Skip to content

Comment on Plugin PR #17

Comment on Plugin PR

Comment on Plugin PR #17

Workflow file for this run

# .github/workflows/comment-pr.yml
#
# Posts a summary comment on a PR on behalf of a read-only checks workflow.
#
# It runs via workflow_run, so it executes on the *base* branch with a
# read/write GITHUB_TOKEN even when the triggering PR came from a fork (fork PRs
# only ever get a read-only token, so the check workflows can't comment
# themselves). It never checks out or runs any PR code — it only downloads the
# `pr-comment` artifact the check workflow produced and posts its contents.
#
# Contract: the producing workflow uploads a `pr-comment` artifact containing
# - pr_number : the PR to comment on (from trusted event context)
# - head_sha : the PR head the results describe; posting is skipped if the PR
# has since advanced, so stale results don't overwrite newer ones
# - comment.md: the rendered comment body, whose first line is an HTML marker
# (e.g. <!-- validate-pr-report -->) used to update in place.
name: Comment on Plugin PR
on:
workflow_run:
workflows: ["Validate Plugin PR", "Security Scan"]
types:
- completed
permissions:
contents: read
pull-requests: write
jobs:
comment:
runs-on: ubuntu-latest
# Only act on check runs that actually ran (success or failure, so failures
# still get a report) and were triggered by a PR event. Skipped runs upload
# no artifact, so there is nothing to post.
if: >-
(github.event.workflow_run.event == 'pull_request' ||
github.event.workflow_run.event == 'issue_comment') &&
(github.event.workflow_run.conclusion == 'success' ||
github.event.workflow_run.conclusion == 'failure')
steps:
- name: Download comment payload
id: download
continue-on-error: true
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: pr-comment
run-id: ${{ github.event.workflow_run.id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
- name: Post PR comment
if: steps.download.outcome == 'success'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
REPO: ${{ github.repository }}
run: |
if [ ! -f pr_number ] || [ ! -f comment.md ]; then
echo "No pr-comment payload found; nothing to post."
exit 0
fi
# PR number is trusted event context from the producing workflow;
# strip to digits defensively before use.
PR_NUMBER=$(tr -dc '0-9' < pr_number)
if [ -z "$PR_NUMBER" ]; then
echo "No PR number in payload; nothing to post."
exit 0
fi
# Don't overwrite a newer report: if the PR head has advanced since
# these results were produced, a fresher run is already on its way.
if [ -f head_sha ]; then
artifact_sha=$(tr -dc '0-9a-fA-F' < head_sha)
current_sha=$(gh api "repos/$REPO/pulls/$PR_NUMBER" --jq '.head.sha')
if [ -n "$artifact_sha" ] && [ -n "$current_sha" ] && [ "$artifact_sha" != "$current_sha" ]; then
echo "PR head advanced ($artifact_sha -> $current_sha); skipping stale comment."
exit 0
fi
fi
# The first line is the report's HTML marker; reuse it to update our
# previous comment of this type in place instead of stacking new ones.
MARKER=$(head -n1 comment.md)
comment_id=""
case "$MARKER" in
"<!--"*"-->")
comment_id=$(MARKER="$MARKER" gh api "repos/$REPO/issues/$PR_NUMBER/comments" \
--paginate \
--jq '.[] | select(.user.login == "github-actions[bot]" and (.body | contains(env.MARKER))) | .id' \
| tail -n 1)
;;
esac
if [ -n "$comment_id" ]; then
gh api --method PATCH "repos/$REPO/issues/comments/$comment_id" \
--raw-field body="$(cat comment.md)" >/dev/null
else
gh pr comment "$PR_NUMBER" --repo "$REPO" --body-file comment.md
fi