Use suggestion-bot to convert pre-commit errors in PRs with fixes into code review suggestions. (#3746)

This can't be done directly from a `pull_request` action, because that's
run without write privileges. This is done for security reasons, because
it runs in the context of the pull request branch. So instead, we
perform this in two steps:

- The `pull_request` action runs `pre-commit` and uploads an artifact
containing the diffs and the event information (which is only used to
extract the pull request number).
- A separate `workflow_run` action is triggered when the `pre-commit`
action finishes. This action is privileged, and should be able to
download the artifact and create corresponding suggestions.

Unfortunately, due to the permissions model in play here, the second
half of this appears to only be testable live in production.

For now, we're splitting the pre-commit action into two actions -- one
to run on PRs and one to run when actually merging commits -- so that
the suggestions are only triggered in the former case. It might be
possible to recombine these using data in the `workflow_run` invocation
to tell them apart, but the documentation here isn't very good so I've
made this PR dump out that event information so that we can look at it
and see if it contains the relevant information.
This commit is contained in:
Richard Smith
2024-03-07 20:54:17 +00:00
committed by GitHub
parent 5665660677
commit 61ea4f8344
3 changed files with 89 additions and 3 deletions
+11 -3
View File
@@ -6,9 +6,6 @@ name: pre-commit
on:
pull_request:
merge_group:
push:
branches: [trunk]
jobs:
pre-commit:
@@ -17,3 +14,14 @@ jobs:
- uses: actions/checkout@v3
- uses: actions/setup-python@v4
- uses: pre-commit/action@v3.0.0
- name: Collect pre-commit output
if: ${{ failure() }}
run: |
mkdir -p pre-commit-output
git diff > pre-commit-output/diff
cp $GITHUB_EVENT_PATH pre-commit-output/event
- uses: actions/upload-artifact@v4
if: ${{ failure() }}
with:
name: pre-commit output
path: pre-commit-output/*