c87eb79140ac359cf4f71604ddbf7209e1282939

Author
Marc Cornellà <marc@mcornella.com>
Committer
GitHub <noreply@github.com>
Date

Message

feat(cli): only allow `omz pr test` on PRs with `testers needed` label (#13238)

Diff

 1diff --git a/lib/cli.zsh b/lib/cli.zsh
 2index 0b144e4e786e292c476b13c2340ebc0cdbabb78a..a002a5073dfd33b25e90537a7970b221dd74d4b0 100644
 3--- a/lib/cli.zsh
 4+++ b/lib/cli.zsh
 5@@ -621,10 +621,48 @@ function _omz::pr::test {
 6     done
 7 
 8     (( $found )) || {
 9-      _omz::log error "could not found the ohmyzsh git remote. Aborting..."
10+      _omz::log error "could not find the ohmyzsh git remote. Aborting..."
11       return 1
12     }
13 
14+    # Check if Pull Request has the "testers needed" label
15+    _omz::log info "checking if PR #$1 has the 'testers needed' label..."
16+    local pr_json label label_id="MDU6TGFiZWw4NzY1NTkwNA=="
17+    pr_json=$(
18+      curl -fsSL \
19+        -H "Accept: application/vnd.github+json" \
20+        -H "X-GitHub-Api-Version: 2022-11-28" \
21+        "https://api.github.com/repos/ohmyzsh/ohmyzsh/pulls/$1"
22+    )
23+
24+    if [[ $? -gt 0 || -z "$pr_json" ]]; then
25+      _omz::log error "error when trying to fetch PR #$1 from GitHub."
26+      return 1
27+    fi
28+
29+    # Check if the label is present with jq or grep
30+    if (( $+commands[jq] )); then
31+      label="$(command jq ".labels.[] | select(.node_id == \"$label_id\")" <<< "$pr_json")"
32+    else
33+      label="$(command grep "\"$label_id\"" <<< "$pr_json" 2>/dev/null)"
34+    fi
35+
36+    # If a maintainer hasn't labeled the PR to test, explain the security risk
37+    if [[ -z "$label" ]]; then
38+      _omz::log warn "PR #$1 does not have the 'testers needed' label. This means that the PR"
39+      _omz::log warn "has not been reviewed by a maintainer and may contain malicious code."
40+
41+      # Ask for explicit confirmation: user needs to type "yes" to continue
42+      _omz::log prompt "Do you want to continue testing it? [yes/N] "
43+      builtin read -r
44+      if [[ "${REPLY:l}" != yes ]]; then
45+        _omz::log error "PR test canceled. Please ask a maintainer to review and label the PR."
46+        return 1
47+      else
48+        _omz::log warn "Continuing to check out and test PR #$1. Be careful!"
49+      fi
50+    fi
51+
52     # Fetch pull request head
53     _omz::log info "fetching PR #$1 to ohmyzsh/pull-$1..."
54     command git fetch -f "$remote" refs/pull/$1/head:ohmyzsh/pull-$1 || {