Skip to content

chore(workflows): update issue label and preview gate - #8341

Merged
wise-king-sullyman merged 2 commits into
patternfly:mainfrom
nicolethoen:update_gh_actions
May 19, 2026
Merged

wise-king-sullyman merged 2 commits into
patternfly:mainfrom
nicolethoen:update_gh_actions

Conversation

@nicolethoen

@nicolethoen nicolethoen commented Apr 28, 2026 •

Copy link
Copy Markdown
Contributor

Replace repo-specific issue labeling with org reusable workflow and gate Surge preview publishing behind the org team-membership check.

Made-with: Cursor

Summary by CodeRabbit

  • Chores
    • Removed an older automated issue-processing workflow.
    • Added a new workflow to automatically apply the "PF Team" label to newly opened issues.
    • Updated PR preview pipeline to also respond to new issue comments, add a permission check step, and gate preview builds based on that check.

Replace repo-specific issue labeling with org reusable workflow and gate
Surge preview publishing behind the org team-membership check.

Made-with: Cursor
@coderabbitai

coderabbitai Bot commented Apr 28, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 911a4f2b-a67a-429a-9fe4-e7fbdcc6a0f4

📥 Commits

Reviewing files that changed from the base of the PR and between 7f27de7 and 587183f.

📒 Files selected for processing (2)
  • .github/workflows/label-pf-team-issue.yml
  • .github/workflows/pr-preview.yml
✅ Files skipped from review due to trivial changes (1)
  • .github/workflows/label-pf-team-issue.yml

Walkthrough

Deletes an old issue-to-project workflow, adds a new issue-labeling workflow that calls a reusable external workflow, and updates the PR preview workflow to accept issue_comment events and gate build-upload behind a permissions check job.

Changes

Cohort / File(s) Summary
Issue workflow removal
.github/workflows/add-new-issues-to-project.yml
Deleted legacy workflow that added new issues to a project board and checked team membership to apply the PF Team label.
Issue labeling (new)
.github/workflows/label-pf-team-issue.yml
Added a new workflow Label PF Team issues that triggers on issues.opened and delegates labeling to a pinned reusable workflow (patternfly/.../add-pf-team-label-workflow.yml) with secrets: inherit.
PR preview workflow
.github/workflows/pr-preview.yml
Expanded triggers to include issue_comment (created) alongside pull_request_target. Added check-permissions job (reusable workflow) and made build-upload depend on it and run only when needs.check-permissions.outputs.allowed == 'true'. Updated GH_PR_NUM to use needs.check-permissions.outputs.pr-number.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title follows conventional commit format with 'chore' type and descriptive subject about workflow updates.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 7/8 reviews remaining, refill in 7 minutes and 30 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@patternfly-build

patternfly-build commented Apr 28, 2026 •

Copy link
Copy Markdown
Collaborator

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (1)
.github/workflows/pr-preview.yml (1)

9-9: Pin the reusable workflow to a commit SHA instead of @main.

Using a moving branch ref can introduce unreviewed behavior changes into this workflow.

Suggested change
-    uses: patternfly/.github/.github/workflows/check-team-membership.yml@main
+    uses: patternfly/.github/.github/workflows/check-team-membership.yml@<commit-sha>
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/pr-preview.yml at line 9, Replace the moving branch ref in
the reusable workflow call by pinning the `uses:
patternfly/.github/.github/workflows/check-team-membership.yml@main` reference
to an exact commit SHA: find the commit SHA you want to lock to in the
patternfly/.github repository, then update the `uses:` value to
`patternfly/.github/.github/workflows/check-team-membership.yml@<commit-sha>`
(replace <commit-sha> with the actual full SHA) so the workflow invocation is
pinned to a fixed revision.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/label-pf-team-issue.yml:
- Line 8: The workflow invocation currently references a mutable branch ref
"patternfly/.github/.github/workflows/add-pf-team-label-workflow.yml@main";
replace the branch ref with the full commit SHA of the desired pinned revision
(e.g., change "@main" to "@<full-commit-sha>"). Locate the uses line in the
workflow (the uses:
patternfly/.github/.github/workflows/add-pf-team-label-workflow.yml@main entry)
and update it to the exact commit SHA from the patternfly repo commit you want
to pin, then commit that change so the reusable workflow is immutable and
reproducible.

In @.github/workflows/pr-preview.yml:
- Around line 3-13: Confirm that the external reusable workflow referenced by
the uses string
"patternfly/.github/.github/workflows/check-team-membership.yml@main" actually
exists in the patternfly/.github repository and, if it does not, either create
that workflow there or update the uses value to the correct repository/path/tag;
update the "check-permissions" job to point to the valid reusable workflow and
ensure the "build-upload" job's if condition (which depends on
needs.check-permissions.outputs.allowed) remains consistent with the chosen
permission-check workflow.

