Repository navigation
fix(workflows): use pull_request_target for auto-changelog-v3 - #5282
Conversation
The current `pull_request: closed` trigger runs in the fork's context
when a PR comes from outside wailsapp/wails. GitHub strips secrets in
that context, so OPENROUTER_API_KEY is empty and the auto-changelog
script exits with "Required env vars: ... OPENROUTER_API_KEY".
Result: no auto-changelog entry for any external contributor's PR.
`pull_request_target` triggers the same way but runs in the base
repository's context with secrets attached. Safe for this workflow
specifically because it:
- already gates on `github.event.pull_request.merged == true`
- explicitly checks out `master` (never fork code)
- only queries the GitHub API for PR metadata + runs a Go script
that lives in master
So none of the usual `pull_request_target` foot-guns (running fork
code with elevated perms) apply here.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
Caution Review failedPull request was closed or merged during review WalkthroughThe GitHub Actions workflow trigger was changed from Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Review rate limit: 5/8 reviews remaining, refill in 15 minutes and 59 seconds.Comment |
There was a problem hiding this comment.
Pull request overview
Updates the v3 auto-changelog GitHub Actions workflow trigger so it can run with repository secrets when external contributors’ fork PRs are merged, preventing silent failures of the changelog auto-fill step.
Changes:
- Switch workflow trigger from
pull_requesttopull_request_targetforclosedevents targetingmaster.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
…): use pull_request_target for auto-changelog-v3
Summary
Fixes auto-changelog-v3 silently failing on every external contributor PR.
Root cause
The current
pull_request: closedtrigger runs in the fork's context when a PR comes from a fork. GitHub strips secrets in that context, soOPENROUTER_API_KEYis empty andv3/scripts/auto-changelog.goexits with:Reproduced just now on the auto-run for #5265 (AkagiYui's fork PR).
Fix
Switch to
pull_request_target, which fires on the same events but runs in base-repo context with secrets attached.Why this is safe here (despite
pull_request_target's usual risks)github.event.pull_request.merged == true(so it only runs on real merges).master(never fork code).master.So the typical
pull_request_targetfootgun — running fork-supplied code with elevated permissions — does not apply.Test plan
auto-changelog-v3.ymlwithpr_number: 5265(companion run) to backfill the missing entry for fix(v3/windows): fixes the 502 Bad Gateway errors that occur when using Vite as the frontend dev server in development mode #5265.🤖 Generated with Claude Code
Summary by CodeRabbit