Comment on Plugin PR #17
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # .github/workflows/comment-pr.yml | |
| # | |
| # Posts a summary comment on a PR on behalf of a read-only checks workflow. | |
| # | |
| # It runs via workflow_run, so it executes on the *base* branch with a | |
| # read/write GITHUB_TOKEN even when the triggering PR came from a fork (fork PRs | |
| # only ever get a read-only token, so the check workflows can't comment | |
| # themselves). It never checks out or runs any PR code — it only downloads the | |
| # `pr-comment` artifact the check workflow produced and posts its contents. | |
| # | |
| # Contract: the producing workflow uploads a `pr-comment` artifact containing | |
| # - pr_number : the PR to comment on (from trusted event context) | |
| # - head_sha : the PR head the results describe; posting is skipped if the PR | |
| # has since advanced, so stale results don't overwrite newer ones | |
| # - comment.md: the rendered comment body, whose first line is an HTML marker | |
| # (e.g. <!-- validate-pr-report -->) used to update in place. | |
| name: Comment on Plugin PR | |
| on: | |
| workflow_run: | |
| workflows: ["Validate Plugin PR", "Security Scan"] | |
| types: | |
| - completed | |
| permissions: | |
| contents: read | |
| pull-requests: write | |
| jobs: | |
| comment: | |
| runs-on: ubuntu-latest | |
| # Only act on check runs that actually ran (success or failure, so failures | |
| # still get a report) and were triggered by a PR event. Skipped runs upload | |
| # no artifact, so there is nothing to post. | |
| if: >- | |
| (github.event.workflow_run.event == 'pull_request' || | |
| github.event.workflow_run.event == 'issue_comment') && | |
| (github.event.workflow_run.conclusion == 'success' || | |
| github.event.workflow_run.conclusion == 'failure') | |
| steps: | |
| - name: Download comment payload | |
| id: download | |
| continue-on-error: true | |
| uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 | |
| with: | |
| name: pr-comment | |
| run-id: ${{ github.event.workflow_run.id }} | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Post PR comment | |
| if: steps.download.outcome == 'success' | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| REPO: ${{ github.repository }} | |
| run: | | |
| if [ ! -f pr_number ] || [ ! -f comment.md ]; then | |
| echo "No pr-comment payload found; nothing to post." | |
| exit 0 | |
| fi | |
| # PR number is trusted event context from the producing workflow; | |
| # strip to digits defensively before use. | |
| PR_NUMBER=$(tr -dc '0-9' < pr_number) | |
| if [ -z "$PR_NUMBER" ]; then | |
| echo "No PR number in payload; nothing to post." | |
| exit 0 | |
| fi | |
| # Don't overwrite a newer report: if the PR head has advanced since | |
| # these results were produced, a fresher run is already on its way. | |
| if [ -f head_sha ]; then | |
| artifact_sha=$(tr -dc '0-9a-fA-F' < head_sha) | |
| current_sha=$(gh api "repos/$REPO/pulls/$PR_NUMBER" --jq '.head.sha') | |
| if [ -n "$artifact_sha" ] && [ -n "$current_sha" ] && [ "$artifact_sha" != "$current_sha" ]; then | |
| echo "PR head advanced ($artifact_sha -> $current_sha); skipping stale comment." | |
| exit 0 | |
| fi | |
| fi | |
| # The first line is the report's HTML marker; reuse it to update our | |
| # previous comment of this type in place instead of stacking new ones. | |
| MARKER=$(head -n1 comment.md) | |
| comment_id="" | |
| case "$MARKER" in | |
| "<!--"*"-->") | |
| comment_id=$(MARKER="$MARKER" gh api "repos/$REPO/issues/$PR_NUMBER/comments" \ | |
| --paginate \ | |
| --jq '.[] | select(.user.login == "github-actions[bot]" and (.body | contains(env.MARKER))) | .id' \ | |
| | tail -n 1) | |
| ;; | |
| esac | |
| if [ -n "$comment_id" ]; then | |
| gh api --method PATCH "repos/$REPO/issues/comments/$comment_id" \ | |
| --raw-field body="$(cat comment.md)" >/dev/null | |
| else | |
| gh pr comment "$PR_NUMBER" --repo "$REPO" --body-file comment.md | |
| fi |