Skip to content

fix(ci): restore PR comments with validated artifacts - #1981

Merged
pront merged 3 commits into
mainfrom
pront-fix-pr-comment-permissions-ci
Oct 6, 2026
Merged

pront merged 3 commits into
mainfrom
pront-fix-pr-comment-permissions-ci

Conversation

@pront

@pront pront commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Summary

Motivation

Missing permissions prevent failure comments from reaching PRs. Restoring write access also requires validating untrusted artifacts.

Changes

Grant PR write access to both comment jobs, isolate downloaded artifacts, and validate the target PR before commenting.

How did you test this PR?

Passed ci-sandbox regressions for permissions and comment lifecycle and artifact isolation and PR validation. Actual fork workflow_run dispatch remains untested.

Does this PR include user-facing changes?

  • No.

Checklist

  • Read the contributor guidelines.

References

Failed comment job for PR #1979

@pront
pront requested a review from a team as a code owner October 2, 2026 21:21
@pront pront added the no-changelog Changes in this PR do not need user-facing explanations in the release changelog label Oct 2, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T20:29:17.085626Z b9839e2 New commits
🔒 Security Review ✅ Completed 2026-10-05T20:30:07.266821Z b9839e2 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@datadoghq-integration datadoghq-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bits Code Review: FAIL

The generated-docs path grants write access while trusting an artifact-controlled PR number, allowing a malicious fork run to direct the bot’s comment to an unrelated PR.

Open Bits AI session

🤖 Bits Code Review · Commit 259be6a · @DataDog review to ask questions

Comment thread .github/workflows/comment_on_pr.yml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 259be6a7f6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/comment_on_pr.yml
@pront pront changed the title fix(ci): grant PR comment workflows write permission fix(ci): restore PR comments with validated artifacts Oct 5, 2026
@pront
pront added this pull request to the merge queue Oct 5, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 5, 2026
@pront
pront enabled auto-merge October 5, 2026 20:27
@pront
pront added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 09f1cd8 Oct 6, 2026
32 of 45 checks passed
@pront
pront deleted the pront-fix-pr-comment-permissions-ci branch October 6, 2026 14:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog Changes in this PR do not need user-facing explanations in the release changelog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants