Skip to content

T8929: auto-close pr workflow pullrequest target trigger fixed - #5221

Merged
c-po merged 4 commits into
vyos:currentfrom
kumvijaya:current
May 27, 2026
Merged

c-po merged 4 commits into
vyos:currentfrom
kumvijaya:current

Conversation

@kumvijaya

@kumvijaya kumvijaya commented May 27, 2026 •

Copy link
Copy Markdown
Contributor

Change summary

Added this workflow to default branch (with restricted branches) as pullrequest target recognised only in the default branch.
Used github token instead of PAT (as this is working on same repo)
Added org restriction to excute only in vyos

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Code style update (formatting, renaming)
  • Refactoring (no functional changes)
  • Migration from an old Vyatta component to vyos-1x, please link to related PR inside obsoleted component
  • Other (please describe):

Related Task(s)

https://vyos.dev/T8929

Related PR(s)

How to test / Smoketest result

Checklist:

  • I have read the CONTRIBUTING document
  • I have linked this PR to one or more Phabricator Task(s)
  • I have run the components SMOKETESTS if applicable
  • My commit headlines contain a valid Task id
  • My change requires a change to the documentation
  • I have updated the documentation accordingly

@kumvijaya
kumvijaya requested a review from c-po May 27, 2026 13:02
@coderabbitai

coderabbitai Bot commented May 27, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Adds a GitHub Actions workflow .github/workflows/pr-auto-close.yml (lines 1-25) that triggers on pull_request_target (opened,reopened) for circinus and sagitta, checks github.repository_owner == 'vyos', sets pull-requests/issues write permissions and contents: read, and runs a pinned superbrothers/close-pull-request action with ${{ github.token }} to close the PR and post a fixed comment.

Changes

PR Auto-Close Automation

Layer / File(s) Summary
Auto-close workflow for protected branches
.github/workflows/pr-auto-close.yml (lines 1-25)
Workflow triggers on pull_request_target opened/reopened events for circinus and sagitta; enforces github.repository_owner == "vyos", grants pull-requests: write, issues: write, contents: read, and invokes a pinned superbrothers/close-pull-request action authenticated with ${{ github.token }} to close the PR and post a fixed comment.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately reflects the main change: adding a GitHub Actions workflow to auto-close PRs targeting specific branches with a fixed pullrequest_target trigger.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description check ✅ Passed The PR description accurately describes the changeset: adding a GitHub Actions workflow to auto-close PRs targeting restricted branches (circinus and sagitta) with organizational restrictions.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
✨ Simplify code
  • Create PR with simplified code

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actions Bot commented May 27, 2026 •

Copy link
Copy Markdown

👍
No issues in PR Title / Commit Title

@github-actions

github-actions Bot commented May 27, 2026 •

Copy link
Copy Markdown

✅ No typos found in changed files.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/pr-auto-close.yml:
- Line 20: Replace the mutable action reference
"superbrothers/close-pull-request@v3" in the workflow step that uses the `uses:`
key with the fixed commit SHA
"superbrothers/close-pull-request@9c18513d320d7b2c7185fb93396d0c664d5d8448" so
the workflow pins to an immutable commit; update the `uses:` value accordingly
where the action is referenced to eliminate supply-chain risk.
- Around line 5-6: Update the pr-auto-close workflow trigger so it also runs
when a PR is reopened: in the workflow definition for the pull_request_target
event (the pr-auto-close workflow), change the types array that currently
contains only "opened" (the key shown as types: - opened) to include "reopened"
as well so the workflow will execute on reopened PRs.
- Line 24: Remove the unnecessary secrets override by deleting the
`github_token: ${{ secrets.PAT }}` entry from the workflow; the
`superbrothers/close-pull-request@v3` action uses the default GITHUB_TOKEN and
the explicit PAT only widens secret exposure with no benefit, so remove that
YAML key/value from the pr-auto-close workflow.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: b4d0f78e-bbdc-4ac6-ba85-b8fc8fd782ce

📥 Commits

Reviewing files that changed from the base of the PR and between f420c29 and 5ae08f7.

📒 Files selected for processing (1)
  • .github/workflows/pr-auto-close.yml
📜 Review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (5)
  • GitHub Check: add-rebase-label / add-rebase-label
  • GitHub Check: add-pr-label / Add PR Labels
  • GitHub Check: assign-author / assign-author
  • GitHub Check: Mergify Merge Protections
  • GitHub Check: Summary
🧰 Additional context used
🪛 zizmor (1.25.2)
.github/workflows/pr-auto-close.yml

[error] 3-9: use of fundamentally insecure workflow trigger (dangerous-triggers): pull_request_target is almost always used insecurely

(dangerous-triggers)


[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🔍 Remote MCP

I'll search for relevant information about the GitHub Actions workflow components and best practices to support your PR review.## Relevant Context for PR #5221 Review

Action Compatibility & Configuration

The superbrothers/close-pull-request action subscribes to pull_request_target events and closes pull requests triggered by the event immediately. The PR uses v3 of this action, which is appropriate—version 3.0.0 changed to use pull_request_target event instead of the earlier pull_request event.

Branch Filtering with pull_request_target

The PR adds branch filtering to trigger the workflow for the circinus and sagitta branches. This is valid: You can use the branches or branches-ignore filter to configure your workflow to only run on pull requests that target specific branches, and when using the pull_request_target event, you can configure a workflow to run only for pull requests that target specific branches.

Workflow Execution Context

Important to note: The pull_request_target event runs in the context of the default branch of the base repository, rather than in the context of the merge commit, as the pull_request event does. This prevents execution of unsafe code from the head of the pull request that could alter your repository or steal any secrets you use in your workflow.

Security Considerations

The PR correctly uses pull_request_target for this auto-close functionality. However, be aware that running untrusted code on the pull_request_target trigger may lead to security vulnerabilities including cache poisoning and granting unintended access to write privileges or secrets. Since this workflow only closes PRs and posts a comment (without executing user code), the security risk is minimal.

Key Point About Default Branch Limitation

The pull_request_target event will only trigger a workflow run if the workflow file exists on the default branch. The PR adds the workflow file to the default branch (current), which aligns with this requirement and explains why the fix was necessary—the workflow wouldn't have been recognized on non-default branches previously.

[::web_search::]

Comment thread .github/workflows/pr-auto-close.yml
Comment thread .github/workflows/pr-auto-close.yml Outdated
Comment thread .github/workflows/pr-auto-close.yml Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
.github/workflows/pr-auto-close.yml (1)

1-1: 💤 Low value

Workflow name mentions only Sagitta but also handles Circinus.

Line 8-10 target both circinus and sagitta. Consider updating the workflow name to reflect both branches.

-name: Auto-Close Pull Requests Sagitta
+name: Auto-Close Pull Requests (Circinus/Sagitta)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/pr-auto-close.yml at line 1, The workflow name "name:
Auto-Close Pull Requests Sagitta" only mentions Sagitta but the workflow handles
both branches (`circinus` and `sagitta`); update the `name:` value to include
both branches (e.g., "Auto-Close Pull Requests — Sagitta & Circinus" or similar)
so the workflow title accurately reflects that it targets `circinus` and
`sagitta`.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In @.github/workflows/pr-auto-close.yml:
- Line 1: The workflow name "name: Auto-Close Pull Requests Sagitta" only
mentions Sagitta but the workflow handles both branches (`circinus` and
`sagitta`); update the `name:` value to include both branches (e.g., "Auto-Close
Pull Requests — Sagitta & Circinus" or similar) so the workflow title accurately
reflects that it targets `circinus` and `sagitta`.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Central YAML (inherited), Organization UI (inherited)

Review profile: CHILL

Plan: Pro Plus

Run ID: 459ed80c-a985-4ab8-bd16-c51641536ca4

📥 Commits

Reviewing files that changed from the base of the PR and between 74f4c4e and 9168089.

📒 Files selected for processing (1)
  • .github/workflows/pr-auto-close.yml
📜 Review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
  • GitHub Check: Mergify Merge Protections
  • GitHub Check: Summary
🧰 Additional context used
🔍 Remote MCP

Summary of Relevant Context for PR #5221 Review

GitHub Actions pull_request_target Event Behavior

The pull_request_target event now always uses the default branch for workflow source and reference: The workflow file and checkout commit will always be taken from the repository's default branch, regardless of the pull request's base branch. This is a critical change—these changes take effect on 12/8/2025, which is relevant to understanding the purpose of this PR fix.

Background on the PR's Issue: The PR description states it "fixes the auto-close PR workflow so the pullrequest target trigger is properly recognized when using the default branch." By default, a workflow only runs when a pull_request_target event's activity type is opened, synchronize, or reopened. The workflow in this PR is configured to trigger on opened and reopened events for branches circinus or sagitta.

Security Considerations for pull_request_target

Assess your usage of pull_request_target and use it only when necessary: Ensure user-controlled input or code cannot influence execution in a way that runs untrusted code. If your workflow does not require elevated permissions or access to secrets, use pull_request instead. Restrict permissions granted to these workflows. Configure the default token permissions to read-only or apply least-privilege settings in the workflow.

The PR correctly sets restrictive permissions (pull-requests: write and contents: read), which aligns with security best practices.

The superbrothers/close-pull-request Action

This Action subscribes to pull_request_target events. When receiving a pull_request_target event, this action closes the pull request triggered by the event immediately. The action was specifically designed to work with pull_request_target events. Version 3.0.0 was released with support for pull_request_target event.

🔇 Additional comments (3)
.github/workflows/pr-auto-close.yml (3)

7-7: LGTM!


22-22: LGTM!


3-10: LGTM!

Also applies to: 12-15, 17-20, 23-25

@sever-sever sever-sever left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We do not accept PRs for the circinus/sagitta branch in this repo.

@sever-sever
sever-sever requested a review from dmbaturin May 27, 2026 14:30

@c-po c-po left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LTS branches do not accept public PRs. Add workflow for auto closing PRs.

@c-po
c-po merged commit ab356b5 into vyos:current May 27, 2026
15 checks passed
@vyosbot vyosbot added mirror-initiated This PR initiated for mirror sync workflow mirror-completed and removed mirror-initiated This PR initiated for mirror sync workflow labels May 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

4 participants