Skip to content

Commit 23b0ad5

Browse files
committed
fix(ci): pin the current pull request base branch
1 parent 1372339 commit 23b0ad5

2 files changed

Lines changed: 20 additions & 6 deletions

File tree

‎.github/scripts/resolve-audit-base.sh‎

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -24,12 +24,13 @@ elif [ "$GITHUB_EVENT_NAME" = workflow_dispatch ]; then
2424
exit 1
2525
fi
2626

27-
base_sha=$(jq -r '.[0].base.sha' <<< "$matching_prs")
28-
if [[ ! "$base_sha" =~ ^[0-9a-f]{40}$ ]]; then
29-
echo 'The pull request did not provide a valid base commit SHA.' >&2
27+
base_ref=$(jq -er '.[0].base.ref | select(type == "string" and length > 0)' <<< "$matching_prs")
28+
if ! git check-ref-format "refs/heads/$base_ref"; then
29+
echo 'The pull request did not provide a valid base branch.' >&2
3030
exit 1
3131
fi
32-
git fetch --depth=1 origin "$base_sha"
32+
git fetch --depth=1 origin "refs/heads/$base_ref"
33+
base_sha=$(git rev-parse --verify 'FETCH_HEAD^{commit}')
3334
echo "ref=$base_sha" >> "$GITHUB_OUTPUT"
3435
elif [ -n "${GITHUB_BEFORE:-}" ] &&
3536
[ "$GITHUB_BEFORE" != 0000000000000000000000000000000000000000 ]; then

‎scripts/audit-base-workflow.test.ts‎

Lines changed: 15 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ function fixture() {
4343
const pr = {
4444
state: 'open',
4545
head: { ref: 'foundation', sha: head, repo: { full_name: 'example/repo' } },
46-
base: { sha: base },
46+
base: { ref: 'parent', sha: base },
4747
}
4848
return { root, repo, base, before, head, pr }
4949
}
@@ -96,6 +96,17 @@ describe('diff audit base selection', () => {
9696
expect(git(data.repo, 'diff', '--name-only', data.before, 'HEAD')).toBe('upstream.sql')
9797
})
9898

99+
it('pins the current base branch when the PR snapshot still reports an older base SHA', () => {
100+
const data = fixture()
101+
const cachedBase = git(data.repo, 'rev-parse', `${data.base}^`)
102+
const result = resolveBase(data, {
103+
PR_RESPONSE: JSON.stringify([[{ ...data.pr, base: { ...data.pr.base, sha: cachedBase } }]]),
104+
})
105+
expect(result.status, result.stderr).toBe(0)
106+
expect(result.output).toBe(`ref=${data.base}`)
107+
expect(git(data.repo, 'rev-parse', 'FETCH_HEAD')).toBe(data.base)
108+
})
109+
99110
it('fails closed when multiple open PRs across pages claim the dispatched branch', () => {
100111
const data = fixture()
101112
const result = resolveBase(data, { PR_RESPONSE: JSON.stringify([[data.pr], [data.pr]]) })
@@ -114,7 +125,9 @@ describe('diff audit base selection', () => {
114125
if (failure === 'tag') overrides.GITHUB_REF_TYPE = 'tag'
115126
if (failure === 'api') overrides.API_EXIT = '73'
116127
if (failure === 'invalid-base')
117-
overrides.PR_RESPONSE = JSON.stringify([[{ ...data.pr, base: { sha: 'HEAD~1' } }]])
128+
overrides.PR_RESPONSE = JSON.stringify([
129+
[{ ...data.pr, base: { ref: 'HEAD~1', sha: 'HEAD~1' } }],
130+
])
118131
if (failure === 'fetch')
119132
git(data.repo, 'remote', 'set-url', 'origin', join(data.root, 'missing.git'))
120133
const result = resolveBase(data, overrides)

0 commit comments

Comments
 (0)