Skip to content
35 changes: 35 additions & 0 deletions .github/workflows/build-android-target.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
# This workflow is intended to be run when we need to build the Android SDK and produce artifacts that require secrets
# when the PR source branch does not have access to secrets (e.g. a fork).
# This workflow will run in the context of the target of the PR and have access to secrets.
# This should only be done after reviewing the PR to ensure that no malicious code has been introduced,
# as it could allow the code on the forked branch to have access to workflow secrets.

name: Build Android on PR Target

on:
pull_request_target:
types: [opened, synchronize, reopened]
branches:
- main
Comment thread
AmyLGalles marked this conversation as resolved.

defaults:
run:
shell: bash

jobs:
check-run:
name: Check PR run
uses: bitwarden/gh-actions/.github/workflows/check-run.yml@main
permissions:
contents: read

run-workflow:
name: Build Android
needs: check-run
if: ${{ github.event.pull_request.head.repo.full_name != github.repository }}
uses: ./.github/workflows/build-android.yml
Comment thread
AmyLGalles marked this conversation as resolved.
secrets: inherit
permissions:
contents: read
pull-requests: write
id-token: write
8 changes: 8 additions & 0 deletions .github/workflows/build-android.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,14 @@ on:
description: "Update Android Repo - Opens a PR updating the SDK in bitwarden/android"
type: boolean
default: false
workflow_call:
secrets:
AZURE_SUBSCRIPTION_ID:
required: true
AZURE_TENANT_ID:
required: true
AZURE_CLIENT_ID:
required: true
Comment thread
AmyLGalles marked this conversation as resolved.

defaults:
run:
Expand Down
35 changes: 35 additions & 0 deletions .github/workflows/build-wasm-internal-target.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
# This workflow is intended to be run when we need to build the WASM SDK and produce artifacts that require secrets
# when the PR source branch does not have access to secrets (e.g. a fork).
# This workflow will run in the context of the target of the PR and have access to secrets.
# This should only be done after reviewing the PR to ensure that no malicious code has been introduced,
# as it could allow the code on the forked branch to have access to workflow secrets.

name: Build @bitwarden/sdk-internal on PR Target

on:
pull_request_target:
types: [opened, synchronize, reopened]
branches:
- main

defaults:
run:
shell: bash

jobs:
check-run:
name: Check PR run
uses: bitwarden/gh-actions/.github/workflows/check-run.yml@main
permissions:
contents: read

run-workflow:
name: Build @bitwarden/sdk-internal
needs: check-run
if: ${{ github.event.pull_request.head.repo.full_name != github.repository }}
uses: ./.github/workflows/build-wasm-internal.yml
Comment thread
AmyLGalles marked this conversation as resolved.
secrets: inherit
permissions:
contents: read
pull-requests: write
id-token: write
8 changes: 8 additions & 0 deletions .github/workflows/build-wasm-internal.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,14 @@ on:
- "rc"
- "hotfix-rc"
workflow_dispatch:
workflow_call:
secrets:
AZURE_SUBSCRIPTION_ID:
required: true
AZURE_TENANT_ID:
required: true
AZURE_CLIENT_ID:
required: true
Comment thread
AmyLGalles marked this conversation as resolved.

permissions: {}

Expand Down
34 changes: 34 additions & 0 deletions .github/workflows/enforce-labels-target.yml
Comment thread
AmyLGalles marked this conversation as resolved.
Outdated
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
# This workflow is intended to be run when we need to enforce PR labels
# when the PR source branch does not have access to secrets (e.g. a fork).
# This workflow will run in the context of the target of the PR and have access to secrets.
# This should only be done after reviewing the PR to ensure that no malicious code has been introduced,
# as it could allow the code on the forked branch to have access to workflow secrets.

name: Enforce PR labels on PR Target

on:
pull_request_target:
types: [labeled, unlabeled, opened, edited, synchronize]
branches:
- main
Comment thread
AmyLGalles marked this conversation as resolved.
Outdated

defaults:
run:
shell: bash

jobs:
check-run:
name: Check PR run
uses: bitwarden/gh-actions/.github/workflows/check-run.yml@main
permissions:
contents: read

run-workflow:
name: Enforce Labels
needs: check-run
if: ${{ github.event.pull_request.head.repo.full_name != github.repository }}
uses: ./.github/workflows/enforce-labels.yml
secrets: inherit
permissions:
contents: read
pull-requests: read
Loading