name: policy # Self-caller: runs the org-wide PR policy gate on THIS repo's own pull requests. # # This workflow is new and will begin enforcing policy on PRs opened AFTER it # merges to main. PRs that are already open at merge time are not retroactively # re-evaluated until one of the trigger events fires again (e.g. a new commit). # # The check-run name this emits is `policy / pr`, matching the org standard # documented in callable-pr-policy.yaml. Do not rename the job below — the # job id (`policy`) is the first segment of that context. # # Uses a local path reference because this repo IS the source of the reusable; # pinning to a SHA of itself would lag by one merge every time either file # changes. Local `./` refs are exempt from the SHA-pin policy. on: pull_request: types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review] concurrency: group: policy-${{ github.event.pull_request.number }} cancel-in-progress: true permissions: contents: read issues: read pull-requests: read jobs: policy: uses: ./.github/workflows/callable-pr-policy.yaml secrets: JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }} JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }} JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}