Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 0 additions & 40 deletions .github/workflows/add-new-issues-to-project.yml

This file was deleted.

9 changes: 9 additions & 0 deletions .github/workflows/label-pf-team-issue.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
name: Label PF Team issues
on:
issues:
types:
- opened
jobs:
label:
uses: patternfly/.github/.github/workflows/add-pf-team-label-workflow.yml@fdb52a63a2220ec8a3b6c2d43f312cda708ffa06
secrets: inherit
12 changes: 10 additions & 2 deletions .github/workflows/pr-preview.yml
Original file line number Diff line number Diff line change
@@ -1,14 +1,22 @@
### WARNING -- this file was generated by generate-workflows
name: pr-preview
on: pull_request_target
on:
issue_comment:
types: [created]
pull_request_target:
jobs:
check-permissions:
uses: patternfly/.github/.github/workflows/check-team-membership.yml@fdb52a63a2220ec8a3b6c2d43f312cda708ffa06
secrets: inherit
build-upload:
needs: check-permissions
if: needs.check-permissions.outputs.allowed == 'true'
Comment on lines +3 to +13

@coderabbitai coderabbitai Bot Apr 28, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Verify the called reusable workflow's event handling and outputs
url="https://raw.githubusercontent.com/patternfly/.github/main/.github/workflows/check-team-membership.yml"
tmp="$(mktemp)"
curl -fsSL "$url" -o "$tmp"

echo "== Triggers =="
rg -n '^\s*(on:|issue_comment:|pull_request:|pull_request_target:|workflow_call:|types:)' "$tmp" -A2 -B1 || true

echo "== Declared outputs =="
rg -n 'outputs:|allowed|pr-number' "$tmp" -A4 -B2 || true

echo "== Event guards =="
rg -n 'github\.event\.issue\.pull_request|github\.event_name|^\s*if:' "$tmp" -A2 -B2 || true

Repository: patternfly/patternfly

Length of output: 1808


🌐 Web query:

patternfly/.github check-team-membership.yml workflow

💡 Result:

No evidence found of a file named check-team-membership.yml in patternfly/.github or any PatternFly repositories. PatternFly repositories like patternfly/patternfly and patternfly/patternfly-react have .github/workflows directories containing files such as release.yml, documentation.yml, and pr-preview, but no check-team-membership.yml. PatternFly-quickstarts and patternfly/react-topology use team membership checker actions (e.g., TheModdingInquisition/actions-team-membership) in workflows like add-to-project.yml and extensions.yml, referencing team: 'frequent-flyers'. General GitHub Actions for team membership checks exist (e.g., tspascoal/get-user-teams-membership), but no exact match for the specified file in PatternFly.

Citations:


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Try to fetch the reusable workflow directly
tmp="$(mktemp)"
if curl -fsSL "https://raw.githubusercontent.com/patternfly/.github/main/.github/workflows/check-team-membership.yml" -o "$tmp" 2>/dev/null; then
    echo "=== Workflow retrieved successfully ==="
    cat "$tmp"
else
    echo "Failed to retrieve workflow, attempting alternative method..."
    # If curl fails, provide diagnostic info
    echo "Curl failed to retrieve workflow from GitHub"
fi

Repository: patternfly/patternfly

Length of output: 1893


Verify the external reusable workflow path before merging.

The suggested PR-only guard (github.event_name == 'pull_request_target' || github.event.issue.pull_request != null) is a valid best practice for filtering issue comments to PR-only contexts. However, the external reusable workflow patternfly/.github/.github/workflows/check-team-membership.yml could not be found in the patternfly/.github repository. Verify that this workflow exists at the specified path and location, or reference the correct workflow used by your team for permission checks. If this workflow doesn't exist yet, it will need to be created in the referenced repository before this change can work.

Suggested change (pending verification of external workflow)
 jobs:
   check-permissions:
+    if: ${{ github.event_name == 'pull_request_target' || github.event.issue.pull_request != null }}
     uses: patternfly/.github/.github/workflows/check-team-membership.yml@main
     secrets: inherit
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.github/workflows/pr-preview.yml around lines 3 - 13, Confirm that the
external reusable workflow referenced by the uses string
"patternfly/.github/.github/workflows/check-team-membership.yml@main" actually
exists in the patternfly/.github repository and, if it does not, either create
that workflow there or update the uses value to the correct repository/path/tag;
update the "check-permissions" job to point to the valid reusable workflow and
ensure the "build-upload" job's if condition (which depends on
needs.check-permissions.outputs.allowed) remains consistent with the chosen
permission-check workflow.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

patternfly/.github/.github/workflows/check-team-membership.yml@main is valid and exists

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@nicolethoen, thanks for confirming! I apologize for the false alarm — my earlier script and web search were unable to access the private patternfly/.github repository, which led to the incorrect finding. I'll note this for future reviews.

runs-on: ubuntu-latest
env:
SURGE_LOGIN: ${{ secrets.SURGE_LOGIN }}
SURGE_TOKEN: ${{ secrets.SURGE_TOKEN }}
GH_PR_TOKEN: ${{ secrets.GH_PR_TOKEN }}
GH_PR_NUM: ${{ github.event.number }}
GH_PR_NUM: ${{ needs.check-permissions.outputs.pr-number }}
steps:
- uses: actions/checkout@v4
# Yes, we really want to checkout the PR
Expand Down
Loading