Skip to content

build: bump pyarrow from 25.0.0 to 25.0.1 #1469

build: bump pyarrow from 25.0.0 to 25.0.1

build: bump pyarrow from 25.0.0 to 25.0.1 #1469

Workflow file for this run

name: PR Title Lint
# Repository-side guard on PR titles: bans agent-branded prefixes
# (e.g. `[codex] ...`) and requires a Conventional Commit title. Feature PRs are
# squash-merged, so the title becomes the commit release-please reads on main to
# compute the version + changelog.
#
# Runs on PRs targeting BOTH `main` and `dev` (issue #852). `main` was previously
# exempt on the grounds that a `dev`->`main` promotion PR "carries a
# non-conventional (merge/promotion) title and would always fail this check".
# `make devmain` remains the preferred path and opens the promotion with
# `chore(main): promote dev`, which release-please treats as a no-release type.
# The checker also accepts GitHub's default `Dev` title only when trusted event
# fields identify the exact same-repository `dev` -> `main` branch pair. Every
# other title targeting `main` or `dev` still follows the normal policy.
# `tests/test_pr_title_guard.py` pins the exact exception and its near-misses.
#
# Note the merge-commit subject GitHub writes for a merged promotion
# (`Merge pull request #N from ...`) is NOT a PR title and is not checked here;
# release-please reads the underlying feature commits, not that subject.
#
# Running is not blocking. This workflow reports a check; whether the check is
# required to merge is live branch-protection configuration.
# `.github/branch-protection-baseline.json` records `PR title lint` as required
# on both branches, but that checked-in intent does not enforce the live rules.
#
# The PR title is untrusted event data, read from $GITHUB_EVENT_PATH by the
# checker (never shell-interpolated), the token is read-only, and this uses
# `pull_request` (never `pull_request_target`). Actions are pinned to commit SHAs.
on:
pull_request:
types: [opened, edited, synchronize, reopened]
branches:
- main
- dev
permissions:
contents: read
concurrency:
group: pr-title-lint-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
title-guard:
name: PR title lint
runs-on: ubuntu-latest
steps:
# Check out the BASE ref, not the PR head, so the policy executable is the
# trusted already-merged copy. A PR that edits or removes
# tools/check_pr_title.py must not be able to weaken its own required
# check. The shared validator is still exercised against the PR's own code
# by the test suite in checks.yml.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.base.sha }}
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.12"
- name: Validate PR title
# The checker reads the title from $GITHUB_EVENT_PATH (set automatically
# by the runner). It is stdlib-only, so no dependency install is needed.
run: |
if [ ! -f tools/check_pr_title.py ]; then
echo "::notice::tools/check_pr_title.py is not on the base ref yet; skipping (bootstrap for the PR that introduces the guard). Enforcement is active for every subsequent PR."
exit 0
fi
python tools/check_pr_title.py