From 695a2cdf83d9c9b9b972604c7e7317f184b8c815 Mon Sep 17 00:00:00 2001 From: yuecideng Date: Thu, 24 Sep 2026 15:58:58 +0000 Subject: [PATCH] fix(ci): trust release docs checkout --- .github/workflows/docs-pages.yml | 4 ++++ tests/ci/test_workflows.py | 15 +++++++++++++++ 2 files changed, 19 insertions(+) diff --git a/.github/workflows/docs-pages.yml b/.github/workflows/docs-pages.yml index f767e1b5d..cf3e5fa96 100644 --- a/.github/workflows/docs-pages.yml +++ b/.github/workflows/docs-pages.yml @@ -177,6 +177,10 @@ jobs: ref: ${{ github.event_name == 'release' && github.event.release.tag_name || inputs.ref != '' && inputs.ref || 'main' }} - uses: ./.github/actions/activate-conda + - name: Trust checked-out repository + shell: bash + run: git config --global --add safe.directory "$GITHUB_WORKSPACE" + - name: Restore full multi-version docs site uses: actions/cache/restore@v4 with: diff --git a/tests/ci/test_workflows.py b/tests/ci/test_workflows.py index 98fbdfcc4..5d33f7c0b 100644 --- a/tests/ci/test_workflows.py +++ b/tests/ci/test_workflows.py @@ -44,3 +44,18 @@ def test_automatic_pages_deployment_requires_existing_docs_artifact() -> None: assert deploy_condition.startswith("always() &&") assert "needs.inspect-docs-artifact.outputs.exists == 'true'" in deploy_condition assert "inputs.artifact_run_id != ''" in deploy_condition + + +def test_manual_docs_build_trusts_checkout_before_architecture_generation() -> None: + jobs = _load_workflow("docs-pages.yml")["jobs"] + steps = jobs["build-and-deploy"]["steps"] + step_names = [step.get("name", "") for step in steps] + + trust_index = step_names.index("Trust checked-out repository") + build_index = step_names.index("Build docs site") + trust_command = steps[trust_index]["run"] + + assert trust_index < build_index + assert ( + 'git config --global --add safe.directory "$GITHUB_WORKSPACE"' in trust_command + )