Auto-assign on fork PRs via pull_request_target#112
Conversation
WalkthroughThe auto-assign workflow now runs for fork-submitted pull requests through ChangesAuto-assign workflow
Estimated code review effort: 1 (Trivial) | ~5 minutes Possibly related PRs
Suggested reviewers: Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/autoassign.yml:
- Around line 3-9: Update the reusable workflow reference in autoassign.yml from
the mutable main branch to a specific immutable commit SHA, preserving the
existing workflow path and permissions configuration.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: dac3febc-b731-4670-bdea-8f06f4cbf5ba
📒 Files selected for processing (1)
.github/workflows/autoassign.yml
| # pull_request_target (not pull_request) so auto-assign works on | ||
| # fork-submitted PRs; fork pull_request runs only get a read-only token. | ||
| # Safe because this workflow never checks out or executes PR code. | ||
| on: | ||
| issues: | ||
| types: [opened] | ||
| pull_request: | ||
| pull_request_target: |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
printf '\n== autoassign workflow ==\n'
cat -n .github/workflows/autoassign.yml
printf '\n== ApolloAutomation references ==\n'
rg -n "ApolloAutomation/Workflows|uses:" .github/workflows -SRepository: ApolloAutomation/AIR-1
Length of output: 1409
🏁 Script executed:
#!/bin/bash
set -euo pipefail
cat -n .github/workflows/autoassign.yml
rg -n "ApolloAutomation/Workflows|uses:" .github/workflows -SRepository: ApolloAutomation/AIR-1
Length of output: 1347
Pin the reusable workflow to a commit SHA.
.github/workflows/autoassign.yml still calls ApolloAutomation/Workflows/.github/workflows/autoassign.yml@main with issues: write and pull-requests: write (line 18). A change on that branch would run here with repository write access.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/autoassign.yml around lines 3 - 9, Update the reusable
workflow reference in autoassign.yml from the mutable main branch to a specific
immutable commit SHA, preserving the existing workflow path and permissions
configuration.
Standardize auto-assign so it runs on PRs opened from forks.
The auto-assign workflow triggers on
pull_request(or skips forks via anif:guard), so fork-submitted PRs never get auto-assigned — forkpull_requestruns only receive a read-onlyGITHUB_TOKEN. This switches topull_request_target, drops the fork-skip guard, and pins the assignee to bharvey88.pull_request_targetruns in the base-repo context with a write token. Safe here because the workflow never checks out or executes PR code — it only assigns.Targeting the default branch (
main) because GitHub runs the auto-assign workflow from the default branch forissues/pull_request_targetevents; a fix only onbetawould stay inert. Matches ApolloAutomation/MSR-2#84.🤖 Generated with Claude Code
Summary by CodeRabbit