Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
51 changes: 51 additions & 0 deletions .github/workflows/pr-target-branch.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
name: "PR target branch"

on:
# pull_request_target so the job can comment on pull requests from forks,
# which a fork-triggered pull_request token cannot do.
#
# DANGER: this runs with a repository token against pull requests from
# untrusted forks. It is safe only because nothing from the head revision is
# checked out or executed, and no pull-request-controlled string reaches a
# `run:` block. Do not add actions/checkout, and keep permissions scoped to
# pull-requests: write.
#
# GitHub reads this file from the pull request's base branch, so it must
# exist on main to guard pull requests into main.
pull_request_target:
types: [opened]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Retargeting leaves stale warnings

The workflow subscribes only to opened, although its comments say retargeting reruns the check and clears the warning. Changing the base branch emits an edited event, and the script has no logic to remove an earlier comment, so a pull request retargeted to mezmo would retain the stale warning.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I deleted the comment. But would it be better to do something like resolving it like what is done in https://github.com/mezmo/aura/blob/main/.github/workflows/pr-target-branch.yml#L89

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes—Aura’s marker-based update is better than deleting the comment. It preserves the audit trail, avoids duplicate bot comments, and replaces the warning in place when the PR is retargeted.

It is not technically resolving a GitHub review thread; it finds the bot’s marker comment and updates it to a “Resolved” message. For Rig, use the same pattern:

Suggested change
types: [opened]
pull_request_target:
types: [opened, reopened, edited]

Add a stable marker such as <!-- pr-target-branch -->, locate only the github-actions[bot] comment containing that marker, and update it to a resolved message when an edited event changes the base away from main. edited is the key event for retargeting; reopened covers a PR reopened while still targeting main. This maintains one warning comment per PR without leaving a stale warning.

Tip: You can customize Greptile's behavior for this repo with .greptile/rules.md and .greptile/config.json.


permissions:
pull-requests: write

concurrency:
group: pr-target-branch-${{ github.event.pull_request.number }}
cancel-in-progress: true

jobs:
check:
name: "Warn on pull requests targeting main"
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
# Pinned to a commit SHA because the tag is mutable and this step holds
# a write-scoped token.
- uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7.1.0
with:
script: |
const pr = context.payload.pull_request;
const base = pr.base.ref;
const {owner, repo} = context.repo;

if (base !== 'main') {
core.info(`Base branch is ${base}; nothing to check.`);
return;
}

const body =
`**This pull request targets \`main\`. Please retarget it to \`mezmo\`.**

Use **Edit** next to the pull request title to change the base branch, then
rebase onto \`mezmo\` if the diff picked up unrelated commits.`;

await github.rest.issues.createComment({owner, repo, issue_number: pr.number, body});
Loading