Skip to content

fix(ci): use shared first merged PR comment action - #8672

Merged
vitormattos merged 2 commits into
mainfrom
fix/contributor-feedback-action
Sep 23, 2026
Merged

vitormattos merged 2 commits into
mainfrom
fix/contributor-feedback-action

Conversation

@vitormattos

@vitormattos vitormattos commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

Summary

Replaces LibreSign's local first-contributor implementation with the shared LibreCodeCoop/github-workflows action introduced by LibreCodeCoop/github-workflows#172.

The workflow now contains only LibreSign-specific presentation content. Detection of a contributor's first merged pull request, manual retry, idempotency, URL placeholder rendering, and GitHub API access are provided by the shared action.

Security

The previous third-party Docker action and the intermediate actions/github-script implementation are both removed.

The final workflow:

  • uses the shared composite action pinned to merged revision 6816f216b2b04d5dd63d01711f88c5ff1d1e0740;
  • installs no runtime dependencies;
  • uses no Docker image;
  • checks out no repository or pull-request content;
  • executes no code from the pull request head;
  • starts with permissions: {};
  • grants only pull-requests: write to the job.

LibreSign message

LibreSign owns the complete message through the required repository Actions variable FIRST_MERGED_PR_MESSAGE.

The workflow passes vars.FIRST_MERGED_PR_MESSAGE directly to the shared action. There is no inline fallback message; a missing or empty variable causes the action to fail instead of publishing unexpected content.

The shared action only provides generic placeholders. LibreSign composes its own survey URL, good-first-issue URL, community link and contributor mention directly in the message.

The survey context is generated with:

https://ls.librecode.coop/index.php/645932?lang=en&source=github-first-merged-pr&repository={repository_name|urlencode}

Automatic and manual execution

The workflow runs automatically when a pull request is closed and merged.

It also supports workflow_dispatch with a required pull_request_number. This allows us to:

  • retry a failed first-contribution notification;
  • validate the workflow against an already merged pull request;
  • process historical merged pull requests one at a time for retrospective contributor outreach.

The shared action evaluates whether the target PR was that contributor's first merged PR at the time it was closed and skips duplicates.

After merge, PR #8311 will be used as the production validation case.

Signed-off-by: Vitor Mattos vitor@php.rio

@vitormattos
vitormattos requested a review from a team as a code owner September 23, 2026 18:36
@vitormattos vitormattos changed the title fix(ci): replace vulnerable contributor feedback action fix(ci): use shared first merged PR comment action Sep 23, 2026
@vitormattos
vitormattos enabled auto-merge (squash) September 23, 2026 19:39
Signed-off-by: Vitor Mattos <vitor@php.rio>
@vitormattos
vitormattos force-pushed the fix/contributor-feedback-action branch from 17c820b to 2cd0371 Compare September 23, 2026 20:07
Signed-off-by: Vitor Mattos <vitor@php.rio>
@vitormattos
vitormattos merged commit bcfef84 into main Sep 23, 2026
69 checks passed
@vitormattos
vitormattos deleted the fix/contributor-feedback-action branch September 23, 2026 20:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant