From 72c9e891279557bf8097c510ae13aa8400247aa4 Mon Sep 17 00:00:00 2001 From: Gaurav Trivedi Date: Thu, 17 Sep 2026 11:57:00 +0530 Subject: [PATCH] fix: pin Publish preview on netlify to the triggering run The dawidd6/action-download-artifact step in this workflow only specified 'workflow', not 'run_id'. Without run_id, the action searches for the most recent successful 'doc-content' artifact for that workflow name across the entire repository instead of the specific run that triggered this workflow_run event. allow_forks defaults to false, which additionally causes the search to skip fork-originated PR runs (every JTBD PR is opened from a fork). The net effect: preview links for fork PRs get attributed to whatever non-fork branch happens to have the most recent successful build, instead of the PR that actually triggered the workflow. Observed on PR #3143: multiple concurrently-building fork PRs (#3143, #3151, #3153, #3155) never received their own preview link; the '"Navigate the preview"' comment kept landing on PR #3192 (a same-repo branch push) instead, whose sticky comment was repeatedly overwritten with unrelated deploy links throughout the day (createdAt stayed 2026-09-09 while the body kept changing). Fix: pin run_id to github.event.workflow_run.id so the artifact download always resolves to the exact run that completed, and set allow_forks: true since this workflow already executes in the base repo's trusted context via workflow_run. Co-authored-by: Cursor --- .github/workflows/publish-netlify.yml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/.github/workflows/publish-netlify.yml b/.github/workflows/publish-netlify.yml index 59b3b14daa..5c0c20c475 100644 --- a/.github/workflows/publish-netlify.yml +++ b/.github/workflows/publish-netlify.yml @@ -27,6 +27,16 @@ jobs: - name: Download doc-content artifact uses: dawidd6/action-download-artifact@07ab29fd4a977ae4d2b275087cf67563dfdf0295 # v9 with: + # Pin to the exact run that triggered this workflow. Without run_id, the + # action falls back to searching for the "most recent successful" artifact + # for this workflow name across the whole repo, which can resolve to a + # completely unrelated PR's build when multiple PRs complete builds close + # together (see https://github.com/eclipse-che/che-docs/pull/3143). + run_id: ${{ github.event.workflow_run.id }} + # This workflow runs via workflow_run in the base repo's trusted context + # (that's the reason it's split from the build workflow at all), so it's + # safe to read a build artifact produced by a fork-originated PR run. + allow_forks: true workflow: ${{ github.event.workflow_run.workflow_id }} name: doc-content path: content