Skip to content

Migrate pull request automation away from pull_request_target - #5335

Open
mrecachinas wants to merge 3 commits into
mainfrom
copilot/prt-migration-20260811-explore
Open

Migrate pull request automation away from pull_request_target#5335
mrecachinas wants to merge 3 commits into
mainfrom
copilot/prt-migration-20260811-explore

Conversation

@mrecachinas

Copy link
Copy Markdown
Member

Summary

This draft updates the pull request automation in this repository to avoid using pull_request_target for PR-driven workflow execution.

The replacement pattern keeps untrusted PR input in lower-privilege pull_request workflows and moves any required repository-write actions into a separate, narrowly scoped follow-up path. Where a follow-up workflow is needed, it re-checks the pull request context before taking action so the workflow operates on the intended PR/head commit rather than trusting mutable PR state.

Expected workflow shift

  • PR-triggered jobs run with reduced permissions.
  • Repository write actions, when still needed, happen after the PR workflow completes.
  • Follow-up jobs validate PR metadata before posting labels, comments, statuses, or other write-side effects.
  • Workflow behavior should remain equivalent for maintainers and contributors, with the permission boundary made more explicit.

Notes

Opening as a draft for repository-owner review before this is marked ready. Please review the workflow-specific behavior and any repository settings assumptions before merge.

mrecachinas and others added 2 commits August 11, 2026 11:01
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@mrecachinas
mrecachinas marked this pull request as ready for review August 12, 2026 13:37
Copilot AI balanced review requested due to automatic review settings August 12, 2026 13:37
@mrecachinas
mrecachinas requested a review from a team as a code owner August 12, 2026 13:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Migrates PR triage automation to a split, least-privilege workflow model.

Changes:

  • Generates triage data in an unprivileged pull_request workflow.
  • Adds a privileged workflow_run writer that validates artifacts and updates sticky comments.
Show a summary per file
File Description
.github/workflows/explore-triage-commenter.yml Builds and uploads triage data.
.github/workflows/explore-triage-commenter-writer.yml Validates data and posts comments.

Review details

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

  • Files reviewed: 2/2 changed files
  • Comments generated: 5
  • Review effort level: Balanced

Comment thread .github/workflows/explore-triage-commenter-writer.yml
Comment thread .github/workflows/explore-triage-commenter-writer.yml
Comment thread .github/workflows/explore-triage-commenter-writer.yml
Comment thread .github/workflows/explore-triage-commenter-writer.yml Outdated
Comment thread .github/workflows/explore-triage-commenter-writer.yml Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 512eb347-ec89-4250-8bf1-87048974b01d
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants