Skip to content

Auto-commit dist/ fixes on any PR, not just Dependabot's - #496

Merged
AnHeuermann merged 1 commit into
mainfrom
ci/auto-commit-dist
Sep 14, 2026
Merged

AnHeuermann merged 1 commit into
mainfrom
ci/auto-commit-dist

Conversation

@AnHeuermann

Copy link
Copy Markdown
Member

Summary

PR #495 failed check-dist because its checked-in dist/index.js had been built with the wrong dependency versions locally (leftover node_modules from another branch), and there was no way for CI to self-heal that outside of Dependabot PRs.

  • check-dist now rebuilds dist/, and if it differs from what's checked in on a pull_request from a same-repo branch, commits and pushes the fix itself, then dispatches a dist-autocommit repository event to re-trigger the other workflows on the new commit (a GITHUB_TOKEN push doesn't start a new run on its own).
  • Forked PRs and pushes straight to main (no branch to push a fix to) fall through to the previous behavior: fail the check and upload the expected dist/ as a workflow artifact.
  • patch-dependabot.yml did exactly this rebuild-commit-push-dispatch dance, but only for Dependabot PRs (gated on github.actor == 'dependabot[bot]'). Its logic is now folded into check-dist.yml and the file is removed.
  • Renames the repository_dispatch event from dependabot-dist-updated to dist-autocommit to reflect the broader scope; updates the listeners in test.yml and codeql-analysis.yml.

Pattern follows OpenModelica/openmodelica-library-testing-action#103.

Test plan

  • Validated all workflow YAML files parse correctly
  • Open a PR with an intentionally stale dist/ and confirm check-dist auto-commits the fix and the re-triggered checks go green
  • Confirm Dependabot PRs still get their dist/ auto-fixed now that the logic lives in check-dist.yml instead of patch-dependabot.yml

check-dist previously only failed loudly when a checked-in dist/
didn't match the build output; a separate patch-dependabot.yml worked
around this for Dependabot PRs only by rebuilding, committing, and
pushing the fix (then dispatching to re-trigger the other workflows,
since a GITHUB_TOKEN push doesn't start a new run). Any other PR with
a stale dist/ - e.g. one built with the wrong dependency versions
locally - just failed with no path to green other than a manual fix.

check-dist now does the rebuild-commit-push-dispatch dance itself for
any same-repo pull_request (falling through to the existing
fail+upload-artifact behavior for forks, and for pushes straight to
main where there's no branch to push a fix to), so
patch-dependabot.yml's logic is folded in and the file is removed.
Renames the repository_dispatch event from dependabot-dist-updated to
dist-autocommit to reflect the broader scope, updating the listeners
in test.yml and codeql-analysis.yml.

Pattern follows OpenModelica/openmodelica-library-testing-action#103.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

# Conflicts:
#	.github/workflows/check-dist.yml
#	.github/workflows/patch-dependabot.yml
@AnHeuermann
AnHeuermann merged commit 67f5b74 into main Sep 14, 2026
11 checks passed
@AnHeuermann
AnHeuermann deleted the ci/auto-commit-dist branch September 14, 2026 10:21
AnHeuermann added a commit that referenced this pull request Sep 14, 2026
…_dispatch (#498)

Verified #496 end-to-end with a throwaway test PR: check-dist correctly
detected a stale dist/, rebuilt it, and pushed the fix as
github-actions[bot]. But the re-trigger step used repository_dispatch,
which always runs against the repository's default branch - it has no
concept of "the branch that dispatched it". The dispatched runs showed
up tagged to main, and the PR's actual head commit (the pushed fix)
ended up with zero check runs beyond the CLA bot. Harmless today since
this repo has no required status checks, but it defeats the entire
point of auto-fixing: the PR looks unvalidated at its final SHA.

workflow_dispatch accepts an explicit ref, so switch the re-trigger to
`gh workflow run <file> --ref <branch>` for check-dist.yml, test.yml,
and codeql-analysis.yml (each now declares workflow_dispatch so it can
be dispatched this way), using the job's GITHUB_TOKEN via the actions:
write permission dispatching needs.

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant