Skip to content

🌱 Bump the k8s-dependencies group across 1 directory with 2 updates #2012

🌱 Bump the k8s-dependencies group across 1 directory with 2 updates

🌱 Bump the k8s-dependencies group across 1 directory with 2 updates #2012

Workflow file for this run

name: file-diff
on:
pull_request:
types: [opened, synchronize, reopened, labeled, unlabeled]
permissions:
contents: read
pull-requests: write
jobs:
check-networkpolicy-changes:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7.0.1
- uses: dorny/paths-filter@v4.0.3
id: filter
with:
list-files: shell
filters: |
networkpolicy:
- 'helm/olmv1/templates/networkpolicy/**'
- name: Comment on PR if NetworkPolicy files changed
if: steps.filter.outputs.networkpolicy == 'true'
continue-on-error: true
uses: marocchino/sticky-pull-request-comment@v3.0.5
with:
header: networkpolicy-changes
message: |
## ⚠️ NetworkPolicy Changes Detected
This PR modifies NetworkPolicy files which affect cluster security.
**Changed files:**
```
${{ steps.filter.outputs.networkpolicy_files }}
```
**Please ensure:**
- These changes are intentional and reviewed carefully
- The OPA policies in `hack/conftest/policy/` are updated accordingly
- The changes have been validated with `make lint-helm`
- After review, a maintainer can apply the `networkpolicy-override` label to allow this check to pass
NetworkPolicy changes require careful review as they affect cluster security.
- name: Check for NetworkPolicy override label
if: steps.filter.outputs.networkpolicy == 'true'
run: |
if gh api repos/$OWNER/$REPO/pulls/$PR --jq '.labels.[].name' | grep -q "${OVERRIDE_LABEL}"; then
echo "Found ${OVERRIDE_LABEL} label, overriding failed results."
else
echo "No ${OVERRIDE_LABEL} label found; NetworkPolicy changes require review."
exit 1
fi
env:
GH_TOKEN: ${{ github.token }}
OWNER: ${{ github.repository_owner }}
REPO: ${{ github.event.repository.name }}
PR: ${{ github.event.pull_request.number }}
OVERRIDE_LABEL: "networkpolicy-override"