Copilot commented on code in PR #13501: URL: https://github.com/apache/gravitino/pull/13501#discussion_r4091804716
########## .github/workflows/label-fix-version.yml: ########## @@ -0,0 +1,149 @@ +# +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. +# + +# Label the issues fixed by a merged PR with the version that the PR's base +# branch is going to release, e.g. main (2.0.0-SNAPSHOT) -> "2.0.0", +# branch-1.2 (1.2.2-SNAPSHOT) -> "1.2.2". If a release on the base branch is +# still in progress (RC tagged but not released), that release is used +# instead, e.g. branch-1.3 (1.3.2-SNAPSHOT, v1.3.1-rc2 only) -> "1.3.1". +# Unassigned issues are also assigned to the PR author. +# +# Issues are taken only from "[#123]" in the PR title and from the PR's +# closing keywords (e.g. "Fix: #123"). PRs without an issue are skipped. +# +# This uses pull_request_target so that PRs from forks get a token that can +# write labels. It never checks out PR code, and all PR-controlled values are +# passed through env to avoid script injection. + +name: Label issues with fix version and assign author + +on: + pull_request_target: + types: [closed] + +permissions: + issues: write + pull-requests: read + contents: read + +jobs: + label-fix-version: + if: github.event.pull_request.merged == true + runs-on: ubuntu-latest + steps: + - name: Label linked issues + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + REPO: ${{ github.repository }} + PR_NUMBER: ${{ github.event.pull_request.number }} + PR_TITLE: ${{ github.event.pull_request.title }} + BASE_REF: ${{ github.event.pull_request.base.ref }} + PR_AUTHOR: ${{ github.event.pull_request.user.login }} + PR_AUTHOR_TYPE: ${{ github.event.pull_request.user.type }} + run: | + set -euo pipefail + + # 1. Collect issue numbers from the title and closing keywords. Title + # ids may come as "[#1][#2]", "[#1 ][#2]" or "[#1, #2]"; the trailing + # "(#PR)" is not in brackets and is ignored. + TITLE_ISSUES=$(printf '%s' "$PR_TITLE" | grep -oE '\[[^]]*\]' | grep -oE '#[0-9]+' \ + | tr -d '#' || true) Review Comment: This pattern accepts any bracketed text containing `#<number>`, not just the documented `[#N]` form. A title such as `[docs #42]` would therefore label and potentially assign issue #42 even though it is not an issue reference; restrict the bracket contents to `#`, digits, commas, and whitespace before extracting numbers. ########## .github/workflows/label-fix-version.yml: ########## @@ -0,0 +1,149 @@ +# +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. +# + +# Label the issues fixed by a merged PR with the version that the PR's base +# branch is going to release, e.g. main (2.0.0-SNAPSHOT) -> "2.0.0", +# branch-1.2 (1.2.2-SNAPSHOT) -> "1.2.2". If a release on the base branch is +# still in progress (RC tagged but not released), that release is used +# instead, e.g. branch-1.3 (1.3.2-SNAPSHOT, v1.3.1-rc2 only) -> "1.3.1". +# Unassigned issues are also assigned to the PR author. +# +# Issues are taken only from "[#123]" in the PR title and from the PR's +# closing keywords (e.g. "Fix: #123"). PRs without an issue are skipped. +# +# This uses pull_request_target so that PRs from forks get a token that can +# write labels. It never checks out PR code, and all PR-controlled values are +# passed through env to avoid script injection. + +name: Label issues with fix version and assign author + +on: + pull_request_target: + types: [closed] + +permissions: + issues: write + pull-requests: read + contents: read + +jobs: + label-fix-version: + if: github.event.pull_request.merged == true + runs-on: ubuntu-latest + steps: + - name: Label linked issues + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + REPO: ${{ github.repository }} + PR_NUMBER: ${{ github.event.pull_request.number }} + PR_TITLE: ${{ github.event.pull_request.title }} + BASE_REF: ${{ github.event.pull_request.base.ref }} + PR_AUTHOR: ${{ github.event.pull_request.user.login }} + PR_AUTHOR_TYPE: ${{ github.event.pull_request.user.type }} + run: | + set -euo pipefail + + # 1. Collect issue numbers from the title and closing keywords. Title + # ids may come as "[#1][#2]", "[#1 ][#2]" or "[#1, #2]"; the trailing + # "(#PR)" is not in brackets and is ignored. + TITLE_ISSUES=$(printf '%s' "$PR_TITLE" | grep -oE '\[[^]]*\]' | grep -oE '#[0-9]+' \ + | tr -d '#' || true) + CLOSING_ISSUES=$(gh api graphql \ + -F owner="${REPO%/*}" -F name="${REPO#*/}" -F number="$PR_NUMBER" \ + -f query=' + query($owner: String!, $name: String!, $number: Int!) { + repository(owner: $owner, name: $name) { + pullRequest(number: $number) { + closingIssuesReferences(first: 50) { + nodes { number repository { nameWithOwner } } Review Comment: `closingIssuesReferences(first: 50)` silently truncates the linked-issue set. A PR can close more than 50 issues, so references after the first page are never labeled or assigned. Iterate the connection with its cursor until all pages are consumed instead of relying on a fixed first page. ########## .github/workflows/label-fix-version.yml: ########## @@ -0,0 +1,149 @@ +# +# Licensed to the Apache Software Foundation (ASF) under one +# or more contributor license agreements. See the NOTICE file +# distributed with this work for additional information +# regarding copyright ownership. The ASF licenses this file +# to you under the Apache License, Version 2.0 (the +# "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. +# + +# Label the issues fixed by a merged PR with the version that the PR's base +# branch is going to release, e.g. main (2.0.0-SNAPSHOT) -> "2.0.0", +# branch-1.2 (1.2.2-SNAPSHOT) -> "1.2.2". If a release on the base branch is +# still in progress (RC tagged but not released), that release is used +# instead, e.g. branch-1.3 (1.3.2-SNAPSHOT, v1.3.1-rc2 only) -> "1.3.1". +# Unassigned issues are also assigned to the PR author. +# +# Issues are taken only from "[#123]" in the PR title and from the PR's +# closing keywords (e.g. "Fix: #123"). PRs without an issue are skipped. +# +# This uses pull_request_target so that PRs from forks get a token that can +# write labels. It never checks out PR code, and all PR-controlled values are +# passed through env to avoid script injection. + +name: Label issues with fix version and assign author + +on: + pull_request_target: + types: [closed] + +permissions: + issues: write + pull-requests: read + contents: read + +jobs: + label-fix-version: + if: github.event.pull_request.merged == true + runs-on: ubuntu-latest + steps: + - name: Label linked issues + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + REPO: ${{ github.repository }} + PR_NUMBER: ${{ github.event.pull_request.number }} + PR_TITLE: ${{ github.event.pull_request.title }} + BASE_REF: ${{ github.event.pull_request.base.ref }} + PR_AUTHOR: ${{ github.event.pull_request.user.login }} + PR_AUTHOR_TYPE: ${{ github.event.pull_request.user.type }} + run: | + set -euo pipefail + + # 1. Collect issue numbers from the title and closing keywords. Title + # ids may come as "[#1][#2]", "[#1 ][#2]" or "[#1, #2]"; the trailing + # "(#PR)" is not in brackets and is ignored. + TITLE_ISSUES=$(printf '%s' "$PR_TITLE" | grep -oE '\[[^]]*\]' | grep -oE '#[0-9]+' \ + | tr -d '#' || true) + CLOSING_ISSUES=$(gh api graphql \ + -F owner="${REPO%/*}" -F name="${REPO#*/}" -F number="$PR_NUMBER" \ + -f query=' + query($owner: String!, $name: String!, $number: Int!) { + repository(owner: $owner, name: $name) { + pullRequest(number: $number) { + closingIssuesReferences(first: 50) { + nodes { number repository { nameWithOwner } } + } + } + } + }' \ + --jq '.data.repository.pullRequest.closingIssuesReferences.nodes[] + | select(.repository.nameWithOwner == env.REPO) | .number' || true) Review Comment: The `|| true` converts any GraphQL/API failure into an empty closing-issue result, so a transient permissions or service error can make the workflow succeed while silently skipping issues referenced only by closing keywords. An empty `nodes` array already produces no output, so let the API failure propagate and fail the job for retry/visibility. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
