Skip to content

fix(workflows): use pull_request_target for auto-changelog-v3 - #5282

Merged
leaanthony merged 2 commits into
masterfrom
fix/auto-changelog-fork-perms
Apr 29, 2026
Merged

leaanthony merged 2 commits into
masterfrom
fix/auto-changelog-fork-perms

Conversation

@leaanthony

@leaanthony leaanthony commented Apr 29, 2026 •

Copy link
Copy Markdown
Member

Summary

Fixes auto-changelog-v3 silently failing on every external contributor PR.

Root cause

The current pull_request: closed trigger runs in the fork's context when a PR comes from a fork. GitHub strips secrets in that context, so OPENROUTER_API_KEY is empty and v3/scripts/auto-changelog.go exits with:

❌ Required env vars: PR_NUMBER, GITHUB_TOKEN, OPENROUTER_API_KEY, GITHUB_REPOSITORY

Reproduced just now on the auto-run for #5265 (AkagiYui's fork PR).

Fix

Switch to pull_request_target, which fires on the same events but runs in base-repo context with secrets attached.

Why this is safe here (despite pull_request_target's usual risks)

  • The workflow already gates on github.event.pull_request.merged == true (so it only runs on real merges).
  • It explicitly checks out master (never fork code).
  • It only queries the GitHub API for PR metadata and runs a Go script that lives in master.

So the typical pull_request_target footgun — running fork-supplied code with elevated permissions — does not apply.

Test plan

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated internal workflow configuration for pull request handling on the main branch.

The current `pull_request: closed` trigger runs in the fork's context
when a PR comes from outside wailsapp/wails. GitHub strips secrets in
that context, so OPENROUTER_API_KEY is empty and the auto-changelog
script exits with "Required env vars: ... OPENROUTER_API_KEY".
Result: no auto-changelog entry for any external contributor's PR.

`pull_request_target` triggers the same way but runs in the base
repository's context with secrets attached. Safe for this workflow
specifically because it:
  - already gates on `github.event.pull_request.merged == true`
  - explicitly checks out `master` (never fork code)
  - only queries the GitHub API for PR metadata + runs a Go script
    that lives in master

So none of the usual `pull_request_target` foot-guns (running fork
code with elevated perms) apply here.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings April 29, 2026 14:12
@coderabbitai

coderabbitai Bot commented Apr 29, 2026 •

Copy link
Copy Markdown
Contributor

Caution

Review failed

Pull request was closed or merged during review

Walkthrough

The GitHub Actions workflow trigger was changed from pull_request to pull_request_target for closed pull requests targeting the master branch, maintaining existing filter conditions and subsequent job logic.

Changes

Cohort / File(s) Summary
Workflow Trigger Update
.github/workflows/auto-changelog-v3.yml
Changed PR workflow trigger from pull_request to pull_request_target for closed PRs targeting master branch.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

🐰 A trigger hops leftward, from pull to the target,
One line changed, the workflow grows smarter!
With secrets now guarded and power in place,
Our changelog v3 wins the race! 🎉

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: switching the workflow trigger from pull_request to pull_request_target for the auto-changelog-v3 workflow.
Description check ✅ Passed The PR description is mostly complete with a clear summary, root cause explanation, proposed fix, and safety justification. However, it does not follow the repository's template structure (missing Type of change checkboxes, Test Configuration section, and other template sections).
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/auto-changelog-fork-perms

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 5/8 reviews remaining, refill in 15 minutes and 59 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@leaanthony
leaanthony merged commit f9beb6a into master Apr 29, 2026
12 of 13 checks passed
@leaanthony
leaanthony deleted the fix/auto-changelog-fork-perms branch April 29, 2026 14:14

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the v3 auto-changelog GitHub Actions workflow trigger so it can run with repository secrets when external contributors’ fork PRs are merged, preventing silent failures of the changelog auto-fill step.

Changes:

  • Switch workflow trigger from pull_request to pull_request_target for closed events targeting master.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

pull Bot pushed a commit to nagyist/wails that referenced this pull request Apr 29, 2026
…): use pull_request_target for auto-changelog-v3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants