build: bump pyarrow from 25.0.0 to 25.0.1 #1469
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: PR Title Lint | |
| # Repository-side guard on PR titles: bans agent-branded prefixes | |
| # (e.g. `[codex] ...`) and requires a Conventional Commit title. Feature PRs are | |
| # squash-merged, so the title becomes the commit release-please reads on main to | |
| # compute the version + changelog. | |
| # | |
| # Runs on PRs targeting BOTH `main` and `dev` (issue #852). `main` was previously | |
| # exempt on the grounds that a `dev`->`main` promotion PR "carries a | |
| # non-conventional (merge/promotion) title and would always fail this check". | |
| # `make devmain` remains the preferred path and opens the promotion with | |
| # `chore(main): promote dev`, which release-please treats as a no-release type. | |
| # The checker also accepts GitHub's default `Dev` title only when trusted event | |
| # fields identify the exact same-repository `dev` -> `main` branch pair. Every | |
| # other title targeting `main` or `dev` still follows the normal policy. | |
| # `tests/test_pr_title_guard.py` pins the exact exception and its near-misses. | |
| # | |
| # Note the merge-commit subject GitHub writes for a merged promotion | |
| # (`Merge pull request #N from ...`) is NOT a PR title and is not checked here; | |
| # release-please reads the underlying feature commits, not that subject. | |
| # | |
| # Running is not blocking. This workflow reports a check; whether the check is | |
| # required to merge is live branch-protection configuration. | |
| # `.github/branch-protection-baseline.json` records `PR title lint` as required | |
| # on both branches, but that checked-in intent does not enforce the live rules. | |
| # | |
| # The PR title is untrusted event data, read from $GITHUB_EVENT_PATH by the | |
| # checker (never shell-interpolated), the token is read-only, and this uses | |
| # `pull_request` (never `pull_request_target`). Actions are pinned to commit SHAs. | |
| on: | |
| pull_request: | |
| types: [opened, edited, synchronize, reopened] | |
| branches: | |
| - main | |
| - dev | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: pr-title-lint-${{ github.event.pull_request.number }} | |
| cancel-in-progress: true | |
| jobs: | |
| title-guard: | |
| name: PR title lint | |
| runs-on: ubuntu-latest | |
| steps: | |
| # Check out the BASE ref, not the PR head, so the policy executable is the | |
| # trusted already-merged copy. A PR that edits or removes | |
| # tools/check_pr_title.py must not be able to weaken its own required | |
| # check. The shared validator is still exercised against the PR's own code | |
| # by the test suite in checks.yml. | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| ref: ${{ github.event.pull_request.base.sha }} | |
| - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: "3.12" | |
| - name: Validate PR title | |
| # The checker reads the title from $GITHUB_EVENT_PATH (set automatically | |
| # by the runner). It is stdlib-only, so no dependency install is needed. | |
| run: | | |
| if [ ! -f tools/check_pr_title.py ]; then | |
| echo "::notice::tools/check_pr_title.py is not on the base ref yet; skipping (bootstrap for the PR that introduces the guard). Enforcement is active for every subsequent PR." | |
| exit 0 | |
| fi | |
| python tools/check_pr_title.py |