name: "Check for private emails used in PRs"

on:
  pull_request:
    types:
      - opened

permissions:
  contents: read

jobs:
  validate_email:
    runs-on: ubuntu-24.04
    if: github.repository == 'llvm/llvm-project'
    steps:
      - name: Fetch LLVM sources
        uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
        with:
          ref: ${{ github.event.pull_request.head.sha }}

      - name: Extract author email
        id: author
        run: |
          git log -1
          echo "EMAIL=$(git show -s --format='%ae' HEAD~0)" >> $GITHUB_OUTPUT
          # Create empty comment file
          echo "[]" > comments

      - name: Validate author email
        if: ${{ endsWith(steps.author.outputs.EMAIL, 'noreply.github.com')  }}
        env:
          COMMENT: >-
            ⚠️ We detected that you are using a GitHub private e-mail address to contribute to the repo.<br/>
            Please turn off [Keep my email addresses private](https://github.com/settings/emails) setting in your account.<br/>
            See [LLVM Developer Policy](https://llvm.org/docs/DeveloperPolicy.html#email-addresses) and
            [LLVM Discourse](https://discourse.llvm.org/t/hidden-emails-on-github-should-we-do-something-about-it) for more information.
        run: |
          cat << EOF > comments
          [{"body" : "$COMMENT"}]
          EOF

      - uses: actions/upload-artifact@330a01c490aca151604b8cf639adc76d48f6c5d4 # v5.0.0
        if: always()
        with:
          name: workflow-args
          path: |
            comments