---

Nitpick comments:
In @.github/workflows/pr-preview.yml:
- Line 9: Replace the moving branch ref in the reusable workflow call by pinning
the `uses: patternfly/.github/.github/workflows/check-team-membership.yml@main`
reference to an exact commit SHA: find the commit SHA you want to lock to in the
patternfly/.github repository, then update the `uses:` value to
`patternfly/.github/.github/workflows/check-team-membership.yml@<commit-sha>`
(replace <commit-sha> with the actual full SHA) so the workflow invocation is
pinned to a fixed revision.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: e1413daf-1f5f-45b0-a1ee-5d62a5189a5a

📥 Commits

Reviewing files that changed from the base of the PR and between 9b2758d and 7f27de7.

📒 Files selected for processing (3)
  • .github/workflows/add-new-issues-to-project.yml
  • .github/workflows/label-pf-team-issue.yml
  • .github/workflows/pr-preview.yml
💤 Files with no reviewable changes (1)
  • .github/workflows/add-new-issues-to-project.yml

Comment thread .github/workflows/label-pf-team-issue.yml Outdated
Comment on lines +3 to +13
on:
issue_comment:
types: [created]
pull_request_target:
jobs:
check-permissions:
uses: patternfly/.github/.github/workflows/check-team-membership.yml@main
secrets: inherit
build-upload:
needs: check-permissions
if: needs.check-permissions.outputs.allowed == 'true'

@coderabbitai coderabbitai Bot Apr 28, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Verify the called reusable workflow's event handling and outputs
url="https://raw.githubusercontent.com/patternfly/.github/main/.github/workflows/check-team-membership.yml"
tmp="$(mktemp)"
curl -fsSL "$url" -o "$tmp"

echo "== Triggers =="
rg -n '^\s*(on:|issue_comment:|pull_request:|pull_request_target:|workflow_call:|types:)' "$tmp" -A2 -B1 || true

echo "== Declared outputs =="
rg -n 'outputs:|allowed|pr-number' "$tmp" -A4 -B2 || true

echo "== Event guards =="
rg -n 'github\.event\.issue\.pull_request|github\.event_name|^\s*if:' "$tmp" -A2 -B2 || true

Repository: patternfly/patternfly

Length of output: 1808


🌐 Web query:

patternfly/.github check-team-membership.yml workflow

💡 Result:

No evidence found of a file named check-team-membership.yml in patternfly/.github or any PatternFly repositories. PatternFly repositories like patternfly/patternfly and patternfly/patternfly-react have .github/workflows directories containing files such as release.yml, documentation.yml, and pr-preview, but no check-team-membership.yml. PatternFly-quickstarts and patternfly/react-topology use team membership checker actions (e.g., TheModdingInquisition/actions-team-membership) in workflows like add-to-project.yml and extensions.yml, referencing team: 'frequent-flyers'. General GitHub Actions for team membership checks exist (e.g., tspascoal/get-user-teams-membership), but no exact match for the specified file in PatternFly.

Citations:


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Try to fetch the reusable workflow directly
tmp="$(mktemp)"
if curl -fsSL "https://raw.githubusercontent.com/patternfly/.github/main/.github/workflows/check-team-membership.yml" -o "$tmp" 2>/dev/null; then
    echo "=== Workflow retrieved successfully ==="
    cat "$tmp"
else
    echo "Failed to retrieve workflow, attempting alternative method..."
    # If curl fails, provide diagnostic info
    echo "Curl failed to retrieve workflow from GitHub"
fi

Repository: patternfly/patternfly

Length of output: 1893


Verify the external reusable workflow path before merging.

The suggested PR-only guard (github.event_name == 'pull_request_target' || github.event.issue.pull_request != null) is a valid best practice for filtering issue comments to PR-only contexts. However, the external reusable workflow patternfly/.github/.github/workflows/check-team-membership.yml could not be found in the patternfly/.github repository. Verify that this workflow exists at the specified path and location, or reference the correct workflow used by your team for permission checks. If this workflow doesn't exist yet, it will need to be created in the referenced repository before this change can work.

Suggested change (pending verification of external workflow)
 jobs:
   check-permissions:
+    if: ${{ github.event_name == 'pull_request_target' || github.event.issue.pull_request != null }}
     uses: patternfly/.github/.github/workflows/check-team-membership.yml@main
     secrets: inherit
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/pr-preview.yml around lines 3 - 13, Confirm that the
external reusable workflow referenced by the uses string
"patternfly/.github/.github/workflows/check-team-membership.yml@main" actually
exists in the patternfly/.github repository and, if it does not, either create
that workflow there or update the uses value to the correct repository/path/tag;
update the "check-permissions" job to point to the valid reusable workflow and
ensure the "build-upload" job's if condition (which depends on
needs.check-permissions.outputs.allowed) remains consistent with the chosen
permission-check workflow.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

patternfly/.github/.github/workflows/check-team-membership.yml@main is valid and exists

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@nicolethoen, thanks for confirming! I apologize for the false alarm — my earlier script and web search were unable to access the private patternfly/.github repository, which led to the incorrect finding. I'll note this for future reviews.

Pin patternfly/.github reusable workflow refs to main tip commit for
reproducibility and supply-chain hardening.

Made-with: Cursor
@wise-king-sullyman
wise-king-sullyman merged commit f198c23 into patternfly:main May 19, 2026
5 of 6 checks passed
@patternfly-build

Copy link
Copy Markdown
Collaborator

🎉 This PR is included in version 6.5.0-prerelease.94 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants