Sitelet https://github.com/lightspeedwp/.github/commit/4acec5e6e78652375940415f481083d7a9b28f7f
Skip to content

Commit 4acec5e

Browse files
committed
Read FEEDBACK_RESPONSE.md through the base repository (#3480)
Address CodeRabbit review on #3486: the base repository serves fork head commits, so reading at pr.head.sha from context.repo works for forks, including deleted ones, with a token scoped to the caller. Verified against a live fork PR (actions/checkout#2581).
1 parent 154a49f commit 4acec5e

2 files changed

Lines changed: 25 additions & 20 deletions

File tree

‎.github/workflows/ai-feedback-validation.yml‎

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -68,24 +68,24 @@ jobs:
6868
return;
6969
}
7070
71-
// Read FEEDBACK_RESPONSE.md from the PR head as data, never by
72-
// checking out PR code. A fork's head repo may be gone (null).
71+
// Read FEEDBACK_RESPONSE.md at the PR head commit as data, never
72+
// by checking out PR code. The base repository serves fork head
73+
// commits too, so this works for forks (even deleted ones) with a
74+
// token scoped to the calling repository.
7375
let feedbackContent = null;
74-
if (pr.head?.repo) {
75-
try {
76-
const { data } = await github.rest.repos.getContent({
77-
owner: pr.head.repo.owner.login,
78-
repo: pr.head.repo.name,
79-
path: 'FEEDBACK_RESPONSE.md',
80-
ref: pr.head.sha,
81-
});
82-
if (!Array.isArray(data) && data.content) {
83-
feedbackContent = Buffer.from(data.content, 'base64').toString('utf8');
84-
}
85-
} catch (error) {
86-
if (error.status !== 404) {
87-
throw error;
88-
}
76+
try {
77+
const { data } = await github.rest.repos.getContent({
78+
owner: context.repo.owner,
79+
repo: context.repo.repo,
80+
path: 'FEEDBACK_RESPONSE.md',
81+
ref: pr.head.sha,
82+
});
83+
if (!Array.isArray(data) && data.content) {
84+
feedbackContent = Buffer.from(data.content, 'base64').toString('utf8');
85+
}
86+
} catch (error) {
87+
if (error.status !== 404) {
88+
throw error;
8989
}
9090
}
9191

‎scripts/workflows/__tests__/reusable-workflows.test.js‎

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -224,15 +224,20 @@ describe('ai-feedback-validation.yml', () => {
224224
expect(core.warning).toHaveBeenCalledWith(expect.stringContaining('No permission to comment'));
225225
});
226226

227-
test('a fork whose head repository was deleted is treated as no feedback file', async () => {
228-
const { github } = makeGithub();
227+
test('a fork PR (even with its head repository deleted) is read through the base repository', async () => {
228+
const { github } = makeGithub({ feedbackFile: VALID_FEEDBACK });
229229
const core = makeCore();
230230
const context = prContext({ body: 'Closes #7' });
231231
context.payload.pull_request.head.repo = null;
232232

233233
await runScript(step, { github, context, core, env: { ENFORCE: 'true' } });
234234

235-
expect(github.rest.repos.getContent).not.toHaveBeenCalled();
235+
expect(github.rest.repos.getContent).toHaveBeenCalledWith({
236+
owner: 'lightspeedwp',
237+
repo: 'example',
238+
path: 'FEEDBACK_RESPONSE.md',
239+
ref: 'abc123',
240+
});
236241
expect(core.setFailed).not.toHaveBeenCalled();
237242
});
238243
});

0 commit comments

Comments
 (0)