Skip to content

feat: new action review-post-release-pr - #227

Merged
kelly-sovacool merged 25 commits into
mainfrom
iss-209
Sep 28, 2026
Merged

kelly-sovacool merged 25 commits into
mainfrom
iss-209

Conversation

@kelly-sovacool

@kelly-sovacool kelly-sovacool commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Changes

  • New composite action review-post-release-pr: automatically reviews post-release cleanup PRs opened by the post-release action.
    • Approves pending workflow runs, approves the PR, and enables squash auto-merge when the only changes are version/date bumps (in the version file, CITATION.cff, codemeta.json, changelog/news file, and/or readme files) that correspond to an actual GitHub release tag. A readme's re-rendered citation snippet (from auto-format) is accepted the same way.
    • Otherwise posts a comment listing the unmet conditions and requests a human reviewer, resolved from: the reviewer input, the actor that triggered the most recent draft-release.yml run, or the repo's default (catch-all *) CODEOWNERS entry.
  • Added review-post-release-pr as a job in the pre-review-pr.yml example workflow, including a workflow_dispatch re-scan job mirroring the existing review-pre-commit-pr job.
  • New ccbr_actions.post_release_pr module with the review/validation logic, plus new generic helpers in ccbr_actions.pr_review (approve_pending_workflow_runs, get_last_workflow_run_actor).
  • Unit tests for the new module and helpers, using a realistic fixture based on chore: post-release cleanup for v0.7.1 Tools#229.

Issues

Resolves #209

PR Checklist

  • This comment contains a description of changes with justifications, with any relevant issues linked.
  • Write unit tests for any new features, bug fixes, or other code changes.
  • Update docs if there are any API changes.
  • Update CHANGELOG.md with a short description of any user-facing changes and reference the PR number. Guidelines: https://keepachangelog.com/en/1.1.0/

AI-assisted: Claude Sonnet 5 via Copilot

@kelly-sovacool
kelly-sovacool marked this pull request as ready for review September 25, 2026 16:48
@codecov

codecov Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.70%. Comparing base (fcda5a8) to head (8605fef).

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #227      +/-   ##
==========================================
+ Coverage   98.18%   98.70%   +0.52%     
==========================================
  Files          13       14       +1     
  Lines         881     1239     +358     
==========================================
+ Hits          865     1223     +358     
  Misses         16       16              
Flag Coverage Δ
python 98.70% <100.00%> (+0.52%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The validator has multiple paths that can approve unvalidated changes, and the example references a release without the new action.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 6 High severity · 1 Medium severity

Open (7)
What changed in this PR

Adds automated review and approval for post-release cleanup PRs.

Changes:

  • Adds validation, reviewer resolution, workflow approval, and auto-merge logic.
  • Adds the composite action, documentation, workflow example, and changelog entry.
  • Adds comprehensive Python unit tests.
File Description
src/​ccbr_actions/​post_release_pr.py Implements review policy and automation.
src/​ccbr_actions/​pr_review.py Adds shared workflow-run helpers.
review-post-release-pr/​action.yml Defines the composite action.
review-post-release-pr/​README.qmd Adds source documentation.
review-post-release-pr/​README.md Adds rendered documentation.
review-pre-commit-pr/​README.qmd Simplifies the existing example.
review-pre-commit-pr/​README.md Updates rendered documentation.
examples/​pre-review-pr.yml Integrates post-release PR review.
tests/​test_post_release_pr.py Tests the new review policy.
tests/​test_pr_review.py Tests shared helper additions.
tests/​test_action_test_coverage.py Registers the API-only action exemption.
README.md Lists the new action.
CHANGELOG.md Records the user-facing feature.
.gitignore Ignores uv.lock.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread examples/pre-review-pr.yml
Comment thread src/ccbr_actions/post_release_pr.py
Comment thread src/ccbr_actions/post_release_pr.py Outdated
Comment thread src/ccbr_actions/post_release_pr.py Outdated
Comment thread src/ccbr_actions/post_release_pr.py
Comment thread src/ccbr_actions/post_release_pr.py Outdated
Comment thread examples/pre-review-pr.yml Outdated
kelly-sovacool and others added 2 commits September 25, 2026 13:52
…#227

