Skip to content

Update and refactor pr trigger permissions - #8815

Open
castillios wants to merge 11 commits into
hackforla:gh-pagesfrom
castillios:pr-trigger-permissions-8590
Open

castillios wants to merge 11 commits into
hackforla:gh-pagesfrom
castillios:pr-trigger-permissions-8590

Conversation

@castillios

@castillios castillios commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Fixes #8590

What changes did you make?

Add default permissions

contents: read
issues: write
pull-requests: write

Refactor workflow

  • Split up linked issue checking and PR commenting functionality from pull-request-trigger.yml into the following:
    • pull-request-trigger.yml handles linked issue checking
    • wr-pull-request-trigger.yml handles PR commenting
  • Refactored check-linked-issue.js into 3 main functions (downloadPRCommentArtifact, checkForLinkedIssue, postPRComment) and several helper functions
    • Implement artifacts into the pr trigger workflow to pass PR comment data between automations

Clean up

  • Replaced console.log with core.info
  • While creating this PR I noticed that the Post Comment logs in WR PR Trigger weren't very detailed. I updated the logging to include the PR # comments are posted to

Why did you make the changes (we will use this info to test)?

Add default permissions

  • According to Will's comment we had to refactor the workflows as a workaround to GitHub's tightening security features.
  • The default permissions I added differ slightly from his solution. The following lists why:
    • After testing the refactor with Will's suggested permissions and still running into errors, I updated wr-pull-request-trigger.yml to include an additional permission, pull-requests: write
    • In wr-pull-request-trigger.yml BOTH issues: write and pull-requests: write were added to allow PR commenting. Despite github docs implying that only one write permission is needed, without both permissions a 403 error will still occur: Testing log with only one write permission. I've included successful test logs using both permissions at the bottom of this PR.

Refactor workflow

  • check-linked-issue.js was broken up into several functions to allow the functionality to split into two automations.

Clean up

  • I replaced console.log with core.info for consistency as they are typically used as a logging tool for GHA workflows.
  • Added PR #'s in WR PR Trigger logs for clarity
  • Any additional commits other than the main refactor (812c9b9), updating permissions (77d3999, 4785794), replacing console.log (830112c), clean up the code and squash any errors (i.e. forgetting an await, cleaning up comments, etc).

CodeQL Alerts

After the PR has been submitted and the resulting GitHub actions/checks have been completed, developers should check the PR for CodeQL alert annotations.

Check the PR's comments. If present on your PR, the CodeQL alert looks similar as shown

Screenshot 2024-10-28 154514

Please let us know that you have checked for CodeQL alerts. Please do not dismiss alerts.

  • I have checked this PR for CodeQL alerts and none were found.
  • I found CodeQL alert(s), and (select one):
    • I have resolved the CodeQL alert(s) as noted
    • I believe the CodeQL alert(s) is a false positive (Merge Team will evaluate)
    • I have followed the Instructions below, but I am still stuck (Merge Team will evaluate)
Instructions for resolving CodeQL alerts

If CodeQL alert/annotations appear, refer to How to Resolve CodeQL alerts.

In general, CodeQL alerts should be resolved prior to PR reviews and merging

Screenshots of Proposed Changes To The Website (if any, please do not include screenshots of code changes)

No visual changes to the website

I tested the workflow for three different scenarios. In WR PR Trigger Log, please view "Post Comment to PR" for a detailed log:

I later added PR #'s to WR PR Trigger's logging - Test log:
image

@github-actions github-actions Bot added role: back end/devOps Tasks for back-end developers status: Updated No blockers and update is ready for review Feature: Refactor GHA Refactoring GitHub actions to fit latest architectural norms size: 8pt Can be done in 31-48 hours Complexity: Extra Large labels Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Want to review this pull request? Take a look at this documentation for a step by step guide!


From your project repository, check out a new branch and test the changes.

git checkout -b castillios-pr-trigger-permissions-8590 gh-pages
git pull https://github.com/castillios/website.git pr-trigger-permissions-8590

@castillios castillios removed the status: Updated No blockers and update is ready for review label Oct 1, 2026
@github-actions github-actions Bot added the status: Updated No blockers and update is ready for review label Oct 1, 2026
@castillios

Copy link
Copy Markdown
Member Author

Hi @daras-cu, while working on this solution, I modeled the refactor off of set-pr-labels.js and how it uses artifacts. Since the functions are very similar, should we consider creating an ER and making a shared module to handle artifacts?

@castillios castillios removed the status: Updated No blockers and update is ready for review label Oct 1, 2026
@daras-cu
daras-cu self-requested a review October 1, 2026 21:01
@daras-cu

daras-cu commented Oct 1, 2026

Copy link
Copy Markdown
Member

ETA: 10/5 EOD
Availability: Sunday, evenings

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Complexity: Extra Large Feature: Refactor GHA Refactoring GitHub actions to fit latest architectural norms role: back end/devOps Tasks for back-end developers size: 8pt Can be done in 31-48 hours

Projects

Status: PR Needs review

Development

Successfully merging this pull request may close these issues.

Specify default permissions for pull-request-trigger.yml and wr-pull-request-trigger.yml

2 participants