Skip to content

feat(ci): open a PR when Apache DevLake publishes a new tag - #148

Open
mfrancisc wants to merge 3 commits into
konflux-ci:mainfrom
mfrancisc:chore/upstream-sync-workflow
Open

mfrancisc wants to merge 3 commits into
konflux-ci:mainfrom
mfrancisc:chore/upstream-sync-workflow

Conversation

@mfrancisc

Copy link
Copy Markdown

Summary

  • Add a scheduled upstream-sync workflow that opens (or updates) a single chore/upstream-sync PR when Apache DevLake publishes a new major, minor, patch, or numbered-beta tag (vX.Y.Z / vX.Y.Z-betaN).
  • The PR head is the upstream tag so GitHub reports real merge conflicts. The bot never auto-merges; land with a merge commit, not squash. Delete chore/upstream-sync after merge if GitHub did not - the next run recreates it.
  • Example of the generated PR: chore: sync upstream Apache DevLake v1.0.3-beta16 mfrancisc/devlake#1

Scheduled workflow opens a single chore/upstream-sync PR for matching
upstream tags and never auto-merges. After merge, delete the branch if
GitHub did not; the next run recreates it.

Upstream-Status: Inappropriate (Konflux-only)

Co-Authored-By: Cursor Grok 4.6 <noreply@example.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@mfrancisc
mfrancisc requested a review from a team as a code owner August 31, 2026 15:39
@fullsend-ai-review

fullsend-ai-review Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 3:41 PM UTC · Completed 3:58 PM UTC

Commit: 9ee3c25 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $4.38

@fullsend-ai-review

fullsend-ai-review Bot commented Aug 31, 2026 •

Copy link
Copy Markdown

Review

Findings

High

  • [protected-path] .github/scripts/upstream-sync.sh, .github/workflows/upstream-sync.yml, AGENTS.md — Three protected files are modified (.github/ prefix, AGENTS.md). No linked issue provides authorization for modifying governance/infrastructure files. Human approval is always required for protected-path changes.

Medium

  • [API contract violation] .github/workflows/upstream-sync.yml:30 — The workflow permissions block grants only contents: write and pull-requests: write, but the script calls gh label create (upstream-sync.sh line 86) which requires issues: write. With explicit permissions, unlisted scopes default to none. Under set -euo pipefail, the ensure_label failure aborts after the force-push but before PR creation, leaving the sync branch orphaned with no PR. Subsequent scheduled runs hit the same failure, creating a stuck loop.
    Remediation: Add issues: write to the permissions block.

  • [injection] .github/scripts/upstream-sync.sh:178 — GHA workflow command injection via newline in INPUT_TAG. Tag validation uses echo | grep -Eq which matches per-line; a multiline workflow_dispatch input can bypass the TAG_REGEX check. The injected workflow command executes via echo on line 179 before git fetch fails on the invalid refspec. Blast radius is narrow (requires repo write access, set -e aborts shortly after).
    Remediation: Replace with bash built-in regex: [[ "$tag" =~ $TAG_REGEX ]].

Low

  • [code-organization] .github/scripts/upstream-sync.sh:18 — Shebang (#!/bin/bash) on line 18 after the Apache license block instead of line 1. The kernel only recognizes shebangs at byte offset 0. Currently unaffected (workflow invokes via bash), but direct execution would fail.
    Remediation: Move #!/bin/bash to line 1.

  • [documentation-formatting] docs/upstream-diffs.md:287 — New section ends with no blank line before the next ## core: heading, inconsistent with every other section boundary in the file.
    Remediation: Add a blank line after line 287.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run

Review

Findings

High

  • [protected-path] .github/scripts/upstream-sync.sh, .github/workflows/upstream-sync.yml, AGENTS.md — Three of four changed files are under protected paths (.github/, AGENTS.md). The PR has no linked issue providing authorization for modifying governance/infrastructure files. Human approval is required for protected-path changes.
    Remediation: Link an issue authorizing modifications to protected paths, or obtain explicit human review approval.

Low

  • [missing-authorization] — No linked issue for a non-trivial feature change adding 280+ lines of new CI automation infrastructure.

  • [edge-case] .github/scripts/upstream-sync.sh:75 — The predict_conflict_paths function's awk parser may always return empty output depending on git merge-tree --write-tree --name-only output format across git versions, making the "Predicted conflicts" section of generated PR bodies non-functional. The feature is purely advisory.

  • [fail-open] .github/scripts/upstream-sync.sh:27 — Security-relevant variables (UPSTREAM_REMOTE_URL, SYNC_BRANCH, BASE_BRANCH) accept environment variable overrides without validation. Currently safe because the workflow sets no overrides, but the implicit trust boundary is fragile.

  • [formatting/correctness] docs/upstream-diffs.md:287 — Missing blank line between the new "ci: automatic upstream-sync PRs" section and the existing ## core: ai_commits domain table heading. Some Markdown parsers may not recognize the heading without a preceding blank line.
    Remediation: Add a blank line after line 287 (excluding \apache/devlake`.`).


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (2)

Review

Findings

High

  • [protected-path] .github/scripts/upstream-sync.sh, .github/workflows/upstream-sync.yml, AGENTS.md — Three files under protected paths (.github/, AGENTS.md) are modified. No linked issue provides authorization context for modifying governance/infrastructure files. Human approval is required for all protected-path changes.
    Remediation: Link a tracking issue to the PR providing authorization for modifying .github/ and AGENTS.md.

Medium

  • [logic-error] .github/scripts/upstream-sync.sh:73 — is_upstream_tag_commit compares dereferenced commit SHAs against git ls-remote --tags output, which for annotated tags contains tag-object SHAs (not commit SHAs). If Apache DevLake uses annotated tags (standard for releases), this function always returns false, preventing force-push updates to existing sync PRs. The script falls back to commenting instead of updating.
    Remediation: Also check ^{} entries from git ls-remote --tags, which show dereferenced commit SHAs for annotated tags.

  • [logic-error] .github/scripts/upstream-sync.sh:79 — predict_conflict_paths uses git merge-tree --write-tree --name-only with an awk filter that exits at CONFLICT or Auto-merging lines. These informational lines may appear before file paths, causing the function to return empty output even when conflicts exist. Impact is cosmetic — the PR body already notes predictions are unreliable.
    Remediation: Parse without --name-only and grep for ^CONFLICT lines to extract conflict paths.

Low

  • [logic-error] .github/scripts/upstream-sync.sh:18 — Shebang (#!/bin/bash) is on line 18 after the license header. The kernel won't recognize it for direct invocation, but the workflow invokes via bash and the existing cherry-pick.sh follows the same pattern.

  • [error-handling-gap] .github/scripts/upstream-sync.sh:166 — git fetch "$UPSTREAM_REMOTE" "${BASE_BRANCH}" || true silently ignores failures. Subsequent commands reference origin/${BASE_BRANCH}, not $UPSTREAM_REMOTE/${BASE_BRANCH}, so this fetch may be vestigial.

  • [edge-case] .github/scripts/upstream-sync.sh:25 — TAG_REGEX only matches -betaN pre-release suffixes; -rc1, -alpha1 are excluded by design.

  • [structural-placement] .github/scripts/upstream-sync.sh — CLAUDE.md recommends scripts/ for automation, but .github/scripts/ is conventional for GitHub Actions helpers and follows existing codebase patterns.

  • [documentation-completeness] AGENTS.md — Upstream-sync section describes behavior but not strategic rationale. A brief "why" sentence would improve context.

  • [shell-dialect-inconsistency] .github/scripts/upstream-sync.sh:18 — Uses #!/bin/bash where some scripts use #!/bin/sh. Bash is justified by set -euo pipefail, +=, and $'\n'.