- Audit that the version file was actually bumped, not just that changed files are allowed.
- Replace generic per-token diff validation with field-specific validators (version, R DESCRIPTION, CITATION.cff, codemeta.json, changelog heading insertion, readme) using full file content instead of GitHub's patch field.
- Paginate get_pr_files and fail closed on a pagination/changed_files count mismatch.
- Pin approvals to the validated head commit, recheck it immediately before approving, and abort if it changed concurrently.
- Track approvals per-commit (is_pr_approved_for_commit) so a stale approval left before an auto-format push no longer short-circuits re-validation.
- Add synchronize to the pull_request trigger so auto-format pushes are re-reviewed.
- Fix the example workflow's action ref: review-post-release-pr isn't in any release yet, so use @main until the next release.

_commit message is ai-generated_

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread src/ccbr_actions/post_release_pr.py Outdated
Comment thread src/ccbr_actions/post_release_pr.py Outdated
Comment thread src/ccbr_actions/post_release_pr.py
Comment thread src/ccbr_actions/pr_review.py
Comment thread src/ccbr_actions/post_release_pr.py Outdated
Comment thread src/ccbr_actions/post_release_pr.py Outdated
Comment thread tests/test_examples.py Outdated
kelly-sovacool and others added 8 commits September 25, 2026 14:09
…quests

Track a per-commit marker in the human-review comment so a synchronize-triggered re-run doesn't spam duplicate comments and reviewer requests for a PR that still fails the same commit's validation. force-review still overrides the skip.

_commit message is ai-generated_
…eedback

- Tighten readme validation to only accept version/date token bumps within a recognized citation context (version mention or bibtex month/year), not any line whose token coincidentally matches.
- Rewrite the codemeta.json validator to compare old vs new content and only permit version/date fields to change, matching the release.
- Require CITATION.cff/codemeta.json date fields to exactly match the release's published/created date instead of only checking the date shape.
- Filter approved workflow runs to the validated commit's exact head SHA, not just branch name, and approve them only after the head-SHA concurrency recheck (previously runs could be approved before an aborted approval was detected).
- Route PRs with an active human CHANGES_REQUESTED review to human review instead of treating 'not yet approved' as permission to auto-approve.
- Fix the version-bump audit for R packages where the version and description files are the same DESCRIPTION file (a validated description role no longer gets silently ignored).
- Make the examples test's @main exception for unreleased actions self-expiring, tied to the release it was written against.

_commit message is ai-generated_
The review-post-release-pr job's synchronize branch had no sender check,
so anyone able to push to a PR titled "chore: post-release cleanup for
..." could trigger the elevated CCBR-bot review token. Require
sender.type == 'Bot' for opened/synchronize, matching the existing
review_requested check. Also restores the bot-sender check in the
README "Example" snippets for review-pre-commit-pr and
review-post-release-pr, which had been simplified away.

_AI-assisted: Claude Sonnet 5 via Copilot_
…thon

review-post-release-pr and review-pre-commit-pr spliced `${{ inputs.* }}`
directly into the literal text of an embedded `shell: python {0}` script.
Any value expanded there is exploitable as a template-injection vector
(GitHub expands the template before Python ever sees the source). Move
each value into a step-level `env:` and read it via `os.environ[...]`
instead.

_AI-assisted: Claude Sonnet 5 via Copilot_
_validate_codemeta_file treated a previously-present dateModified/
datePublished/dateCreated field going missing as an unchanged field,
silently accepting the removal as a valid bump. Require the field to
either stay unchanged or be present and match a release date.

_AI-assisted: Claude Sonnet 5 via Copilot_
kelly-sovacool and others added 3 commits September 28, 2026 12:01
Note that it returns the actor for the most recent run of the given
workflow file repo-wide, not necessarily the run tied to the specific
release/PR under review.

_AI-assisted: Claude Sonnet 5 via Copilot_
_AI-assisted: Claude Sonnet 5 via Copilot_
@kelly-sovacool
kelly-sovacool merged commit 4f51c7f into main Sep 28, 2026
17 checks passed
@kelly-sovacool
kelly-sovacool deleted the iss-209 branch September 28, 2026 16:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

auto-approve post-release cleanup PRs

2 participants