From 39326249471dd8582e50f4170aebcdcbd91ac5f7 Mon Sep 17 00:00:00 2001 From: silverwind Date: Sat, 3 Oct 2026 11:36:38 +0200 Subject: [PATCH] ci: relay fork PR reviews to giteabot through workflow_run (#39546) `pull_request_review` runs on fork PRs, which includes all backport PRs, get a read-only token and no secrets, so giteabot cannot write lgtm labels and statuses there. A no-op `giteabot-review` workflow now triggers giteabot through `workflow_run`, which gets both. This allows retiring the legacy fly.io webhook bot. Part of https://github.com/go-gitea/giteabot/issues/15 --- .github/workflows/giteabot-backport.yml | 2 +- .github/workflows/giteabot-review.yml | 19 +++++++++++++++++++ .github/workflows/giteabot.yml | 21 +++++++++------------ 3 files changed, 29 insertions(+), 13 deletions(-) create mode 100644 .github/workflows/giteabot-review.yml diff --git a/.github/workflows/giteabot-backport.yml b/.github/workflows/giteabot-backport.yml index e44fb9b7bfa..b2d8b19247c 100644 --- a/.github/workflows/giteabot-backport.yml +++ b/.github/workflows/giteabot-backport.yml @@ -19,7 +19,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 30 steps: - - uses: go-gitea/giteabot@4c9d4d3fd913b5c35f59dcc0b004a3d11d5b22bf # v1.0.7 + - uses: go-gitea/giteabot@f48c6a15e0d384f037aea19cc05ff5e9551096b9 # v1.1.0 with: github_token: ${{ secrets.GITEABOT_TOKEN }} gitea_fork: giteabot/gitea diff --git a/.github/workflows/giteabot-review.yml b/.github/workflows/giteabot-review.yml new file mode 100644 index 00000000000..d9ba62b73d8 --- /dev/null +++ b/.github/workflows/giteabot-review.yml @@ -0,0 +1,19 @@ +name: giteabot-review + +# Relays PR reviews to giteabot.yml through its workflow_run trigger, because review +# runs on fork PRs get no secrets and a read-only token. The job itself does nothing. + +on: + pull_request_review: + types: + - submitted + - edited + - dismissed + +permissions: {} + +jobs: + relay: + runs-on: ubuntu-latest + steps: + - run: "true" diff --git a/.github/workflows/giteabot.yml b/.github/workflows/giteabot.yml index 3e1407165ea..867773b3623 100644 --- a/.github/workflows/giteabot.yml +++ b/.github/workflows/giteabot.yml @@ -20,13 +20,12 @@ on: - closed - review_requested - review_request_removed - # Review events keep review-derived state such as lgtm labels and status checks - # in sync after approvals, edits, or dismissals. - pull_request_review: + # Reviews arrive through giteabot-review because fork PR review runs get no secrets + workflow_run: + workflows: + - giteabot-review types: - - submitted - - edited - - dismissed + - requested # Periodic maintenance is still useful as a backstop for queue cleanup and # other housekeeping, even though main pushes now trigger it promptly. schedule: @@ -43,12 +42,12 @@ on: permissions: {} concurrency: - group: ${{ format('{0}-{1}', github.workflow, (github.event_name == 'pull_request_target' || github.event_name == 'pull_request_review') && format('pr-{0}', github.event.pull_request.number) || 'maintenance') }} + group: ${{ format('{0}-{1}', github.workflow, github.event_name == 'pull_request_target' && format('pr-{0}', github.event.pull_request.number) || github.event_name == 'workflow_run' && format('review-{0}', github.event.workflow_run.head_sha) || 'maintenance') }} cancel-in-progress: false jobs: giteabot: - if: github.repository == 'go-gitea/gitea' + if: github.repository == 'go-gitea/gitea' && (github.event_name != 'workflow_run' || github.event.workflow_run.event == 'pull_request_review') runs-on: ubuntu-latest timeout-minutes: 30 permissions: @@ -57,9 +56,7 @@ jobs: pull-requests: write statuses: write steps: - # pull_request_review runs without repository secrets on fork PRs, so fall - # back to the workflow token for the non-backport checks handled here. - - uses: go-gitea/giteabot@4c9d4d3fd913b5c35f59dcc0b004a3d11d5b22bf # v1.0.7 + - uses: go-gitea/giteabot@f48c6a15e0d384f037aea19cc05ff5e9551096b9 # v1.1.0 with: - github_token: ${{ secrets.GITEABOT_TOKEN || github.token }} + github_token: ${{ secrets.GITEABOT_TOKEN }} checks: ${{ github.event.inputs.checks || 'labels,merge_queue,lock,feedback,last_call,milestones,lgtm,translation_comment,pr_actions' }}