[llvm] workflows: Add require-release-manager composite action (PR #194758)
Tom Stellard via llvm-commits
llvm-commits at lists.llvm.org
Wed Apr 29 07:36:50 PDT 2026
https://github.com/tstellar updated https://github.com/llvm/llvm-project/pull/194758
>From 05dc342236746300a377d5d5aea1df6e4c7f218c Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Tue, 28 Apr 2026 11:16:56 -0700
Subject: [PATCH 1/5] workflows: Add require-release-manager composite action
This action checks that the workflow was started by someone in the
llvm-release-managers team. This is meant to replace the existing
checks which use a python script and will help to consolidate the
access token generation into a single place.
Also start using it in the release-binaries workflow.
---
.github/workflows/release-binaries.yml | 22 +++---------
.../require-release-manager/action.yml | 35 +++++++++++++++++++
2 files changed, 40 insertions(+), 17 deletions(-)
create mode 100644 .github/workflows/require-release-manager/action.yml
diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index 1ea01738d75b7..cb77a32a50195 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -50,6 +50,7 @@ permissions:
jobs:
prepare:
name: Prepare to build binaries
+ environment: release
runs-on: ${{ inputs.runs-on }}
if: github.repository_owner == 'llvm'
outputs:
@@ -65,12 +66,6 @@ jobs:
attestation-name: ${{ steps.vars.outputs.attestation-name }}
steps:
- # It's good practice to use setup-python, but this is also required on macos-14
- # due to https://github.com/actions/runner-images/issues/10385
- - uses: actions/setup-python at a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
- with:
- python-version: '3.14'
-
- name: Install Windows ARM64 dependencies
if: runner.os == 'Windows' && runner.arch == 'ARM64'
run: |
@@ -83,19 +78,12 @@ jobs:
with:
persist-credentials: false
- - name: Install Dependencies
- shell: bash
- run: |
- pip install --require-hashes -r ./llvm/utils/git/requirements.txt
-
- name: Check Permissions
if: github.event_name != 'pull_request'
- env:
- GITHUB_TOKEN: ${{ github.token }}
- USER_TOKEN: ${{ secrets.RELEASE_TASKS_USER_TOKEN }}
- shell: bash
- run: |
- ./llvm/utils/release/./github-upload-release.py --token "$GITHUB_TOKEN" --user "$GITHUB_ACTOR" --user-token "$USER_TOKEN" check-permissions
+ uses: ./.github/workflows/require-release-manager
+ with:
+ LLVM_TOKEN_GENERATOR_CLIENT_ID: ${{ secrets.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+ LLVM_TOKEN_GENERATOR_PRIVATE_KEY: ${{ secrets.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
# The name of the Windows binaries uses the version from source, so we need
# to fetch it here.
diff --git a/.github/workflows/require-release-manager/action.yml b/.github/workflows/require-release-manager/action.yml
new file mode 100644
index 0000000000000..520b2d02693a3
--- /dev/null
+++ b/.github/workflows/require-release-manager/action.yml
@@ -0,0 +1,35 @@
+name: Require Release Manager
+description: >-
+ This checks to make sure the person that initiated the workflow is a
+ release manager.
+inputs:
+ LLVM_TOKEN_GENERATOR_CLIENT_ID:
+ description: >-
+ Client ID for generating access tokens.
+ required: true
+ LLVM_TOKEN_GENERATOR_PRIVATE_KEY:
+ description: >-
+ Private key for generating access tokens
+ required: true
+
+runs:
+ using: "composite"
+ steps:
+ - id: app-token
+ uses: actions/create-github-app-token at 1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1
+ with:
+ app-id: ${{ inputs.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+ private-key: ${{ inputs.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
+ owner: ${{ github.repository_owner }}
+ permission-members: read
+
+ - name: Check Permissions
+ uses: actions/github-script at 3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
+ with:
+ github-token: ${{ steps.app-token.outputs.token }}
+ script: |
+ await github.rest.teams.getMembershipForUserInOrg({
+ org: context.repo.owner,
+ team_slug: "llvm-release-managers"
+ username: context.actor
+ });
>From cfbb00258931bc2789206b699f9b998dd4916cfa Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Wed, 29 Apr 2026 07:12:46 -0700
Subject: [PATCH 2/5] fix environment
---
.github/workflows/release-binaries.yml | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index cb77a32a50195..af25c04bdfee7 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -50,7 +50,9 @@ permissions:
jobs:
prepare:
name: Prepare to build binaries
- environment: release
+ environment:
+ deployment: false
+ environment: ${{ case( github.event_name == 'pull_request', null, 'release') }}
runs-on: ${{ inputs.runs-on }}
if: github.repository_owner == 'llvm'
outputs:
>From 94d516309661c9c948b6e135b70c9e2456cf643c Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Wed, 29 Apr 2026 07:30:53 -0700
Subject: [PATCH 3/5] Fix name
---
.github/workflows/release-binaries.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/.github/workflows/release-binaries.yml b/.github/workflows/release-binaries.yml
index af25c04bdfee7..feab47e50583a 100644
--- a/.github/workflows/release-binaries.yml
+++ b/.github/workflows/release-binaries.yml
@@ -52,7 +52,7 @@ jobs:
name: Prepare to build binaries
environment:
deployment: false
- environment: ${{ case( github.event_name == 'pull_request', null, 'release') }}
+ name: ${{ case( github.event_name == 'pull_request', null, 'release') }}
runs-on: ${{ inputs.runs-on }}
if: github.repository_owner == 'llvm'
outputs:
>From c7cd2d01c4f74c342174942c2669780a550e95f7 Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Wed, 29 Apr 2026 07:33:35 -0700
Subject: [PATCH 4/5] Fix secrets
---
.github/workflows/release-binaries-all.yml | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/.github/workflows/release-binaries-all.yml b/.github/workflows/release-binaries-all.yml
index 5a775082f4586..5186aee028051 100644
--- a/.github/workflows/release-binaries-all.yml
+++ b/.github/workflows/release-binaries-all.yml
@@ -78,6 +78,9 @@ jobs:
release-binaries-all:
name: Build Release Binaries
+ environment:
+ deployment: false
+ name: ${{ case( github.event_name == 'pull_request', null, 'release') }}
needs:
- setup-variables
permissions:
@@ -102,7 +105,8 @@ jobs:
upload: ${{ needs.setup-variables.outputs.upload == 'true'}}
runs-on: "${{ matrix.runs-on }}"
secrets:
- # This will be empty for pull_request events, but that's fine, because
- # the release-binaries workflow does not use this secret for the
+ # These will be empty for pull_request events, but that's fine, because
+ # the release-binaries workflow does not use these secrets for the
# pull_request event.
- RELEASE_TASKS_USER_TOKEN: ${{ secrets.RELEASE_TASKS_USER_TOKEN }}
+ LLVM_TOKEN_GENERATOR_CLIENT_ID: ${{ secrets.LLVM_TOKEN_GENERATOR_CLIENT_ID }}
+ LLVM_TOKEN_GENERATOR_PRIVATE_KEY: ${{ secrets.LLVM_TOKEN_GENERATOR_PRIVATE_KEY }}
>From 395ff77c17028819932cce15b4409571bca3a7b7 Mon Sep 17 00:00:00 2001
From: Tom Stellard <tstellar at redhat.com>
Date: Wed, 29 Apr 2026 07:36:27 -0700
Subject: [PATCH 5/5] Remove environment from caller
---
.github/workflows/release-binaries-all.yml | 3 ---
1 file changed, 3 deletions(-)
diff --git a/.github/workflows/release-binaries-all.yml b/.github/workflows/release-binaries-all.yml
index 5186aee028051..d331d2699f4cb 100644
--- a/.github/workflows/release-binaries-all.yml
+++ b/.github/workflows/release-binaries-all.yml
@@ -78,9 +78,6 @@ jobs:
release-binaries-all:
name: Build Release Binaries
- environment:
- deployment: false
- name: ${{ case( github.event_name == 'pull_request', null, 'release') }}
needs:
- setup-variables
permissions:
More information about the llvm-commits
mailing list