From af20a45503aec7e99f82c6cfd3efaf4d760437f3 Mon Sep 17 00:00:00 2001 From: Chris Shuttlesworth Date: Sun, 4 Oct 2026 15:48:40 -0400 Subject: [PATCH] Run mirror-playwright only for same-repo PRs The repo is public and arc-workflows is self-hosted, so a fork PR that touches the mirror's paths would run its own code on our runner. A fork token cannot push to ghcr, so the gate loses nothing. Refs cshuttle/Monitoring#1285 Co-Authored-By: Claude Opus 5.5 --- .github/workflows/mirror-playwright.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/mirror-playwright.yml b/.github/workflows/mirror-playwright.yml index c75def6..06467b1 100644 --- a/.github/workflows/mirror-playwright.yml +++ b/.github/workflows/mirror-playwright.yml @@ -51,6 +51,11 @@ jobs: # stale pin. resolve: name: resolve tag + # Same-repo PRs only. This repo is public and arc-workflows is self-hosted, + # so a fork PR touching the paths above would run its own code on our + # runner (Monitoring#1285). A fork's token cannot push to ghcr anyway, so + # nothing is lost; `mirror` needs this job and skips with it. + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository runs-on: arc-workflows outputs: tag: ${{ steps.tag.outputs.tag }}