chore(workflows): update issue label and preview gate - #8341
Conversation
Replace repo-specific issue labeling with org reusable workflow and gate Surge preview publishing behind the org team-membership check. Made-with: Cursor
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI (base), Organization UI (inherited) Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
✅ Files skipped from review due to trivial changes (1)
WalkthroughDeletes an old issue-to-project workflow, adds a new issue-labeling workflow that calls a reusable external workflow, and updates the PR preview workflow to accept issue_comment events and gate build-upload behind a permissions check job. Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Review rate limit: 7/8 reviews remaining, refill in 7 minutes and 30 seconds.Comment |
|
Preview: https://pf-pr-8341.surge.sh A11y report: https://pf-pr-8341-a11y.surge.sh |
There was a problem hiding this comment.
Actionable comments posted: 2
🧹 Nitpick comments (1)
.github/workflows/pr-preview.yml (1)
9-9: Pin the reusable workflow to a commit SHA instead of@main.Using a moving branch ref can introduce unreviewed behavior changes into this workflow.
Suggested change
- uses: patternfly/.github/.github/workflows/check-team-membership.yml@main + uses: patternfly/.github/.github/workflows/check-team-membership.yml@<commit-sha>🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed. In @.github/workflows/pr-preview.yml at line 9, Replace the moving branch ref in the reusable workflow call by pinning the `uses: patternfly/.github/.github/workflows/check-team-membership.yml@main` reference to an exact commit SHA: find the commit SHA you want to lock to in the patternfly/.github repository, then update the `uses:` value to `patternfly/.github/.github/workflows/check-team-membership.yml@<commit-sha>` (replace <commit-sha> with the actual full SHA) so the workflow invocation is pinned to a fixed revision.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/label-pf-team-issue.yml:
- Line 8: The workflow invocation currently references a mutable branch ref
"patternfly/.github/.github/workflows/add-pf-team-label-workflow.yml@main";
replace the branch ref with the full commit SHA of the desired pinned revision
(e.g., change "@main" to "@<full-commit-sha>"). Locate the uses line in the
workflow (the uses:
patternfly/.github/.github/workflows/add-pf-team-label-workflow.yml@main entry)
and update it to the exact commit SHA from the patternfly repo commit you want
to pin, then commit that change so the reusable workflow is immutable and
reproducible.
In @.github/workflows/pr-preview.yml:
- Around line 3-13: Confirm that the external reusable workflow referenced by
the uses string
"patternfly/.github/.github/workflows/check-team-membership.yml@main" actually
exists in the patternfly/.github repository and, if it does not, either create
that workflow there or update the uses value to the correct repository/path/tag;
update the "check-permissions" job to point to the valid reusable workflow and
ensure the "build-upload" job's if condition (which depends on
needs.check-permissions.outputs.allowed) remains consistent with the chosen
permission-check workflow.
---
Nitpick comments:
In @.github/workflows/pr-preview.yml:
- Line 9: Replace the moving branch ref in the reusable workflow call by pinning
the `uses: patternfly/.github/.github/workflows/check-team-membership.yml@main`
reference to an exact commit SHA: find the commit SHA you want to lock to in the
patternfly/.github repository, then update the `uses:` value to
`patternfly/.github/.github/workflows/check-team-membership.yml@<commit-sha>`
(replace <commit-sha> with the actual full SHA) so the workflow invocation is
pinned to a fixed revision.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI (base), Organization UI (inherited)
Review profile: CHILL
Plan: Pro
Run ID: e1413daf-1f5f-45b0-a1ee-5d62a5189a5a
📒 Files selected for processing (3)
.github/workflows/add-new-issues-to-project.yml.github/workflows/label-pf-team-issue.yml.github/workflows/pr-preview.yml
💤 Files with no reviewable changes (1)
- .github/workflows/add-new-issues-to-project.yml
| on: | ||
| issue_comment: | ||
| types: [created] | ||
| pull_request_target: | ||
| jobs: | ||
| check-permissions: | ||
| uses: patternfly/.github/.github/workflows/check-team-membership.yml@main | ||
| secrets: inherit | ||
| build-upload: | ||
| needs: check-permissions | ||
| if: needs.check-permissions.outputs.allowed == 'true' |
There was a problem hiding this comment.
