Skip to content

Run mirror-playwright only for same-repo PRs - #75

Merged
cshuttle merged 1 commit into
mainfrom
fix/mirror-playwright-fork-gate
Oct 4, 2026
Merged

cshuttle merged 1 commit into
mainfrom
fix/mirror-playwright-fork-gate

Conversation

@cshuttle

@cshuttle cshuttle commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Why

This repo is public, and mirror-playwright runs on pull_request on the self-hosted arc-workflows runners. A fork PR that touches playwright-test.yml or mirror-playwright.yml would run its own code on our runner. #72 moved selftest PR runs to hosted runners; this was the one PR path left (found in the arc-workflows capture on Monitoring#1285).

What

  • resolve now runs only for workflow_dispatch and same-repo PRs. mirror needs resolve, so it skips with it.
  • Nothing is lost: a fork PR's token is read-only and could never push to ghcr.
  • This PR touches mirror-playwright.yml, so its own run proves a same-repo PR still mirrors.

Refs cshuttle/Monitoring#1285

🤖 Generated with Claude Code

The repo is public and arc-workflows is self-hosted, so a fork PR that
touches the mirror's paths would run its own code on our runner. A fork
token cannot push to ghcr, so the gate loses nothing.

Refs cshuttle/Monitoring#1285

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@cshuttle
cshuttle merged commit 06fcab0 into main Oct 4, 2026
13 checks passed
@cshuttle
cshuttle deleted the fix/mirror-playwright-fork-gate branch October 4, 2026 19:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant