@@ -238,6 +238,25 @@ jobs:
238238 group : check-repo-size-${{ github.event.pull_request.number }}
239239
240240 steps :
241+ - name : Checkout repository
242+ uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
243+ with :
244+ # Check out the base ref, not the PR's head, since this job runs with
245+ # `pull-requests: write` permissions and must not execute untrusted code from the PR.
246+ ref : ${{ github.event.pull_request.base.sha }}
247+ sparse-checkout : |
248+ pr-checks
249+ .github/actions/post-comment
250+
251+ - name : Set up Node.js
252+ uses : actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
253+ with :
254+ node-version : 24
255+ cache : " npm"
256+
257+ - name : Install dependencies
258+ run : npm ci --workspace=pr-checks
259+
241260 - name : Download repo size comment
242261 uses : actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
243262 with :
@@ -269,48 +288,22 @@ jobs:
269288 fi
270289
271290 - name : Post a warning about modifying CHANGELOG.md
291+ id : post-changelog-warning
272292 # Release, backport, mergeback, and bundle-update PRs deliberately modify CHANGELOG.md,
273293 # so skip comment management entirely for these automation flows.
274294 if : >-
275295 !startsWith(github.event.pull_request.head.ref, 'update-v') &&
276296 !startsWith(github.event.pull_request.head.ref, 'backport-v') &&
277297 !startsWith(github.event.pull_request.head.ref, 'mergeback/') &&
278298 !startsWith(github.event.pull_request.head.ref, 'update-bundle/')
279- env :
280- COMMENT_MARKER : " <!-- changelog-warning-bot -->"
281- GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
282- PR_NUMBER : ${{ github.event.pull_request.number }}
283- CHANGED : ${{ needs.other-checks.outputs.changelog-changed }}
284- run : |
285- comment_id=$(
286- gh api "repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments" \
287- --paginate \
288- --jq ".[] | select(.body | contains(\"$COMMENT_MARKER\")) | .id" \
289- | head -n 1
290- )
291-
292- # If CHANGELOG.md is no longer modified (e.g. a later commit reverted the change),
293- # remove any stale warning comment left over from an earlier push instead of leaving it
294- # to incorrectly claim the file is still modified.
295- if [[ "$CHANGED" == "false" ]]; then
296- if [[ -n "$comment_id" ]]; then
297- echo "CHANGELOG.md is no longer modified; deleting stale warning comment ($comment_id)."
298- gh api --method DELETE "repos/$GITHUB_REPOSITORY/issues/comments/$comment_id"
299- else
300- echo "CHANGELOG.md was not modified and no warning comment exists; nothing to do."
301- fi
302- exit 0
303- fi
304-
305- # If CHANGELOG.md has been modified and a warning comment already exists, do not post a duplicate comment.
306- if [[ -n "$comment_id" ]]; then
307- echo "CHANGELOG.md warning comment already exists ($comment_id)."
308- exit 0
309- fi
310-
311- body="$COMMENT_MARKER
312- ⚠️ \`CHANGELOG.md\` has been modified in this PR. Please do not modify \`CHANGELOG.md\` directly.
313- Instead, create a change-note file in \`unreleased-change-notes/\`. The \`CHANGELOG.md\`
314- file will be automatically generated from those change-notes.
315- See [\`unreleased-change-notes/README.md\`](unreleased-change-notes/README.md) for more information."
316- gh api --method POST "repos/$GITHUB_REPOSITORY/issues/$PR_NUMBER/comments" --field body="$body"
299+ uses : ./.github/actions/post-comment
300+ with :
301+ body : |
302+ ⚠️ `CHANGELOG.md` has been modified in this PR. Please do not modify `CHANGELOG.md` directly.
303+ Instead, create a change-note file in `unreleased-change-notes/`. The `CHANGELOG.md`
304+ file will be automatically generated from those change-notes.
305+ See [`unreleased-change-notes/README.md`](unreleased-change-notes/README.md) for more information.
306+ action-condition : ${{ needs.other-checks.outputs.changelog-changed }}
307+ action-if-true : upsert
308+ action-if-false : delete
309+ token : ${{ secrets.GITHUB_TOKEN }}
0 commit comments