Repository navigation
Derive the PR for automations from the triggering run - #5614
Merged
Merged
Conversation
The PR automations workflow identified the pull request and event from JSON files uploaded by the init run and unpacked both archives into its checkout. Resolve the pull request from the workflow_run payload instead, by head repository and branch, and read only the event action and changed groups from the artifacts, copying those entries out by name rather than unpacking the archives. Also give the job read-only default permissions, stop persisting checkout credentials, and gate the automation steps on a resolved pull request. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
obenland
requested review from
dhruvkb and
krysal
and
a lite review from Copilot
and removed request for
a team
September 9, 2026 19:36
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
pr_automations.ymlidentified the pull request and event from JSON files uploaded bypr_automations_init.yml, and unpacked both artifact archives into its checkout ofmain. Since the init run executes pull request code, this changes the handoff so the privileged side derives what it can itself:workflow_runpayload by head repository and branch, matching the run's head SHA where possible.workflow_run.pull_requestsis empty for these runs, so it is not used.pr_automations_init.ymlis unchanged, so runs from branches opened before this lands keep working.Testing Instructions
Open, edit or review a pull request after this is merged and confirm the "PR automations" run resolves the pull request, applies labels, and updates the project board as before. The extraction and resolution steps were exercised locally against good, malformed and ambiguous inputs.
Checklist
Update index.md).main) or a parent feature branch.ov just catalog/generate-docsfor catalogPRs) or the media properties generator (
ov just catalog/generate-docs media-propsfor the catalog or
ov just api/generate-docsfor the API) where applicable.Developer Certificate of Origin
Developer Certificate of Origin
π€ Generated with Claude Code