Skip to content

feat(github): export check-run pull identity parser - #284

Merged
kjgbot merged 2 commits into
mainfrom
codex/check-run-pr-identity-0925
Sep 25, 2026
Merged

kjgbot merged 2 commits into
mainfrom
codex/check-run-pr-identity-0925

Conversation

@kjgbot

@kjgbot kjgbot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Cloud PR AgentWorkforce/cloud#3987 needs a provider-owned normalization boundary for check_run.pull_requests[] identities.

This adds a dependency-free @relayfile/adapter-github/webhook-identity export that:

  • accepts canonical GitHub API and HTML pull-request URLs
  • validates the expected owner/repository and exact GitHub origin
  • rejects malformed, foreign, non-HTTPS, credentialed, port-qualified, and unsafe-number identities
  • preserves URL-authoritative behavior when GitHub supplies both URL and number

Validation:

  • npx turbo test typecheck --filter=@relayfile/adapter-github (407/407 tests)
  • npx turbo build typecheck test (157/157 tasks across 52 packages)
  • npm pack --dry-run --json --workspace=@relayfile/adapter-github (new dist JS/types included)
  • git diff --check

After merge, publish a patch release and update Cloud #3987 to consume this export before resolving its adapter-boundary review thread.


Note

Low Risk
Additive public API and tests only; no changes to existing adapter routing or inbound behavior, though downstream webhook identity logic will depend on this validation boundary.

Overview
Adds @relayfile/adapter-github/webhook-identity as a new subpath export with githubCheckRunPullRequestNumber, a dependency-free helper for normalizing one check_run.pull_requests[] entry into a PR number or null.

When no url/html_url is present it accepts a positive safe integer number. When a URL field exists it is authoritative (including empty/malformed values): it parses canonical api.github.com/repos/.../pulls/N and github.com/.../pull/N paths case-insensitively, requires HTTPS and exact GitHub origins, and fails closed on wrong owner/repo, foreign hosts, credentialed URLs, bad paths, and unsafe PR numbers. Build wiring (tsconfig, package.json exports) and node tests cover the matrix; CHANGELOG documents the export for webhook consumers (e.g. Cloud #3987).

Reviewed by Cursor Bugbot for commit a19457b. Bugbot is set up for automated code reviews on this repo. Configure here.

Session-Id: 01a0d618-8d1e-7303-aae8-049e5ba404f5
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 6d41c025-fc98-4488-bfac-9d4379ece495


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 3 potential issues.

1 flag not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)

Devin Review

Comment thread packages/github/src/webhook-identity.ts Outdated
Comment thread packages/github/src/webhook-identity.ts Outdated
Comment thread packages/github/src/webhook-identity.ts Outdated
@kjgbot

kjgbot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

To use Codex here, create a Codex account and connect to github.

Session-Id: 01a0d618-8d1e-7303-aae8-049e5ba404f5
@kjgbot
kjgbot merged commit 1aa9f5a into main Sep 25, 2026
4 checks passed
@kjgbot
kjgbot deleted the codex/check-run-pr-identity-0925 branch September 25, 2026 03:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant