Repository navigation
ci: require shared installer confirmation through PR comments - #108
Closed
karthikbekalp wants to merge 1 commit into
Closed
karthikbekalp wants to merge 1 commit into
karthikbekalp wants to merge 1 commit into
Conversation
Signed-off-by: Karthik BekalPattathana <133984042+karthikbekalp@users.noreply.github.com>
This was referenced Oct 7, 2026
Closed
Closed
| if isinstance(sha, str) and re.fullmatch(r"[0-9a-f]{40}", sha): | ||
| try: | ||
| set_status(repo, sha, "error", DATA_ERROR, run_url) | ||
| except (OSError, subprocess.CalledProcessError, json.JSONDecodeError, TypeError, ValueError): |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Installer definition changes can require a corresponding update to the shared Deadline Cloud submitter installer. Add a static confirmation check that asks the PR author or a maintainer through one public PR comment.
The checker watches XML definitions under
installer/andinstall_builder/, including additions, deletions, nested files, and both sides of renames. It creates or updates one bot comment and accepts exactly one of these commands in a new PR conversation comment:/installer-followup done/installer-followup in-review/installer-followup not-neededAccepted commands update the same comment and make the
Installer coordinationstatus pass. Missing confirmation keeps it failing; editing or deleting the only valid response makes it fail again. Unrelated PRs pass without a question. Maintainer replies require current write, maintain, or admin permission. The checker uses fixed public wording and never echoes reply text, review identifiers, or tracking links.The reusable workflow supports trusted
pull_request_targetandissue_commentcallers, including fork PRs. It checks out only central tooling and never executes PR code. It explicitly publishes the status on the current PR head because comment events run on the default branch. Incomplete or stale API data and posting failures produce an error instead of a successful result.Validation: all 88 Python 3.13 unit tests pass, including 30 new tests for detection, command permissions, comment reuse, response edits/deletions, fork-head status updates, and error handling. Actionlint and zizmor validation passes for the reusable workflow and all 10 callers. The trusted-trigger annotation documents why
pull_request_targetis safe here: only central tooling is checked out and PR data is never executed.Merge this central workflow before the caller PRs. After a caller runs, configure the
Installer coordinationcommit status as required in the repository'smainlinebranch protection rule or ruleset to enforce confirmation before merge. The setup guide documents the commands, permissions, caller workflow, and rollout.Caller rollout drafts (each contains only the new caller workflow):