From 346b20eb6e71675b7e447901db6c44d3a5068c1c Mon Sep 17 00:00:00 2001 From: tobin Date: Thu, 24 Sep 2026 03:19:18 +0000 Subject: [PATCH] Flag unvalidated command sources in scope guard output Report command-source entries the guard skipped and stop the pass message from claiming every added entry came from a live repo. Remote-Dev: homespace --- .github/scripts/external-pr-scope.js | 7 ++++--- .github/workflows/external-pr-scope-guard.yml | 6 +++++- 2 files changed, 9 insertions(+), 4 deletions(-) diff --git a/.github/scripts/external-pr-scope.js b/.github/scripts/external-pr-scope.js index 206b0c72..cf31e441 100644 --- a/.github/scripts/external-pr-scope.js +++ b/.github/scripts/external-pr-scope.js @@ -69,9 +69,10 @@ function analyze({ changedFiles, before, after, liveRepos }) { problems.push('makes no in-scope change (expected additions to marketplace.json)'); } + const unvalidated = []; for (const name of added) { - // Command sources have no repo URL to validate. - if (after[name] && after[name].source && after[name].source.source === 'command') continue; + // Command sources have no repo URL to validate; report them so a reviewer checks them by hand. + if (after[name] && after[name].source && after[name].source.source === 'command') { unvalidated.push(name); continue; } const u = after[name] && after[name].source && after[name].source.url; if (!u) { problems.push(`added "${name}" has no source.url to validate`); continue; } const r = normalizeRepo(u); @@ -81,7 +82,7 @@ function analyze({ changedFiles, before, after, liveRepos }) { } } - return { ok: problems.length === 0, problems, added, removed, modified, liveRepoCount: liveRepos.size }; + return { ok: problems.length === 0, problems, added, removed, modified, unvalidated, liveRepoCount: liveRepos.size }; } async function readPlugins(github, owner, repo, ref) { diff --git a/.github/workflows/external-pr-scope-guard.yml b/.github/workflows/external-pr-scope-guard.yml index 3d67296f..683e178b 100644 --- a/.github/workflows/external-pr-scope-guard.yml +++ b/.github/workflows/external-pr-scope-guard.yml @@ -51,4 +51,8 @@ jobs: ); return; } - console.log(`Scope guard passed: adds ${result.added.join(', ') || 'none'}, all from repos already live here.`); + const unvalidated = result.unvalidated || []; + if (unvalidated.length) { + core.warning(`Command-source entries are not repo-validated; review manually: ${unvalidated.join(', ')}`); + } + console.log(`Scope guard passed: adds ${result.added.join(', ') || 'none'}${unvalidated.length ? '' : ', all from repos already live here'}.`);