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
# Verify the called reusable workflow's event handling and outputs
url="https://raw.githubusercontent.com/patternfly/.github/main/.github/workflows/check-team-membership.yml"
tmp="$(mktemp)"
curl -fsSL "$url" -o "$tmp"
echo "== Triggers =="
rg -n '^\s*(on:|issue_comment:|pull_request:|pull_request_target:|workflow_call:|types:)' "$tmp" -A2 -B1 || true
echo "== Declared outputs =="
rg -n 'outputs:|allowed|pr-number' "$tmp" -A4 -B2 || true
echo "== Event guards =="
rg -n 'github\.event\.issue\.pull_request|github\.event_name|^\s*if:' "$tmp" -A2 -B2 || trueRepository: patternfly/patternfly
Length of output: 1808
🌐 Web query:
patternfly/.github check-team-membership.yml workflow
💡 Result:
No evidence found of a file named check-team-membership.yml in patternfly/.github or any PatternFly repositories. PatternFly repositories like patternfly/patternfly and patternfly/patternfly-react have .github/workflows directories containing files such as release.yml, documentation.yml, and pr-preview, but no check-team-membership.yml. PatternFly-quickstarts and patternfly/react-topology use team membership checker actions (e.g., TheModdingInquisition/actions-team-membership) in workflows like add-to-project.yml and extensions.yml, referencing team: 'frequent-flyers'. General GitHub Actions for team membership checks exist (e.g., tspascoal/get-user-teams-membership), but no exact match for the specified file in PatternFly.
Citations:
- 1: https://github.com/patternfly/patternfly-quickstarts/blob/main/.github/workflows/add-to-project.yml
- 2: https://github.com/TheModdingInquisition/actions-team-membership
- 3: https://github.com/patternfly/react-topology/blob/main/.github/workflows/extensions.yml
- 4: https://github.com/patternfly/patternfly-react/blob/main/.github/workflows/documentation.yml
- 5: https://github.com/patternfly/patternfly/blob/main/.github/workflows/release.yml
- 6: https://github.com/patternfly/patternfly/actions
- 7: https://github.com/patternfly/patternfly-react/blob/main/.github/workflows/release.yml
- 8: https://github.com/patternfly/patternfly-org
- 9: https://github.com/patternfly/patternfly
- 10: https://github.com/patternfly/patternfly-org/tree/main
🏁 Script executed:
#!/bin/bash
set -euo pipefail
# Try to fetch the reusable workflow directly
tmp="$(mktemp)"
if curl -fsSL "https://raw.githubusercontent.com/patternfly/.github/main/.github/workflows/check-team-membership.yml" -o "$tmp" 2>/dev/null; then
echo "=== Workflow retrieved successfully ==="
cat "$tmp"
else
echo "Failed to retrieve workflow, attempting alternative method..."
# If curl fails, provide diagnostic info
echo "Curl failed to retrieve workflow from GitHub"
fiRepository: patternfly/patternfly
Length of output: 1893
Verify the external reusable workflow path before merging.
The suggested PR-only guard (github.event_name == 'pull_request_target' || github.event.issue.pull_request != null) is a valid best practice for filtering issue comments to PR-only contexts. However, the external reusable workflow patternfly/.github/.github/workflows/check-team-membership.yml could not be found in the patternfly/.github repository. Verify that this workflow exists at the specified path and location, or reference the correct workflow used by your team for permission checks. If this workflow doesn't exist yet, it will need to be created in the referenced repository before this change can work.
Suggested change (pending verification of external workflow)
jobs:
check-permissions:
+ if: ${{ github.event_name == 'pull_request_target' || github.event.issue.pull_request != null }}
uses: patternfly/.github/.github/workflows/check-team-membership.yml@main
secrets: inherit🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In @.github/workflows/pr-preview.yml around lines 3 - 13, Confirm that the
external reusable workflow referenced by the uses string
"patternfly/.github/.github/workflows/check-team-membership.yml@main" actually
exists in the patternfly/.github repository and, if it does not, either create
that workflow there or update the uses value to the correct repository/path/tag;
update the "check-permissions" job to point to the valid reusable workflow and
ensure the "build-upload" job's if condition (which depends on
needs.check-permissions.outputs.allowed) remains consistent with the chosen
permission-check workflow.
There was a problem hiding this comment.
patternfly/.github/.github/workflows/check-team-membership.yml@main is valid and exists
There was a problem hiding this comment.
@nicolethoen, thanks for confirming! I apologize for the false alarm — my earlier script and web search were unable to access the private patternfly/.github repository, which led to the incorrect finding. I'll note this for future reviews.
Pin patternfly/.github reusable workflow refs to main tip commit for reproducibility and supply-chain hardening. Made-with: Cursor
|
🎉 This PR is included in version 6.5.0-prerelease.94 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Replace repo-specific issue labeling with org reusable workflow and gate Surge preview publishing behind the org team-membership check.
Made-with: Cursor
Summary by CodeRabbit