Repository navigation
Playground preview: derive PR from the triggering run - #978
Conversation
|
Waiting to see that the generated playground env works before approving |
The publish workflow takes the head SHA from the workflow_run event and resolves the associated pull request through the API, rather than reading the PR number and commit SHA back from the build artifact name. The build artifact is located by the name the trusted build derives from that PR and SHA, keeping the published preview aligned with the commit that was built.
cb7e579 to
3cecd11
Compare
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message. To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
✅ WordPress Plugin Check Report
📊 ReportAll checks passed! No errors or warnings found. 🤖 Generated by WordPress Plugin Check Action • Learn more about Plugin Check |
|
@jeffpaul Looks like GH actions are back online |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #978 +/- ##
==========================================
Coverage 74.57% 74.57%
Complexity 3132 3132
==========================================
Files 132 132
Lines 12213 12213
==========================================
Hits 9108 9108
Misses 3105 3105
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
What
The privileged
pr-playground-preview.ymlpublisher currently reads the PR number and commit SHA out of the build artifact's name (ai-plugin-zip-pr<n>-<sha>). This change instead:workflow_runevent (context.payload.workflow_run.head_sha).The published preview and the comment target now follow from the commit that was actually built, not from artifact-supplied values.
Why
The build workflow runs on PR code with a read-only token; its artifacts (name and contents) are untrusted. Binding to the
workflow_runhead SHA keeps the publish step aligned with the triggering run.Testing
actionlintclean; embeddedgithub-scriptsyntax-checked.