diff --git a/.github/workflows/deploy-staging.yml b/.github/workflows/deploy-staging.yml index 50b48c1..674c4d9 100644 --- a/.github/workflows/deploy-staging.yml +++ b/.github/workflows/deploy-staging.yml @@ -20,6 +20,28 @@ jobs: with: fetch-depth: 0 + - name: Resolve governance comparison refs + id: governance-refs + shell: bash + env: + EVENT_NAME: ${{ github.event_name }} + EVENT_BEFORE: ${{ github.event.before }} + PR_BASE_SHA: ${{ github.event.pull_request.base.sha }} + PR_HEAD_SHA: ${{ github.event.pull_request.head.sha }} + run: | + set -euo pipefail + if [[ "${EVENT_NAME}" == "pull_request" ]]; then + base="${PR_BASE_SHA}" + head="${PR_HEAD_SHA}" + elif [[ "${EVENT_NAME}" == "push" && -n "${EVENT_BEFORE}" && ! "${EVENT_BEFORE}" =~ ^0+$ ]]; then + base="${EVENT_BEFORE}" + head="HEAD" + else + base="origin/dev" + head="HEAD" + fi + printf 'base=%s\nhead=%s\n' "${base}" "${head}" >> "${GITHUB_OUTPUT}" + - name: Set up .NET uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 with: @@ -33,6 +55,9 @@ jobs: cache-dependency-path: infra/cdk/package-lock.json - name: Repository quality gate + env: + BASE_REF: ${{ steps.governance-refs.outputs.base }} + HEAD_REF: ${{ steps.governance-refs.outputs.head }} run: bash scripts/governance-check.sh - name: Validate CDK deployment infrastructure