FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Handle fork PR associations in invalid-label writer by mrecachinas · Pull Request #4497 · github/copilot-cli · GitHub

Repository navigation

Handle fork PR associations in invalid-label writer - #4497

Merged
devm33 merged 1 commit into
mainfrom
copilot/fix-fork-invalid-pr-close-20260814
Aug 29, 2026
Merged

devm33 merged 1 commit into
mainfrom
copilot/fix-fork-invalid-pr-close-20260814

Conversation

mrecachinas commented Aug 14, 2026 •
edited
Loading

Copy link
Copy Markdown
Member

Summary

This updates the trusted invalid-label writer to handle fork pull request workflow runs when GitHub does not populate the run's pull request association.

When the association is absent, the writer now searches using trusted workflow-run metadata and requires exactly one open pull request matching the expected base repository, full head repository, branch, and head SHA. Ambiguous, malformed, or stale matches continue to fail closed.

The existing workflow identity checks, pull request revalidation, label/state checks, write permissions, and scheduled reconciliation fallback remain unchanged.

Validation

  • actionlint with shellcheck
  • exact-match, ambiguous-match, and stale-SHA association cases
  • security-focused rubber-duck review of the uncommitted diff

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 512eb347-ec89-4250-8bf1-87048974b01d
mrecachinas marked this pull request as ready for review August 14, 2026 20:47
mrecachinas requested review from a team and a balanced review from Copilot August 14, 2026 20:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Pull request overview

Adds fail-closed fork PR discovery when workflow-run PR associations are absent.

Changes:

  • Validates workflow-run head metadata.
  • Finds one exact open PR by repository, branch, and SHA.
  • Revalidates the resolved PR before closing it.
Show a summary per file
File Description
.github/workflows/close-invalid-pr-writer.yml Adds secure fallback PR association and validation.

Review details

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Balanced

devm33 merged commit 024bf28 into main Aug 29, 2026
5 checks passed
devm33 deleted the copilot/fix-fork-invalid-pr-close-20260814 branch August 29, 2026 02:27
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants


Back | FazBrowse Home | New Git URL