 | + gh api --method POST "repos/$GH_REPO/issues/$PR_NUMBER/comments" \ |
| 103 | + -F "body=@body.md" >/dev/null |
| 104 | + fi |
| 105 | + fi |
| 106 | +
|
| 107 | + exit "$status" |
0 commit comments