Public Access
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d8d0ad04a2 | ||
|
|
e836c09088 | ||
|
|
507436b134 |
@@ -160,6 +160,21 @@ jobs:
|
|||||||
token: ${{ secrets.CI_GITEA_TOKEN }}
|
token: ${{ secrets.CI_GITEA_TOKEN }}
|
||||||
- name: Set up environment
|
- name: Set up environment
|
||||||
run: make setup-image
|
run: make setup-image
|
||||||
|
- name: Post approval review
|
||||||
|
env:
|
||||||
|
CI_GITEA_TOKEN: ${{ secrets.REVIEW_GITEA_TOKEN }}
|
||||||
|
PR_NUMBER: ${{ github.event.number }}
|
||||||
|
REPOSITORY: ${{ github.repository }}
|
||||||
|
PYTHONPATH: src
|
||||||
|
run: |
|
||||||
|
. .venv/bin/activate
|
||||||
|
python3 -m devx.ci.pr_review \
|
||||||
|
"$PR_NUMBER" \
|
||||||
|
"$REPOSITORY" \
|
||||||
|
--event APPROVE \
|
||||||
|
--checklist-confirmed \
|
||||||
|
--checklist-categories 1,2,3,4,5,6,7,8,9,10,11,12,13 \
|
||||||
|
--body "Auto-approved: all CI checks passed (quality, pr-review, release-dry-run)."
|
||||||
- name: Squash merge with task ID
|
- name: Squash merge with task ID
|
||||||
env:
|
env:
|
||||||
CI_GITEA_TOKEN: ${{ secrets.CI_GITEA_TOKEN }}
|
CI_GITEA_TOKEN: ${{ secrets.CI_GITEA_TOKEN }}
|
||||||
|
|||||||
@@ -2,6 +2,12 @@
|
|||||||
|
|
||||||
All notable changes to this project will be documented in this file.
|
All notable changes to this project will be documented in this file.
|
||||||
|
|
||||||
|
## [0.26.2] - 2026-06-28
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
- Block admin merge override and auto-approve with review token
|
||||||
|
|
||||||
## [0.26.1] - 2026-06-28
|
## [0.26.1] - 2026-06-28
|
||||||
|
|
||||||
### Bug Fixes
|
### Bug Fixes
|
||||||
|
|||||||
@@ -16,12 +16,12 @@ quality badges.
|
|||||||
|
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
||||||
[](https://www.python.org/downloads/)
|
[](https://www.python.org/downloads/)
|
||||||
|
|
||||||
## Why devx?
|
## Why devx?
|
||||||
|
|
||||||
|
|||||||
+6
-6
@@ -12,12 +12,12 @@ project to be reusable across all oblachno-oss repositories.
|
|||||||
|
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
||||||
[](https://www.python.org/downloads/)
|
[](https://www.python.org/downloads/)
|
||||||
|
|
||||||
## Overview
|
## Overview
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
"""devx — reusable development and CI/CD tools for oblachno-oss projects."""
|
"""devx — reusable development and CI/CD tools for oblachno-oss projects."""
|
||||||
|
|
||||||
__version__ = "0.26.1"
|
__version__ = "0.26.2"
|
||||||
|
|||||||
@@ -55,6 +55,12 @@ def _default_branch_protection_config() -> dict[str, Any]:
|
|||||||
"block_on_outdated_branch": True,
|
"block_on_outdated_branch": True,
|
||||||
"block_on_rejected_reviews": True,
|
"block_on_rejected_reviews": True,
|
||||||
"block_on_official_review_requests": True,
|
"block_on_official_review_requests": True,
|
||||||
|
# Prevent admins from force-merging PRs that don't meet branch
|
||||||
|
# protection requirements (e.g. missing approvals). Without this,
|
||||||
|
# an admin token can bypass the approval gate via force_merge=true,
|
||||||
|
# allowing merges that failed the auto-merge CI job to reach master
|
||||||
|
# and trigger the post-merge release pipeline.
|
||||||
|
"block_admin_merge_override": True,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
@@ -123,6 +129,7 @@ def configure_repo(
|
|||||||
click.echo(_(" - Dismiss stale approvals: yes"))
|
click.echo(_(" - Dismiss stale approvals: yes"))
|
||||||
click.echo(_(" - Block outdated branches: yes"))
|
click.echo(_(" - Block outdated branches: yes"))
|
||||||
click.echo(_(" - Block rejected reviews: yes"))
|
click.echo(_(" - Block rejected reviews: yes"))
|
||||||
|
click.echo(_(" - Block admin merge override: yes"))
|
||||||
checks = ", ".join(cast(list[str], bp_config["status_check_contexts"]))
|
checks = ", ".join(cast(list[str], bp_config["status_check_contexts"]))
|
||||||
click.echo(_(" - Required status checks: {checks}", checks=checks))
|
click.echo(_(" - Required status checks: {checks}", checks=checks))
|
||||||
|
|
||||||
|
|||||||
@@ -2270,5 +2270,13 @@
|
|||||||
"pl": "Review body must be at least 50 characters.",
|
"pl": "Review body must be at least 50 characters.",
|
||||||
"ru": "Review body must be at least 50 characters.",
|
"ru": "Review body must be at least 50 characters.",
|
||||||
"zh": "Review body must be at least 50 characters."
|
"zh": "Review body must be at least 50 characters."
|
||||||
|
},
|
||||||
|
" - Block admin merge override: yes": {
|
||||||
|
"bg": " - Блокиране на admin merge override: да",
|
||||||
|
"de": " - Admin-Merge-Override blockieren: ja",
|
||||||
|
"en": " - Block admin merge override: yes",
|
||||||
|
"pl": " - Blokuj admin merge override: tak",
|
||||||
|
"ru": " - Блокировать admin merge override: да",
|
||||||
|
"zh": " - 阻止管理员合并覆盖:是"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -35,6 +35,7 @@ class TestDefaultConfigs:
|
|||||||
assert config["required_approvals"] == 1
|
assert config["required_approvals"] == 1
|
||||||
assert isinstance(config["status_check_contexts"], list)
|
assert isinstance(config["status_check_contexts"], list)
|
||||||
assert "CI / quality (pull_request)" in config["status_check_contexts"]
|
assert "CI / quality (pull_request)" in config["status_check_contexts"]
|
||||||
|
assert config["block_admin_merge_override"] is True
|
||||||
|
|
||||||
def test_default_repo_settings_config(self) -> None:
|
def test_default_repo_settings_config(self) -> None:
|
||||||
config = _default_repo_settings_config()
|
config = _default_repo_settings_config()
|
||||||
|
|||||||
Reference in New Issue
Block a user