.github/.github/workflows/policy.yaml
2026-08-03 19:15:30 -04:00

36 lines
1.3 KiB
YAML

name: policy
# Self-caller: runs the org-wide PR policy gate on THIS repo's own pull requests.
#
# This workflow is new and will begin enforcing policy on PRs opened AFTER it
# merges to main. PRs that are already open at merge time are not retroactively
# re-evaluated until one of the trigger events fires again (e.g. a new commit).
#
# The check-run name this emits is `policy / pr`, matching the org standard
# documented in callable-pr-policy.yaml. Do not rename the job below — the
# job id (`policy`) is the first segment of that context.
#
# Uses a local path reference because this repo IS the source of the reusable;
# pinning to a SHA of itself would lag by one merge every time either file
# changes. Local `./` refs are exempt from the SHA-pin policy.
on:
pull_request:
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
concurrency:
group: policy-${{ github.event.pull_request.number }}
cancel-in-progress: true
permissions:
contents: read
issues: read
pull-requests: read
jobs:
policy:
uses: ./.github/workflows/callable-pr-policy.yaml
secrets:
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}