From 48cb24c5b82a6e73e787c9589ca6aec741ab24d2 Mon Sep 17 00:00:00 2001 From: Jonathan Hess Date: Fri, 25 Sep 2026 17:09:50 +0000 Subject: [PATCH] ci: add multi-approvers GitHub Actions workflow Add the multi-approvers workflow using abcxyz/actions to enforce the two-person code review requirement for external contributions in accordance with go/github-bermuda. --- .github/workflows/multi-approvers.yaml | 52 ++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) create mode 100644 .github/workflows/multi-approvers.yaml diff --git a/.github/workflows/multi-approvers.yaml b/.github/workflows/multi-approvers.yaml new file mode 100644 index 00000000..c58102e4 --- /dev/null +++ b/.github/workflows/multi-approvers.yaml @@ -0,0 +1,52 @@ +# Copyright 2026 Google LLC +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# https://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +name: 'multi-approvers' + +on: + # zizmor: ignore[dangerous-triggers] - {Multi-approver check runs in base context without checking out untrusted code} + pull_request_target: + types: + - 'opened' + - 'edited' + - 'reopened' + - 'synchronize' + - 'ready_for_review' + - 'review_requested' + - 'review_request_removed' + pull_request_review: + types: + - 'submitted' + - 'dismissed' + +permissions: + actions: 'write' + contents: 'read' + id-token: 'write' + pull-requests: 'read' + +concurrency: + group: '${{ github.workflow }}-${{ github.head_ref || github.ref }}' + cancel-in-progress: true + +jobs: + multi-approvers: + runs-on: 'ubuntu-latest' + steps: + - name: 'Multi-approvers' + uses: 'abcxyz/actions/.github/actions/multi-approvers@7c003a22a2308639325a29f9d4f4ff60781f6ce1' # main + with: + team: 'googlers' + token: '${{ secrets.MULTI_APPROVERS_TOKEN }}' + user-id-allowlist: '25180681,55107282,122572305,78513119,49699333,70984784,44816363,205009765,56741989,224858768,104649659'