diff --git a/.github/workflows/pr-body.yml b/.github/workflows/pr-body.yml index 899d5b7..007f132 100644 --- a/.github/workflows/pr-body.yml +++ b/.github/workflows/pr-body.yml @@ -26,6 +26,12 @@ on: the same as an unset one, so this default stays the one place that value lives. type: string default: "" + deny-branches: + description: >- + ERE; a PR whose head branch matches fails the `branch` job. A generic session name says + nothing about the change, in the PR list or in `git log`. Empty turns the check off. + type: string + default: "^claude/project-thread-" concurrency: group: pr-body-${{ github.event.pull_request.number }} @@ -36,6 +42,20 @@ permissions: pull-requests: write jobs: + branch: + if: github.event.pull_request.state == 'open' + runs-on: ubuntu-latest + timeout-minutes: 1 + steps: + - env: + HEAD_REF: ${{ github.event.pull_request.head.ref }} + DENY: ${{ inputs.deny-branches }} + run: | + if [ -n "$DENY" ] && grep -Eq -- "$DENY" <<<"$HEAD_REF"; then + echo "::error::branch '$HEAD_REF' matches '$DENY': push the work to claude/- (git push -u origin HEAD:claude/-) and open the PR from it" + exit 1 + fi + fill: if: >- github.event.pull_request.head.repo.full_name == github.repository diff --git a/docs/4-reference_workflows.md b/docs/4-reference_workflows.md index bb9bf2f..af58f74 100644 --- a/docs/4-reference_workflows.md +++ b/docs/4-reference_workflows.md @@ -286,6 +286,7 @@ jobs: | `devkit-ref` | *(required)* | pin to the same tag as `uses:` | | `devkit-repo` | `marola-dev/marola-devkit` | | | `umbrella` | `""` | MAROLA_UMBRELLA — resolves a MIP-scoped branch's doc link when this repo carries no `docs/MIPs/` of its own | +| `deny-branches` | `^claude/project-thread-` | ERE: the `branch` job fails a PR whose head branch matches, so a generic session name never reaches review. Empty turns it off | `umbrella` defaults to empty, not `marola-dev/marola`: an empty `MAROLA_UMBRELLA` env var and an unset one are the same thing to `scripts/lib/mip_ref.sh`'s own `${MAROLA_UMBRELLA:-marola-dev/marola}`,