ci(github): require maintainer edits on fork PRs#4791
Conversation
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
|
Warning Review limit reached
More reviews will be available in 7 minutes and 29 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
E2E Advisor RecommendationRequired E2E: None Full advisor summaryE2E Recommendation AdvisorBase: Required E2E
Optional E2E
New E2E recommendations
|
E2E Scenario Advisor RecommendationRequired scenario E2E: None Full scenario advisor summaryE2E Scenario AdvisorBase: Required scenario E2E
Optional scenario E2E
Relevant changed files
|
PR Review AdvisorFindings: 0 needs attention, 1 worth checking, 0 nice ideas Review findings🛠️ Needs attention
🔎 Worth checking
🌱 Nice ideas
This is an automated advisory review. A human maintainer must make the final merge decision. |
Summary
Adds a lightweight pull_request_target workflow that fails fork PRs when maintainers cannot modify the branch. This makes the repository policy visible in CI without checking out or executing untrusted PR code.
Changes
.github/workflows/require-maintainer-edits.yaml.maintainer_can_modifyis false, with an actionable error message.Type of Change
Verification
npm testwas attempted but did not pass because the existingtest/install-preflight.test.tscasewarns on Podman but still runs onboardingexpectedHost preflight found warnings.while the local output reportedHost preflight found issues...; this appears unrelated to the workflow-only change.npx prek run --all-filespassesnpm testpassesnpm run docsbuilds without warnings (doc changes only)Signed-off-by: Carlos Villela cvillela@nvidia.com