mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-10-08 08:02:27 +00:00
* ci: skip the AI reviews and the Discord notice on Dependabot PRs
They already do not review them, they just fail while doing so. The Claude
action rejects a bot actor outright ("Workflow initiated by non-human actor"),
and the Codex and Pi jobs find no API key because GitHub gives Dependabot-
triggered runs a separate secret scope from Actions. Verified on #11302: zero
reviews posted, the only comment is a Cloudflare deployment notice, while
codex-review and pi-review both reported success.
So every Dependabot PR carried two permanently red checks that meant nothing,
which is the worst kind of signal — it buries a Dependabot PR that genuinely is
broken, and a green tick that means "skipped" reads exactly like one that means
"looked and approved".
Skipping states it honestly. The workflow_call branch is untouched, so a review
can still be requested on a specific bot PR when the diff deserves one, which is
worth doing for a grouped security update that swaps a cipher or drops a parser
rather than just moving a version.
The Discord notice is excluded for the same reason plus its own: nobody wants a
forum thread per lockfile bump.
Not fixed here, deliberately: making these actually review bot PRs would need
the org's review credentials copied into the Dependabot secret scope, which is a
wider grant than this is worth given the PRs in question are lockfile diffs.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* ci: gate the close-time Discord job too, and trim the comments
Both reviewers caught the same gap: merge_success_emoji runs on every `closed`
event with no exclusion, and the reusable workflow it calls exits 1 when it
cannot find a thread. Since open_thread no longer creates one for Dependabot,
the failure would have moved from open-time to merge-time rather than going
away. Gated to match.
The comments are cut from eight lines to two per file. AGENTS.md:205 asks for
constraints in <=4 lines, stated once, describing the code as it is — mine
narrated the drafting history and argued the change to a reviewer, both of which
belong in the PR description. Also drops "bot-authored", which overstated a
condition that only covers dependabot[bot].
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
61 lines
2.4 KiB
YAML
61 lines
2.4 KiB
YAML
name: Create discord thread when a PR is opened, react with green checkmark when PR is merged
|
|
|
|
on:
|
|
pull_request:
|
|
types:
|
|
- opened
|
|
- ready_for_review
|
|
- closed
|
|
issue_comment:
|
|
types:
|
|
- created
|
|
- edited
|
|
|
|
jobs:
|
|
notify_discord_when_pr_opened:
|
|
# No thread is opened for Dependabot PRs, so nothing downstream may assume one.
|
|
if: (github.event.pull_request.draft == false) && (github.event.action == 'opened' || github.event.action == 'ready_for_review') && (github.event.pull_request.user.login != 'dependabot[bot]')
|
|
uses: ./.github/workflows/shareable-discord-notification.yml
|
|
with:
|
|
PR_TITLE: ${{ github.event.pull_request.title }}
|
|
PR_URL: ${{ github.event.pull_request.html_url }}
|
|
PR_AUTHOR: ${{ github.event.pull_request.user.login }}
|
|
PR_STATUS: "opened"
|
|
PR_NUMBER: ${{ github.event.pull_request.number }}
|
|
DISCORD_CHANNEL_ID: "1372204995868491786"
|
|
DISCORD_GUILD_ID: "930051556043276338"
|
|
secrets:
|
|
DISCORD_WEBHOOK_URL: ${{ secrets.DISCORD_PR_REVIEWS_WEBHOOK }}
|
|
DISCORD_BOT_TOKEN: ${{ secrets.DISCORD_AI_BOT_TOKEN }}
|
|
|
|
merge_success_emoji:
|
|
# Must match open_thread's exclusion: this reacts to a thread that was never created.
|
|
if: github.event.action == 'closed' && github.event.pull_request.user.login != 'dependabot[bot]'
|
|
uses: ./.github/workflows/shareable-discord-notification.yml
|
|
with:
|
|
PR_STATUS: "merged"
|
|
DISCORD_CHANNEL_ID: "1372204995868491786"
|
|
DISCORD_GUILD_ID: "930051556043276338"
|
|
PR_NUMBER: ${{ github.event.pull_request.number }}
|
|
secrets:
|
|
DISCORD_BOT_TOKEN: ${{ secrets.DISCORD_AI_BOT_TOKEN }}
|
|
|
|
notify_discord_on_comment:
|
|
if: >
|
|
github.event_name == 'issue_comment'
|
|
&& github.event.issue.pull_request
|
|
&& github.event.comment.user.login != 'cloudflare-workers-and-pages[bot]'
|
|
&& github.event.comment.user.login != 'ellipsis-dev[bot]'
|
|
uses: ./.github/workflows/shareable-discord-notification.yml
|
|
with:
|
|
PR_STATUS: "comment"
|
|
PR_NUMBER: ${{ github.event.issue.number }}
|
|
COMMENT_BODY: ${{ github.event.comment.body }}
|
|
COMMENT_AUTHOR: ${{ github.event.comment.user.login }}
|
|
COMMENT_URL: ${{ github.event.comment.html_url }}
|
|
COMMENT_IS_EDIT: ${{ github.event.action == 'edited' }}
|
|
DISCORD_CHANNEL_ID: "1372204995868491786"
|
|
DISCORD_GUILD_ID: "930051556043276338"
|
|
secrets:
|
|
DISCORD_BOT_TOKEN: ${{ secrets.DISCORD_AI_BOT_TOKEN }}
|