name: Label Automated PR on: # zizmor: ignore[dangerous-triggers] # Information from the PR is used only inside builtin `contains` function, it's not passed down as untrusted code. pull_request_target: types: [opened, reopened] permissions: {} concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number }} cancel-in-progress: true jobs: agentscan: runs-on: ubuntu-slim # run only for our repo and ignore PRs from origin that only maintainers can do # also ignore known bots if: | github.repository == 'vitest-dev/vitest' && github.event.pull_request.head.repo.full_name != github.repository && !contains( fromJSON('["dependabot[bot]","github-actions[bot]","sheremet-va","hi-ogawa","AriPerkkio","macarie","antfu","userquin","patak-cat"]'), github.event.pull_request.user.login ) name: AgentScan Alert permissions: pull-requests: write # comment, label and close PRs steps: - name: AgentScan id: agentscan uses: MatteoGabriele/agentscan-action@8112fb79b33fafb8506159df20129a34209ac410 # v2.5.0 with: github-token: ${{ secrets.GITHUB_TOKEN }} # the `labels` mode also labels accounts with mixed signals, # only maintainers add the `maybe automated` label mode: silent trusted-author-associations: 'owner, collaborator, member' # if the account is confirmed to be a bot, just close the PR - name: Close flagged accounts if: steps.agentscan.outputs.community-flagged == 'true' || steps.agentscan.outputs.classification == 'automation' uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: INPUT_BODY: | Your account has been [automatically flagged](https://agentscan.tools/user/${{ github.event.pull_request.user.login }}) as likely to be created by a bot, LLM, or agent, and will be automatically closed. If you believe this is a mistake, please reply to this comment and we will review it. *These measures help us reduce maintenance burden and keep the team's work efficient. See our [AI contributions policy](https://github.com/vitest-dev/vitest/blob/main/CONTRIBUTING.md#ai-contributions) for more context.* with: script: | const prNumber = context.payload.pull_request.number; await github.rest.issues.addLabels({ owner: context.repo.owner, repo: context.repo.repo, issue_number: prNumber, labels: ['bot'], }) await github.rest.issues.createComment({ owner: context.repo.owner, repo: context.repo.repo, issue_number: prNumber, body: process.env.INPUT_BODY, }) await github.rest.pulls.update({ owner: context.repo.owner, repo: context.repo.repo, pull_number: prNumber, state: 'closed', });