Skip to content

docs: ACCOUNTS.md lists dev balances as ETH, and the amount is off by 100x #127

docs: ACCOUNTS.md lists dev balances as ETH, and the amount is off by 100x

docs: ACCOUNTS.md lists dev balances as ETH, and the amount is off by 100x #127

# SECURITY: This workflow uses pull_request_target. Do NOT add actions/checkout

Check warning on line 1 in .github/workflows/label-external-prs.yml

View workflow run for this annotation

GitHub Actions / Label External PRs for Import

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
# with a PR-controlled ref: that would execute attacker code with write access
# to secrets. Only read pull_request metadata.
name: Label External PRs for Import
on:
pull_request_target:
types: [closed]
branches: [main]
permissions:
pull-requests: write
concurrency:
group: label-external-pr-${{ github.event.pull_request.number }}
cancel-in-progress: false
# Partial cancellation could leave a PR unlabeled; label application is
# idempotent so letting both runs finish is safe.
jobs:
label:
# Skip unmerged closes and the automated upstream-sync squash PRs.
# Bot author AND sync branch are both checked as belt-and-suspenders;
# either alone is sufficient to identify a sync PR.
if: >-
github.repository == 'circlefin/arc-node' &&
github.event.pull_request.merged == true &&
!(github.event.pull_request.user.login == 'circle-github-action-bot' &&
github.event.pull_request.head.ref == 'sync/copybara-export')
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Apply pending-import label
env:
GH_TOKEN: ${{ github.token }}
PR_NUMBER: ${{ github.event.pull_request.number }}
REPO: ${{ github.repository }}
run: |
set -euo pipefail
gh pr edit "${PR_NUMBER}" --repo "${REPO}" --add-label pending-import