Skip to content

Migrate pull request automation away from pull_request_target - #9051

Open
mrecachinas wants to merge 3 commits into
mainfrom
copilot/prt-migration-20260811-advisory-database
Open

Migrate pull request automation away from pull_request_target#9051
mrecachinas wants to merge 3 commits into
mainfrom
copilot/prt-migration-20260811-advisory-database

Conversation

@mrecachinas

Copy link
Copy Markdown
Member

Summary

This draft updates the pull request automation in this repository to avoid using pull_request_target for PR-driven workflow execution.

The replacement pattern keeps untrusted PR input in lower-privilege pull_request workflows and moves any required repository-write actions into a separate, narrowly scoped follow-up path. Where a follow-up workflow is needed, it re-checks the pull request context before taking action so the workflow operates on the intended PR/head commit rather than trusting mutable PR state.

Expected workflow shift

  • PR-triggered jobs run with reduced permissions.
  • Repository write actions, when still needed, happen after the PR workflow completes.
  • Follow-up jobs validate PR metadata before posting labels, comments, statuses, or other write-side effects.
  • Workflow behavior should remain equivalent for maintainers and contributors, with the permission boundary made more explicit.

Notes

Opening as a draft for repository-owner review before this is marked ready. Please review the workflow-specific behavior and any repository settings assumptions before merge.

mrecachinas and others added 2 commits August 11, 2026 10:56
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@mrecachinas
mrecachinas marked this pull request as ready for review August 12, 2026 13:36
Copilot AI balanced review requested due to automatic review settings August 12, 2026 13:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Splits PR automation into low-privilege signal workflows and privileged follow-up writers.

Changes:

  • Replaces pull_request_target triggers with pull_request.
  • Adds validated writer workflows for staging-branch creation and cleanup.
  • Adds manual dispatch support for writer workflows.
Show a summary per file
File Description
.github/workflows/create_staging_branch.yaml Emits the staging-creation signal.
.github/workflows/create_staging_branch_writer.yaml Creates staging branches and retargets PRs.
.github/workflows/delete_staging_and_head_branches.yaml Emits the branch-cleanup signal.
.github/workflows/delete_staging_and_head_branches_writer.yaml Validates PRs and deletes branches.

Review details

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

  • Files reviewed: 4/4 changed files
  • Comments generated: 4
  • Review effort level: Balanced

Comment thread .github/workflows/create_staging_branch.yaml
Comment thread .github/workflows/delete_staging_and_head_branches.yaml
Comment thread .github/workflows/create_staging_branch_writer.yaml Outdated
Comment thread .github/workflows/delete_staging_and_head_branches_writer.yaml Outdated
Add trusted scheduled reconciliation for conflicted pull requests, bind workflow-run writes to PR head identity, and safely encode validated Git refs during cleanup.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 512eb347-ec89-4250-8bf1-87048974b01d
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants