ci: check the changelog without checking out fork code - #1918
Open
Jahongir-Qurbonov wants to merge 1 commit into
Open
Jahongir-Qurbonov wants to merge 1 commit into
Jahongir-Qurbonov wants to merge 1 commit into
Conversation
The changelog check fails on every pull request from a fork, whether or not a newsfragment was added: `actions/checkout` refuses to check out fork code from a `pull_request_target` workflow, so `towncrier check` never runs and the `if: failure()` step posts the "Changelog is required!" comment anyway. Keep the workflow on `pull_request_target`, since commenting on fork pull requests needs a token with write access, but stop checking out the fork. Only the base repository is checked out, the list of changed files comes from the API, and `.github/scripts/check_changelog.py` applies the same rules as `towncrier check`, reading the fragment directory, news file and categories from the base repository's `pyproject.toml`. Also drop the `pip install -U towncrier` step, so the job no longer depends on whichever towncrier release is current, and declare least-privilege permissions. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
❌ Changelog is required!You need to add a brief description of the changes to the Changes file should be named like The content of the file should be a brief description of the changes in Possible categories are: |
Contributor
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
The changelog check currently fails on every pull request opened from a fork, regardless of whether a
newsfragment was added.
actions/checkoutnow refuses to check out fork code from apull_request_targetworkflow:Because the checkout step fails,
towncrier checknever runs, and theif: failure()step posts the"Changelog is required!" comment even when the fragment is there. Recent examples: #1917 (has
CHANGES/1876.bugfix.rst) and #1916.Fix
The workflow keeps running on
pull_request_target, since commenting on fork pull requests needs atoken with write access, but it no longer checks out the fork:
gh api repos/{repo}/pulls/{number}/files;.github/scripts/check_changelog.pyapplies the same rules astowncrier check, reading thetowncrier configuration (fragment directory, news file, categories) from the base repository's
pyproject.toml, so the categories stay in one place;permissionsare added (contents: read,pull-requests: write).The
pip install -U towncrierstep goes away with it, so the job no longer depends on whatevertowncrier release is current.
The bot comment steps are unchanged.
Behaviour
The script matches
towncrier checkon the cases that matter:CHANGES/1876.bugfix.rstCHANGES.rst(release build)CHANGES/.template.rst.jinja2onlyCHANGES/1234.bugfixes.rst(typo in category)CHANGES/+orphan.misc.rstNote
pull_request_targetworkflows run from the base branch, so this pull request will itself be checked bythe current, broken version of the workflow and its
changes-requiredcheck will fail the same way.The fix only takes effect once it is merged into
dev-3.x.Alternatives considered
allow-unsafe-pr-checkout: trueon the checkout step restores the old behaviour in one line, but itopts back into exactly the risk the guard describes: towncrier would read the fork's
pyproject.tomland jinja2 template in a job holding the base repository's token.
pull_requestjob plus aworkflow_runjob that comments is the other standardpattern, but it is a much larger change for the same outcome.
🤖 Generated with Claude Code