Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
19 commits
Select commit Hold shift + click to select a range
b2b77a8
Add CHANGELOG.md modification check and warning comment
mario-campos Oct 8, 2026
fbd33ac
Gate comment-post step on successful fetch-base
mario-campos Oct 8, 2026
43ac64c
Use `gh api` instead of third-party Action
mario-campos Oct 8, 2026
f7aa9dc
Move post-comment step to `post-pr-comments` job
mario-campos Oct 8, 2026
780e947
Skip CHANGELOG.md modification warning for release and backport PRs
mario-campos Oct 8, 2026
ae75d46
Exclude "Mergeback" and "Update default bundle" PRs from CHANGELOG.md…
mario-campos Oct 8, 2026
6e4d3fb
Use a sticky comment to warn about CHANGELOG.md changes
mario-campos Oct 8, 2026
d97a656
Update CHANGELOG.md warning message to reference change-notes directory
mario-campos Oct 8, 2026
ccdf690
Escape backticks PR comment body
mario-campos Oct 8, 2026
928548a
Refine exclusion conditions for CHANGELOG-modification comment
mario-campos Oct 8, 2026
0707124
Delete CHANGELOG.md-modification comment if CHANGELOG.md no longer mo…
mario-campos Oct 8, 2026
27d37d9
Format all file references as inline Markdown code spans
mario-campos Oct 8, 2026
9fe741e
Simplify `if` condition of CHANGELOG-comment-post step
mario-campos Oct 8, 2026
8c8b082
Add script and Action for managing PR comments
mario-campos Oct 9, 2026
14cefaa
Replace bash/run step with local Action `post-comment`
mario-campos Oct 9, 2026
4d464b0
Improve issue ID parsing and validation logic
mario-campos Oct 9, 2026
3c452a1
Use HTTP link to `unreleased-change-notes/README.md`
mario-campos Oct 9, 2026
f1419b8
Reject empty `--marker`
mario-campos Oct 9, 2026
e7dadca
Refactor comment handling logic into `performAction` for improved tes…
mario-campos Oct 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 46 additions & 0 deletions .github/actions/post-comment/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
name: "Post comment"
description: "Create, update, or delete a sticky PR comment identified by an automatically-derived HTML-comment marker. If this action is used more than once within the same job, give each step an explicit 'id:' so the derived marker stays unique."
inputs:
body:
description: "Full comment markdown."
required: true
action-condition:
description: "The business condition ('true' or 'false') that selects which action to perform."
required: true
action-if-true:
description: "Action to perform when action-condition is 'true'. One of: none, insert, upsert, delete."
required: true
action-if-false:
description: "Action to perform when action-condition is 'false'. One of: none, insert, upsert, delete."
required: true
issue-id:
description: "The issue or pull request number to post/update/delete the comment on. Defaults to the current pull request if not provided."
required: false
token:
description: "The GitHub token to authenticate with."
required: true
runs:
using: composite
steps:
- name: Post comment
shell: bash
env:
BODY: ${{ inputs.body }}
# Derived from the workflow name, job id, and step id/sequence-number so that repeated
# runs of the same step find the same comment (for upsert/delete), while distinct steps
# (even within the same job) get distinct markers.
MARKER: <!-- post-comment:${{ github.workflow }}:${{ github.job }}:${{ github.action }} -->
GH_TOKEN: ${{ inputs.token }}
ISSUE_ID: ${{ inputs.issue-id || github.event.pull_request.number }}
ACTION_CONDITION: ${{ inputs.action-condition }}
ACTION_IF_TRUE: ${{ inputs.action-if-true }}
ACTION_IF_FALSE: ${{ inputs.action-if-false }}
run: |
npx tsx ./pr-checks/post-comment.ts \
--body "$BODY" \
--marker "$MARKER" \
--action-condition "$ACTION_CONDITION" \
--action-if-true "$ACTION_IF_TRUE" \
--action-if-false "$ACTION_IF_FALSE" \
--issue-id "$ISSUE_ID" \
--repository "$GITHUB_REPOSITORY"
60 changes: 58 additions & 2 deletions .github/workflows/pr-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -92,6 +92,8 @@ jobs:
contents: read
runs-on: ubuntu-latest
timeout-minutes: 10
outputs:
changelog-changed: ${{ steps.changelog-check.outputs.changed }}

concurrency:
cancel-in-progress: ${{ github.event_name == 'pull_request' || false }}
Expand Down Expand Up @@ -181,6 +183,20 @@ jobs:
path: ${{ runner.temp }}/repo-size/
if-no-files-found: error

- name: Check for CHANGELOG.md changes
id: changelog-check
if: steps.fetch-base.outcome == 'success'
env:
BASE_SHA: ${{ steps.fetch-base.outputs.merge_base }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
if ! git diff --exit-code --quiet "$BASE_SHA" "$HEAD_SHA" -- CHANGELOG.md; then
echo "CHANGELOG.md was modified in this PR."
echo "changed=true" >> "$GITHUB_OUTPUT"
else
echo "changed=false" >> "$GITHUB_OUTPUT"
fi

- name: "Backport: Check out base ref"
id: checkout-base
if: ${{ startsWith(github.head_ref, 'backport-') }}
Expand All @@ -201,8 +217,8 @@ jobs:
exit 1
fi

post-repo-size-comment:
name: Post repo size comment
post-pr-comments:
name: Post PR comments
needs: other-checks
# Keep write permissions isolated from the job that checks out and tests PR code. This job only
# posts the candidate comment body produced by the read-only `pr-checks` job.
Expand All @@ -222,6 +238,25 @@ jobs:
group: check-repo-size-${{ github.event.pull_request.number }}

steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Check out the base ref, not the PR's head, since this job runs with
# `pull-requests: write` permissions and must not execute untrusted code from the PR.
ref: ${{ github.event.pull_request.base.sha }}
sparse-checkout: |
pr-checks
.github/actions/post-comment

- name: Set up Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
cache: "npm"

- name: Install dependencies
run: npm ci --workspace=pr-checks

- name: Download repo size comment
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
Expand Down Expand Up @@ -251,3 +286,24 @@ jobs:
else
echo "Skipping repo size comment because the delta is below the threshold and no sticky comment exists."
fi

- name: Post a warning about modifying CHANGELOG.md
id: post-changelog-warning
# Release, backport, mergeback, and bundle-update PRs deliberately modify CHANGELOG.md,
# so skip comment management entirely for these automation flows.
if: >-
!startsWith(github.event.pull_request.head.ref, 'update-v') &&
!startsWith(github.event.pull_request.head.ref, 'backport-v') &&
!startsWith(github.event.pull_request.head.ref, 'mergeback/') &&
!startsWith(github.event.pull_request.head.ref, 'update-bundle/')
uses: ./.github/actions/post-comment
Comment thread
mario-campos marked this conversation as resolved.
with:
body: |
⚠️ `CHANGELOG.md` has been modified in this PR. Please do not modify `CHANGELOG.md` directly.
Instead, create a change-note file in `unreleased-change-notes/`. The `CHANGELOG.md`
file will be automatically generated from those change-notes.
See [`unreleased-change-notes/README.md`](https://github.com/github/codeql-action/blob/main/unreleased-change-notes/README.md) for more information.
action-condition: ${{ needs.other-checks.outputs.changelog-changed }}
action-if-true: upsert
action-if-false: delete
token: ${{ secrets.GITHUB_TOKEN }}
Loading
Loading