Skip to content

Derive the PR for automations from the triggering run - #5614

Merged
obenland merged 1 commit into
mainfrom
ci/pr-automations-handoff
Sep 9, 2026
Merged

obenland merged 1 commit into
mainfrom
ci/pr-automations-handoff

Conversation

@obenland

@obenland obenland commented Sep 9, 2026

Copy link
Copy Markdown
Member

Description

pr_automations.yml identified the pull request and event from JSON files uploaded by pr_automations_init.yml, and unpacked both artifact archives into its checkout of main. Since the init run executes pull request code, this changes the handoff so the privileged side derives what it can itself:

  • The pull request is resolved from the workflow_run payload by head repository and branch, matching the run's head SHA where possible. workflow_run.pull_requests is empty for these runs, so it is not used.
  • Only the event action and changed groups are read from the artifacts, by copying the one expected entry out of each archive rather than unpacking it, and both values are validated before use.
  • The job gets read-only default permissions, the checkout no longer persists credentials, and the two automation steps only run once the pull request is resolved.

pr_automations_init.yml is unchanged, so runs from branches opened before this lands keep working.

Testing Instructions

Open, edit or review a pull request after this is merged and confirm the "PR automations" run resolves the pull request, applies labels, and updates the project board as before. The extraction and resolution steps were exercised locally against good, malformed and ambiguous inputs.

Checklist

  • My pull request has a descriptive title (not a vague title likeUpdate index.md).
  • My pull request targets the default branch of the repository (main) or a parent feature branch.
  • My commit messages follow best practices.
  • My code follows the established code style of the repository.
  • I added or updated tests for the changes I made (if applicable).
  • I added or updated documentation (if applicable).
  • I tried running the project locally and verified that there are no visible errors.
  • I ran the DAG documentation generator (ov just catalog/generate-docs for catalog
    PRs) or the media properties generator (ov just catalog/generate-docs media-props
    for the catalog or ov just api/generate-docs for the API) where applicable.

Developer Certificate of Origin

Developer Certificate of Origin
Developer Certificate of Origin
Version 1.1

Copyright (C) 2004, 2006 The Linux Foundation and its contributors.
1 Letterman Drive
Suite D4700
San Francisco, CA, 94129

Everyone is permitted to copy and distribute verbatim copies of this
license document, but changing it is not allowed.


Developer's Certificate of Origin 1.1

By making a contribution to this project, I certify that:

(a) The contribution was created in whole or in part by me and I
    have the right to submit it under the open source license
    indicated in the file; or

(b) The contribution is based upon previous work that, to the best
    of my knowledge, is covered under an appropriate open source
    license and I have the right under that license to submit that
    work with modifications, whether created in whole or in part
    by me, under the same open source license (unless I am
    permitted to submit under a different license), as indicated
    in the file; or

(c) The contribution was provided directly to me by some other
    person who certified (a), (b) or (c) and I have not modified
    it.

(d) I understand and agree that this project and the contribution
    are public and that a record of the contribution (including all
    personal information I submit with it, including my sign-off) is
    maintained indefinitely and may be redistributed consistent with
    this project or the open source license(s) involved.

πŸ€– Generated with Claude Code

The PR automations workflow identified the pull request and event from
JSON files uploaded by the init run and unpacked both archives into its
checkout. Resolve the pull request from the workflow_run payload instead,
by head repository and branch, and read only the event action and changed
groups from the artifacts, copying those entries out by name rather than
unpacking the archives. Also give the job read-only default permissions,
stop persisting checkout credentials, and gate the automation steps on a
resolved pull request.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@obenland
obenland requested a review from a team as a code owner September 9, 2026 19:36
@obenland
obenland requested review from dhruvkb and krysal and a lite review from Copilot and removed request for a team September 9, 2026 19:36

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@openverse-bot openverse-bot added 🧱 stack: mgmt Related to repo management and automations 🚦 status: awaiting triage Has not been triaged & therefore, not ready for work labels Sep 9, 2026
@openverse-bot openverse-bot moved this to πŸ‘€ Needs Review in Openverse PRs Sep 9, 2026
@obenland obenland added πŸ’» aspect: code Concerns the software code in the repository 🧰 goal: internal improvement Improvement that benefits maintainers, not users 🟨 priority: medium Not blocking but should be addressed soon πŸ”§ tech: github actions Involves Github Actions labels Sep 9, 2026
@obenland
obenland merged commit 4ab0586 into main Sep 9, 2026
68 of 78 checks passed
@obenland
obenland deleted the ci/pr-automations-handoff branch September 9, 2026 19:42
@github-project-automation github-project-automation Bot moved this from πŸ‘€ Needs Review to 🀝 Merged in Openverse PRs Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

πŸ’» aspect: code Concerns the software code in the repository 🧰 goal: internal improvement Improvement that benefits maintainers, not users 🟨 priority: medium Not blocking but should be addressed soon 🧱 stack: mgmt Related to repo management and automations 🚦 status: awaiting triage Has not been triaged & therefore, not ready for work πŸ”§ tech: github actions Involves Github Actions

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

3 participants