Skip to content

feat: add generic first merged PR comment action - #172

Merged
vitormattos merged 23 commits into
mainfrom
feat/first-merged-contribution-template
Sep 23, 2026
Merged

vitormattos merged 23 commits into
mainfrom
feat/first-merged-contribution-template

Conversation

@vitormattos

@vitormattos vitormattos commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

Summary

Adds a generic, tested first-merged-pr-comment composite action and matching organization workflow template.

The shared implementation is intentionally limited to:

  1. determining whether a pull request is the contributor's first merged pull request;
  2. rendering a repository-defined Markdown message from GitHub-derived placeholders;
  3. creating the comment once, with safe retries.

Product-specific concepts such as surveys, community links, documentation URLs, labels, or project-specific destinations are not part of the action contract.

Message templating

Consumers configure the complete message through the repository variable:

FIRST_MERGED_PR_MESSAGE

Built-in placeholders:

  • {server_url}
  • {api_url}
  • {repository}
  • {repository_owner}
  • {repository_name}
  • {repository_url}
  • {pull_request_number}
  • {pull_request_url}
  • {contributor_login}
  • {contributor_mention}
  • {contributor_url}
  • {merge_commit_sha}

Placeholders can be composed anywhere in the message, including complete URLs and query strings. The only supported filter in the initial contract is |urlencode.

Example:

Feedback: https://example.org/form?repo={repository|urlencode}&pr={pull_request_number|urlencode}

The renderer performs textual substitution only. It does not evaluate shell, Python, JavaScript, GitHub expressions, Jinja, or other executable template syntax. Unknown placeholders and filters fail closed.

Security

  • no Docker action or container image;
  • no runtime package installation;
  • Python standard library only;
  • pull_request_target executes only trusted base-repository workflow code;
  • no checkout, artifacts, scripts, or configuration from the pull request head;
  • top-level permissions: {};
  • job receives only pull-requests: write;
  • composite action is referenced from the template by immutable commit SHA.

This removes the previous dependency path that built node:lts-buster-slim and reported vulnerable npm dependencies.

Retry and idempotency

The workflow supports workflow_dispatch with a pull request number.

First-merge detection is evaluated at the historical close time of the target pull request, so a retry remains correct even after later contributions. Successful comments receive an internal marker and are not duplicated by retries.

Tests

Adds focused tests for:

  • generic built-in context;
  • arbitrary URL/query-string composition;
  • URL encoding;
  • unknown placeholders;
  • unknown filters;
  • empty templates;
  • first merged PR creates a comment;
  • later merged PR does not create a comment;
  • closed/unmerged PR skips;
  • bot PR skips;
  • duplicate-marker retry skips;
  • historical first-merge query;
  • generic action and workflow contracts without product-specific inputs.

The repository CI also validates actionlint, zizmor, REUSE, workflow policy, and the complete Python test suite.

Signed-off-by: Vitor Mattos vitor@php.rio

@vitormattos
vitormattos force-pushed the feat/first-merged-contribution-template branch from 54da0f3 to babe5f3 Compare September 23, 2026 18:37
Signed-off-by: Vitor Mattos <vitor@php.rio>
@vitormattos
vitormattos force-pushed the feat/first-merged-contribution-template branch from 8aa93b6 to 9065385 Compare September 23, 2026 18:38
Signed-off-by: Vitor Mattos <vitor@php.rio>
Signed-off-by: Vitor Mattos <vitor@php.rio>
Signed-off-by: Vitor Mattos <vitor@php.rio>
@vitormattos vitormattos changed the title feat: add first merged contribution workflow feat: add generic first merged PR comment action Sep 23, 2026
@vitormattos
vitormattos merged commit 6816f21 into main Sep 23, 2026
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant