Repository navigation
Conversation
Pin the reusable release and Feishu PR notification workflows from openpi-dev/automation to ac8a414 (current main), matching the full-SHA pinning used by pages.yml and the actions inside the automation workflows. Update the contract test and docs accordingly.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
feishu-pr-notification.ymlandrelease.ymlcall reusable workflows fromopenpi-dev/automationat@main. Every action in this repository (ci.yml,pages.yml,labeler.yml) is pinned to a full commit SHA, and #671 notes that the repository only allows SHA-pinned actions. These two callers are the exception, and they are the most privileged workflows we have:feishu-pr-notification.ymlruns onpull_request_targetfor fork PRs and passesFEISHU_PR_BOT_WEBHOOKandFEISHU_PR_BOT_SECRET.release.ymlgrantsid-token: writefor npm trusted publishing.With
@main, any change merged inopenpi-dev/automationstarts running here with those secrets and that OIDC authority on the next event, without review in this repository.Value
Changes to automation reach OpenPI's secrets and publish identity only through a reviewed OpenPI PR, the same way SHA-pinned actions already work. This reverses the "follow
main" choice from #279 on purpose. The cost is an SHA bump PR whenever automation changes, which has been rare: the last automation commit is from 2026-09-02.Approach
ac8a4140e4ce458a2ed693c5ec9798946ccc0dda # main, the currentmainHEAD ofopenpi-dev/automation. This uses the same@<sha> # <ref>style aspages.yml.tests/github/automation-workflows.test.tsasserted@main. It now requires a 40-hex SHA with a# maincomment and rejects any non-SHA automation ref.RELEASING.mdanddocs/contributing/feishu-pr-notifications.mdnow describe the pin.pull_request_targetreview, at the pinned revision:contents: readandpull-requests: read, passes only the two Feishu secrets (notsecrets: inherit), and never references the PR head ref. The existing contract test already enforces this.run:steps. It skips drafts and calls one action, itself SHA-pinned (actions/feishu-pr-notification@a681421). That action reads the event JSON, builds a sanitized card, signs it, andfetches the webhook. It has nochild_process, noeval, and does no shell interpolation of PR titles or bodies.labeler.yml(alsopull_request_target) is already pinned and checks out nothing.Validation
bun run check: passed.bun run test: node 2315 passed / 0 failed; UI 1158 passed.tests/github/automation-workflows.test.ts: 6/6 pass. Revertingrelease.ymlto@mainmakes the pin test fail as intended.ac8a414(gh api repos/openpi-dev/automation/contents/.github/workflows/<file>?ref=ac8a414…).Impact
.github/workflows/**, so it needs review from @tt-a1i or @openpi-dev/release-managers. Futureopenpi-dev/automationchanges take effect only after a PR here updates the SHA. For releases, the npm trusted publisher still validates the callingrelease.yml, which is unchanged apart from the ref.