Repository navigation
T8929: auto-close pr workflow pullrequest target trigger fixed - #5221
Conversation
📝 WalkthroughWalkthroughAdds a GitHub Actions workflow ChangesPR Auto-Close Automation
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
👍 |
|
✅ No typos found in changed files. |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/pr-auto-close.yml:
- Line 20: Replace the mutable action reference
"superbrothers/close-pull-request@v3" in the workflow step that uses the `uses:`
key with the fixed commit SHA
"superbrothers/close-pull-request@9c18513d320d7b2c7185fb93396d0c664d5d8448" so
the workflow pins to an immutable commit; update the `uses:` value accordingly
where the action is referenced to eliminate supply-chain risk.
- Around line 5-6: Update the pr-auto-close workflow trigger so it also runs
when a PR is reopened: in the workflow definition for the pull_request_target
event (the pr-auto-close workflow), change the types array that currently
contains only "opened" (the key shown as types: - opened) to include "reopened"
as well so the workflow will execute on reopened PRs.
- Line 24: Remove the unnecessary secrets override by deleting the
`github_token: ${{ secrets.PAT }}` entry from the workflow; the
`superbrothers/close-pull-request@v3` action uses the default GITHUB_TOKEN and
the explicit PAT only widens secret exposure with no benefit, so remove that
YAML key/value from the pr-auto-close workflow.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository YAML (base), Central YAML (inherited), Organization UI (inherited)
Review profile: CHILL
Plan: Pro Plus
Run ID: b4d0f78e-bbdc-4ac6-ba85-b8fc8fd782ce
📒 Files selected for processing (1)
.github/workflows/pr-auto-close.yml
📜 Review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
- GitHub Check: add-rebase-label / add-rebase-label
- GitHub Check: add-pr-label / Add PR Labels
- GitHub Check: assign-author / assign-author
- GitHub Check: Mergify Merge Protections
- GitHub Check: Summary
🧰 Additional context used
🪛 zizmor (1.25.2)
.github/workflows/pr-auto-close.yml
[error] 3-9: use of fundamentally insecure workflow trigger (dangerous-triggers): pull_request_target is almost always used insecurely
(dangerous-triggers)
[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🔍 Remote MCP
I'll search for relevant information about the GitHub Actions workflow components and best practices to support your PR review.## Relevant Context for PR #5221 Review
Action Compatibility & Configuration
The superbrothers/close-pull-request action subscribes to pull_request_target events and closes pull requests triggered by the event immediately. The PR uses v3 of this action, which is appropriate—version 3.0.0 changed to use pull_request_target event instead of the earlier pull_request event.
Branch Filtering with pull_request_target
The PR adds branch filtering to trigger the workflow for the circinus and sagitta branches. This is valid: You can use the branches or branches-ignore filter to configure your workflow to only run on pull requests that target specific branches, and when using the pull_request_target event, you can configure a workflow to run only for pull requests that target specific branches.
Workflow Execution Context
Important to note: The pull_request_target event runs in the context of the default branch of the base repository, rather than in the context of the merge commit, as the pull_request event does. This prevents execution of unsafe code from the head of the pull request that could alter your repository or steal any secrets you use in your workflow.
Security Considerations
The PR correctly uses pull_request_target for this auto-close functionality. However, be aware that running untrusted code on the pull_request_target trigger may lead to security vulnerabilities including cache poisoning and granting unintended access to write privileges or secrets. Since this workflow only closes PRs and posts a comment (without executing user code), the security risk is minimal.
Key Point About Default Branch Limitation
The pull_request_target event will only trigger a workflow run if the workflow file exists on the default branch. The PR adds the workflow file to the default branch (current), which aligns with this requirement and explains why the fix was necessary—the workflow wouldn't have been recognized on non-default branches previously.
[::web_search::]
There was a problem hiding this comment.
🧹 Nitpick comments (1)
.github/workflows/pr-auto-close.yml (1)
1-1: 💤 Low valueWorkflow name mentions only Sagitta but also handles Circinus.
Line 8-10 target both
circinusandsagitta. Consider updating the workflow name to reflect both branches.-name: Auto-Close Pull Requests Sagitta +name: Auto-Close Pull Requests (Circinus/Sagitta)🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/pr-auto-close.yml at line 1, The workflow name "name: Auto-Close Pull Requests Sagitta" only mentions Sagitta but the workflow handles both branches (`circinus` and `sagitta`); update the `name:` value to include both branches (e.g., "Auto-Close Pull Requests — Sagitta & Circinus" or similar) so the workflow title accurately reflects that it targets `circinus` and `sagitta`.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In @.github/workflows/pr-auto-close.yml:
- Line 1: The workflow name "name: Auto-Close Pull Requests Sagitta" only
mentions Sagitta but the workflow handles both branches (`circinus` and
`sagitta`); update the `name:` value to include both branches (e.g., "Auto-Close
Pull Requests — Sagitta & Circinus" or similar) so the workflow title accurately
reflects that it targets `circinus` and `sagitta`.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository YAML (base), Central YAML (inherited), Organization UI (inherited)
Review profile: CHILL
Plan: Pro Plus
Run ID: 459ed80c-a985-4ab8-bd16-c51641536ca4
📒 Files selected for processing (1)
.github/workflows/pr-auto-close.yml
📜 Review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
- GitHub Check: Mergify Merge Protections
- GitHub Check: Summary
🧰 Additional context used
🔍 Remote MCP
Summary of Relevant Context for PR #5221 Review
GitHub Actions pull_request_target Event Behavior
The pull_request_target event now always uses the default branch for workflow source and reference: The workflow file and checkout commit will always be taken from the repository's default branch, regardless of the pull request's base branch. This is a critical change—these changes take effect on 12/8/2025, which is relevant to understanding the purpose of this PR fix.
Background on the PR's Issue: The PR description states it "fixes the auto-close PR workflow so the pullrequest target trigger is properly recognized when using the default branch." By default, a workflow only runs when a pull_request_target event's activity type is opened, synchronize, or reopened. The workflow in this PR is configured to trigger on opened and reopened events for branches circinus or sagitta.
Security Considerations for pull_request_target
Assess your usage of pull_request_target and use it only when necessary: Ensure user-controlled input or code cannot influence execution in a way that runs untrusted code. If your workflow does not require elevated permissions or access to secrets, use pull_request instead. Restrict permissions granted to these workflows. Configure the default token permissions to read-only or apply least-privilege settings in the workflow.
The PR correctly sets restrictive permissions (pull-requests: write and contents: read), which aligns with security best practices.
The superbrothers/close-pull-request Action
This Action subscribes to pull_request_target events. When receiving a pull_request_target event, this action closes the pull request triggered by the event immediately. The action was specifically designed to work with pull_request_target events. Version 3.0.0 was released with support for pull_request_target event.
🔇 Additional comments (3)
.github/workflows/pr-auto-close.yml (3)
7-7: LGTM!
22-22: LGTM!
3-10: LGTM!Also applies to: 12-15, 17-20, 23-25
sever-sever
left a comment
There was a problem hiding this comment.
We do not accept PRs for the circinus/sagitta branch in this repo.
c-po
left a comment
There was a problem hiding this comment.
LTS branches do not accept public PRs. Add workflow for auto closing PRs.
Change summary
Added this workflow to default branch (with restricted branches) as pullrequest target recognised only in the default branch.
Used github token instead of PAT (as this is working on same repo)
Added org restriction to excute only in vyos
Types of changes
Related Task(s)
https://vyos.dev/T8929Related PR(s)
How to test / Smoketest result
Checklist: