# Uses `workflow_run` to securely add a comment to the PR that triggered CI. # # Important: For security, the `workflow_run` trigger runs the workflow from the default branch, # so any changes to this workflow must be made in the default branch to take effect. # # This workflow is neccesary because PRs opened by external forks do not have write access to # their PR, so the PR-triggered workflow can't add comments to the PR. # If this was in the CI workflow, it'd be tidier and easier to debug but unfortunately that # isn't possible due to the lower security context that the CI workflow runs in. name: CI comment on: workflow_run: workflows: ["CI"] types: - completed jobs: summary: if: github.event.workflow_run.event == 'pull_request' runs-on: ubuntu-latest steps: - name: Download summaries id: download uses: actions/download-artifact@v4 with: run-id: ${{ github.event.workflow_run.id }} pattern: summary-* path: summaries github-token: ${{ secrets.GITHUB_TOKEN }} - name: Merge summaries id: summary run: | ls -R files=$(find $dir -type f) if [ -z "$files" ]; then echo "No files found in dir: $dir" exit 0 fi echo "message<> $GITHUB_OUTPUT echo "## CI Summary" >> $GITHUB_OUTPUT for file in $files; do echo $(cat $file) >> $GITHUB_OUTPUT done repo_url="${{ github.server_url }}/${{ github.repository }}" run_url="$repo_url/actions/runs/${{ github.event.workflow_run.id }}" echo > $GITHUB_OUTPUT echo "[Full summary]($run_url) (scroll down)" >> $GITHUB_OUTPUT echo "EOF" >> $GITHUB_OUTPUT - name: Set PR comment if: steps.summary.outputs.message uses: marocchino/sticky-pull-request-comment@v2 with: number: ${{ github.event.workflow_run.pull_requests[0].number }} header: ${{ github.event.workflow_run.name }} message: ${{ steps.summary.outputs.message }} - name: Delete PR comment if: ${{ !steps.summary.outputs.message }} uses: marocchino/sticky-pull-request-comment@v2 with: number: ${{ github.event.workflow_run.pull_requests[0].number }} header: ${{ github.event.workflow_run.name }} delete: true