Skip to content

ci: add a PR gate for pull requests from outside contributors - #383

Merged
allen0099 merged 1 commit into
masterfrom
ci/pr-gate
Sep 29, 2026
Merged

allen0099 merged 1 commit into
masterfrom
ci/pr-gate

Conversation

@allen0099

Copy link
Copy Markdown
Owner

The repository gets unrequested pull requests from accounts that open hundreds of them a month. #379, for example, was a one-line change with no test and no changelog fragment. This adds a check that filters those out before a maintainer reads them, using the rules in the contributing guide.

What the gate does

It runs only for outside contributors. OWNER, MEMBER and COLLABORATOR authors are exempt, and so are bots such as Renovate and Dependabot.

Condition Result
The description does not close an issue (Fixes #N, owner/repo#N or the issue URL) Comment, close, check fails
The linked issue is not assigned to the PR author Comment, close, check fails
A change under fastapi_cachex/ has no test under tests/, or no changelog.d/<issue>.<section>.md Comment, check fails, PR stays open and is re-checked on every push or edit
The skip-pr-gate label is present Skipped (maintainer override, e.g. for a refactor that needs no fragment)
  • The gate keeps one comment per pull request, marked <!-- pr-gate -->, and updates it instead of posting again.
  • A concurrency group serializes runs per pull request.
  • At most 10 referenced issues are looked up.

Security

The workflow uses pull_request_target, so it can comment on and close pull requests from forks. That is safe here only because it never checks out or runs code from the pull request:

  • there is no run: step and no checkout;
  • no ${{ }} expression inside the script;
  • pull request data is read as JS values from the event payload and the API.

Permissions are issues: read and pull-requests: write, with permissions: {} at the top level. zizmor's dangerous-triggers finding is suppressed inline, with that justification.

Docs

  • docs/CONTRIBUTING.md and the zh-TW mirror gain a "Before You Open a Pull Request" section: claim the issue, wait for assignment, then open the PR. It also covers what the gate does and how a maintainer overrides it.
  • A new .github/pull_request_template.md points to that section.

Testing

  • I ran the script body locally against a mocked github/context/core in 15 scenarios, covering:
    • no linked issue, an unassigned issue, and an assigned issue (case-insensitive login);
    • the #N, owner/repo#N and URL forms, and suffixes #3 not matching;
    • a PR number, a 404 and a 410 reference, and a body with 1000 references (capped at 10 lookups);
    • missing tests or fragment, and a removed fragment not counting;
    • updating the earlier comment, the skip label, and another bot's marker comment being ignored.
  • An independent review also checked the workflow for injection and permission problems.
  • The skip-pr-gate label has been created.
  • The first real run will be the next outside pull request.

Mass-PR accounts open unrequested one-line pull requests without tests or a
changelog fragment. The PR gate closes a pull request from an outside
contributor that does not close an issue assigned to its author, and fails
with a comment when a change to fastapi_cachex/ lacks a test or a fragment.
Maintainers, collaborators and bots are exempt; the skip-pr-gate label
waives the check.

It runs on pull_request_target so it can comment and close on fork pull
requests, and reads the pull request only through the API: no pull request
code is checked out or run.

CONTRIBUTING (en and zh-TW) documents the rules, and a pull request template
points to them.
@allen0099 allen0099 added enhancement New feature or request ci CI workflows, test suite and tooling labels Sep 29, 2026
@allen0099
allen0099 merged commit f89a3b4 into master Sep 29, 2026
12 checks passed
@allen0099
allen0099 deleted the ci/pr-gate branch September 29, 2026 12:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci CI workflows, test suite and tooling enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant