From 532c98a41dba6eb4695c3131639917cf56760488 Mon Sep 17 00:00:00 2001 From: Andre_601 <11576465+Andre601@users.noreply.github.com> Date: Wed, 27 May 2026 23:35:42 +0200 Subject: [PATCH 1/2] Improve Wiki validation run --- ..._validation.disabled => pr_wiki_validation.yml} | 14 +------------- 1 file changed, 1 insertion(+), 13 deletions(-) rename .github/workflows/{pr_wiki_validation.disabled => pr_wiki_validation.yml} (65%) diff --git a/.github/workflows/pr_wiki_validation.disabled b/.github/workflows/pr_wiki_validation.yml similarity index 65% rename from .github/workflows/pr_wiki_validation.disabled rename to .github/workflows/pr_wiki_validation.yml index 8441e6c..c91d29f 100644 --- a/.github/workflows/pr_wiki_validation.disabled +++ b/.github/workflows/pr_wiki_validation.yml @@ -19,7 +19,6 @@ on: permissions: contents: read - issues: write env: RUN_URL: "${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_number }}" @@ -33,6 +32,7 @@ jobs: with: fetch-depth: 0 ref: "${{ github.event.pull_request.head.sha }}" + persist-credentials: false - name: "Setup Python 3.x" uses: actions/setup-python@v6 with: @@ -41,15 +41,3 @@ jobs: run: "python -m pip install mkdocs-material" - name: "Build Site" run: "mkdocs build --strict" - - name: "Create Comment" - uses: peter-evans/create-or-update-comment@v5 - if: ${{ failure() }} - with: - body: |- - ## Wiki Build failure - - Something went wrong while creating a test-build of the Wiki for this Pull request. - Please check the [Workflow Logs](${{ env.RUN_URL }}) for any errors. - issue-number: "${{ github.event.pull_request.number }}" - token: "${{ secrets.GITHUB_TOKEN }}" - edit-mode: replace From ff1d8bb74cfe323f4ffdbe74c81fe7e2b4a4a4f4 Mon Sep 17 00:00:00 2001 From: Andre_601 <11576465+Andre601@users.noreply.github.com> Date: Wed, 27 May 2026 23:52:08 +0200 Subject: [PATCH 2/2] Separate comment into its own workflow. --- .../comment_on_failed_validation.yml | 34 +++++++++++++++++++ 1 file changed, 34 insertions(+) create mode 100644 .github/workflows/comment_on_failed_validation.yml diff --git a/.github/workflows/comment_on_failed_validation.yml b/.github/workflows/comment_on_failed_validation.yml new file mode 100644 index 0000000..68c3ae6 --- /dev/null +++ b/.github/workflows/comment_on_failed_validation.yml @@ -0,0 +1,34 @@ +# +# A separate Workflow to comment on Pull requests +# for failed Wiki validation runs. +# +# This is to avoid code execution injected by +# extensions, plugins or hooks in MkDocs, that could +# abuse write permissions. +# +name: "Comment on failed Validation" + +on: + workflow_run: + workflows: + - "Validate Wiki Build" + types: + - completed + +permissions: + pull-requests: write + +jobs: + comment: + if: github.event.workflow_run.conclusion == 'failure' + runs-on: ubuntu-latest + steps: + - name: Comment on Pull request + uses: peter-evans/create-or-update-comment@v5 + with: + issue-number: ${{ github.event.workflow_run.pull_requests[0].number }} + body: | + ## Build validation failed + + Something went wrong while running a test-build with this Pull request's changes. + Please check the [Workflow Run Logs](${{ github.event.workflow_run.html_url }}) for any details.