DataBiosphere / azul

Metadata indexer and query service used for AnVIL, HCA, LungMAP, and CGP
Apache License 2.0
7 stars 2 forks source link

Require approval to run GH Actions for every PR by outside collaborator #4054

Closed hannes-ucsc closed 2 years ago

hannes-ucsc commented 2 years ago

It looks like we're only requiring approval for first-time outside contributors. That would mean that once a first PR was approved, subsequent PRs would not. I want to tighten that and require approval for every PR from an outside contributor, not just the first one.

https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#configuring-required-approval-for-workflows-from-public-forks

Originally posted by @hannes-ucsc in https://github.com/DataBiosphere/azul/issues/4012#issuecomment-1089299018

We need to do this for every repository we maintain.

hannes-ucsc commented 2 years ago

I inventoried all of our repositories and tagged them with the boardwalk topic so we can easily filter them:

Currently this gives

The check boxes track my progress adjusting the permissions.