  • [error-handling-pattern] .github/scripts/upstream-sync.sh:31 — die() is a new idiom not in existing scripts but reasonable for a complex script.

  • [comment-style] .github/scripts/upstream-sync.sh — Top-of-file summary comment differs from existing scripts but improves readability.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 8:48 AM UTC · Completed 9:07 AM UTC

Commit: 9ee3c25 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $4.66

@codecov-commenter

codecov-commenter commented Sep 3, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 41.60%. Comparing base (c3c2f94) to head (22b24cd).

❗ There is a different number of reports uploaded between BASE (c3c2f94) and HEAD (22b24cd). Click for more details.

HEAD has 10 uploads less than BASE
Flag BASE (c3c2f94) HEAD (22b24cd)
unit-tests-go 6 1
unit-tests-python 6 1
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main     #148      +/-   ##
==========================================
- Coverage   48.05%   41.60%   -6.45%     
==========================================
  Files         154      154              
  Lines       10501    10501              
==========================================
- Hits         5046     4369     -677     
- Misses       5237     6019     +782     
+ Partials      218      113     -105     
Flag Coverage Δ
e2e-go 9.51% <ø> (-12.75%) ⬇️
unit-tests-go 35.89% <ø> (ø)
unit-tests-python 55.49% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.
see 27 files with indirect coverage changes


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update c3c2f94...22b24cd. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Sep 3, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

Purely additive CI automation (new workflow + shell script) with no tests and 3 protected paths, but the additive nature, clean regression history on modified docs files, and known non-bot author keep the composite risk at moderate.

Previous run

Risk Assessment: moderate (2/5)

Details

CI automation touching protected paths with no tests, but narrowly scoped sync automation from upstream by established contributor.

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

fullsend-ai-review Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 9:36 AM UTC · Completed 9:55 AM UTC

Commit: efeae75 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $4.65

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

required: false
type: string

permissions:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[medium] API contract violation

The workflow permissions block grants only contents: write and pull-requests: write, but the script calls gh label create (upstream-sync.sh line 86) which requires issues: write. With explicit permissions, unlisted scopes default to none. Under set -euo pipefail, the ensure_label failure aborts after the force-push but before PR creation, leaving the sync branch orphaned. Subsequent scheduled runs hit the same failure.

Suggested fix: Add issues: write to the permissions block.

[ -n "$tag" ] || die "no upstream tags matching ${TAG_REGEX}"
echo "Newest matching upstream tag: ${tag}"
else
echo "${tag}" | grep -Eq "$TAG_REGEX" || die "tag ${tag} does not match ${TAG_REGEX}"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[medium] injection

GHA workflow command injection via newline in INPUT_TAG. Tag validation uses echo | grep -Eq which matches per-line. A multiline workflow_dispatch input can bypass the TAG_REGEX check. The injected workflow command executes via echo on line 179 before git fetch fails on the invalid refspec. Blast radius is narrow (requires repo write access, set -e aborts shortly after).

Suggested fix: Replace with bash built-in regex: [[ "$tag" =~ $TAG_REGEX ]] which treats ^/$ as string anchors.

# limitations under the License.
#

#!/bin/bash

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] code-organization

Shebang (#!/bin/bash) on line 18 after the Apache license block instead of line 1. The kernel only recognizes shebangs at byte offset 0. Currently unaffected because the workflow invokes the script as bash .github/scripts/upstream-sync.sh, but direct execution would fail.

Suggested fix: Move #!/bin/bash to line 1; license block follows after.

Comment thread docs/upstream-diffs.md

**Rebase notes:** New files; no upstream equivalent. If upstream adds a workflow
or script with the same path, pick a different name. The job `if:` must keep
excluding `apache/devlake`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[low] documentation-formatting

New ## ci: automatic upstream-sync PRs section ends with no blank line before the next ## core: ai_commits domain table heading. Every other section boundary in the file has a blank line separator.

Suggested fix: Add a blank line after line 287.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

risk/moderate PR risk: moderate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants