feat(action): trust-check/validate-source-branch - Validate PR source branch
- Dominant language
- Shell
- Stars
- 0
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
## Parent Epic
Part of #22 (Atomic Release Pipeline Actions)
## Priority
P2 - Security validation for W5
## Description
Create a composite action that validates a PR's source branch matches an expected pattern.
Used to enforce that PRs to protected branches come from expected source branches.
## Inputs
| Input | Required | Default | Description |
|-------|----------|---------|-------------|
| `source-branch` | Yes | - | The source branch of the PR |
| `allowed-pattern` | Yes | - | Allowed branch pattern (glob supported) |
## Outputs
| Output | Description |
|--------|-------------|
| `valid` | "true" if branch matches pattern |
| `pattern-matched` | The pattern that matched (for multiple patterns) |
## Usage Example
```yaml
# Single pattern
- uses: arustydev/gha/actions/trust-check/validate-source-branch@v1
with:
source-branch: ${{ github.head_ref }}
allowed-pattern: "charts/*"
# Multiple patterns (comma-separated)
- uses: arustydev/gha/actions/trust-check/validate-source-branch@v1
with:
source-branch: ${{ github.head_ref }}
allowed-pattern: "charts/*,hotfix/*,release/*"
```
## Source Reference
`helm-charts/.github/scripts/attestation-lib.sh`:
- `validate_source_branch()` (lines 296-314)
## Implementation Notes
- Support glob patterns (e.g., `charts/*`)
- Support multiple patterns (comma-separated)
- Fail with clear error message on mismatch
Contributor guide
Assessment
This issue has not been assessed yet.