Skip to content

ci: skip integration/otel tests for external pull requests - #728

Merged
hln33 merged 1 commit into
aws:mainfrom
hln33:main
Sep 18, 2026
Merged

hln33 merged 1 commit into
aws:mainfrom
hln33:main

Conversation

@hln33

@hln33 hln33 commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Issue #, if available:
N/A

Description of changes:

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@hln33
hln33 marked this pull request as ready for review September 15, 2026 17:29
@hln33
hln33 deployed to ai-pr-review-runtime September 15, 2026 17:29 — with GitHub Actions Active
@hln33
hln33 force-pushed the main branch 3 times, most recently from 18ddf77 to 5993b13 Compare September 17, 2026 16:38
@hln33
hln33 merged commit 2f530ee into aws:main Sep 18, 2026
17 of 18 checks passed
hln33 added a commit to aws/aws-durable-execution-sdk-js that referenced this pull request Sep 24, 2026
Issue #, if available: N/A

## Description of changes

Skip both conformance workflows for pull requests from forks and from
Dependabot.

`conformance-tests.yml` and `otel-conformance-tests.yml` are triggered
directly by `pull_request` (not called from `build.yml`) and both
consume secrets — `TEST_ROLE_ARN`, `TEST_LAMBDA_EXECUTION_ROLE_ARN`, and
the OTel backend tokens. A fork PR that touches
`packages/aws-durable-execution-sdk-js/**` therefore starts a run that
cannot authenticate and fails on an empty secret.

`build.yml` already guards `integration-tests` and
`capacity-provider-tests` the same way (`build.yml:143-146`,
`:161-164`); this extends that to the two conformance workflows, using
the wording the Python SDK settled on in
aws/aws-durable-execution-sdk-python#728 so the repos read identically.

The guard goes on the root job of each workflow — `discover_suites` and
`opentelemetry`. The conformance matrix has `needs: discover_suites`, so
the skip cascades without a second copy of the condition.

```yaml
if: github.event_name != 'pull_request' || (github.actor != 'dependabot[bot]' && github.event.pull_request.head.repo.full_name == github.repository)
```

`push` to main and `workflow_dispatch` runs are unaffected by the first
clause, and the condition is a no-op for same-repo branches, so
maintainer PRs keep full conformance signal.

By submitting this pull request, I confirm that you can use, modify,
copy, and redistribute this contribution, under the terms of your
choice.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants