Repository navigation
Ci/automerge develop to main - #85
brendanobra wants to merge 7 commits into
Conversation
…nto ci/automerge-develop-to-main
There was a problem hiding this comment.
CodeQL found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.
There was a problem hiding this comment.
Pull request overview
Adds GitHub automation to keep main synchronized with develop by introducing a composite “sync-branches” action and a consumer workflow that runs on pushes to develop (with a manual workflow_dispatch option).
Changes:
- Added a composite action (
.github/actions/sync-branches) that mergessource_branch→target_branch, and falls back to opening/updating a PR on conflicts or push failures. - Added a consumer workflow (
sync-develop-to-main.yml) and a matching consumer template to run the sync automatically (with concurrency + permissions). - Added installer lock metadata and a release helper script for moving the floating major tag.
Reviewed changes
Copilot reviewed 6 out of 6 changed files in this pull request and generated 7 comments.
Show a summary per file
| File | Description |
|---|---|
| .github/workflows/sync-develop-to-main.yml | Consumer workflow to run develop→main sync on push/dispatch. |
| .github/automation-install.lock.json | Records installed automation module and managed files. |
| .github/actions/sync-branches/scripts/move-major-tag.sh | Release helper to move actions-v<major> tag to a stable release tag. |
| .github/actions/sync-branches/README.md | Usage/integration documentation for the sync action and installer flow. |
| .github/actions/sync-branches/consumer-template.yml | Template workflow consumers can copy to enable syncing. |
| .github/actions/sync-branches/action.yml | Composite action implementing merge/push with PR fallback behavior. |
|
|
||
| ### 1. Copy The Consumer Template | ||
|
|
||
| Copy `actions/sync-branches/consumer-template.yml` into your consumer repo as `.github/workflows/sync-develop-to-main.yml`. |
| This integration guide is stored in `actions/sync-branches/` for easy discovery. | ||
|
|
||
| The composite action is at `actions/sync-branches/action.yml`. |
| --version) | ||
| VERSION="$2" | ||
| shift 2 | ||
| ;; |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The workflow bypasses its bundled action, suppresses downstream CI, and contains security and branch-update issues.
Review effort: Balanced
Findings: 4
Open (13)
Pass composite-action inputs through environment variables · New Avoid force-with-lease overwriting reviewer commits · New Invoke the bundled local action after checking out the repository · New Withset -u, passing--versionwithout a value (or as the last arg) will crash due to an… Sync conflict PRs with later source-branch updates · New Use credentials or dispatches that trigger downstream workflows · New The example consumer workflow omitsissues: write, but the action’s default behavior… The documented file locations omit the.github/prefix, but the action and docs are actually…pr_labelsdefault in the README (auto-sync,needs-review) does not match the composite action… The README referencesactions/sync-branches/consumer-template.yml, but in this repo the template… Include Issues write access in the PAT requirements · New These commands are indented more than the surroundingifbody, which makes the bash script… TheEXISTING=...assignment is indented deeper than the surrounding bash block, which makes the…
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The workflow bypasses its vendored action, and repeated conflicts can leave fallback PRs stale.
Review effort: Balanced
Findings: 2
Open (9)
Invoke the bundled local action after checking out the repository Withset -u, passing--versionwithout a value (or as the last arg) will crash due to an… Refresh existing fallback PRs after conflicting source updates · New Use credentials or dispatches that trigger downstream workflows The documented file locations omit the.github/prefix, but the action and docs are actually… The README referencesactions/sync-branches/consumer-template.yml, but in this repo the template… Align PAT selection with the documented trigger policy · New Remove the unmatched Markdown fence · New Include Issues write access in the PAT requirements
Resolved since last review (7)
Avoid force-with-lease overwriting reviewer commits Pass composite-action inputs through environment variables Sync conflict PRs with later source-branch updates The example consumer workflow omitsissues: write, but the action’s default behavior…pr_labelsdefault in the README (auto-sync,needs-review) does not match the composite action… These commands are indented more than the surroundingifbody, which makes the bash script… TheEXISTING=...assignment is indented deeper than the surrounding bash block, which makes the…
| if [[ -n "$existing_head" ]]; then | ||
| echo "Reusing existing fallback branch ${existing_head}." | ||
| echo "fallback_branch=${existing_head}" >> "$GITHUB_OUTPUT" | ||
| echo "source_sha=${source_sha}" >> "$GITHUB_OUTPUT" | ||
| echo "reason=${reason}" >> "$GITHUB_OUTPUT" | ||
| exit 0 |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Repeated conflicts leave fallback PR branches stale, and several reliability and documentation issues remain.
Review effort: Balanced
Findings: 1
Open (10)
Withset -u, passing--versionwithout a value (or as the last arg) will crash due to an… Fallback PR lookup misses results beyond the first 30 · New Fallback runs after indeterminate setup or branch checks · New Refresh existing fallback PRs after conflicting source updates Use credentials or dispatches that trigger downstream workflows The documented file locations omit the.github/prefix, but the action and docs are actually… The README referencesactions/sync-branches/consumer-template.yml, but in this repo the template… Remove the unmatched Markdown fence Align PAT selection with the documented trigger policy Include Issues write access in the PAT requirements
Resolved since last review (1)
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Conflict outcomes are misclassified, and repeated conflicts can leave fallback artifacts stale.
Review effort: Balanced
Findings: 1
Open (7)
Withset -u, passing--versionwithout a value (or as the last arg) will crash due to an… Require push output only when merge succeeds · New Fallback PR lookup misses results beyond the first 30 Refresh existing fallback PRs after conflicting source updates Use credentials or dispatches that trigger downstream workflows The documented file locations omit the.github/prefix, but the action and docs are actually… The README referencesactions/sync-branches/consumer-template.yml, but in this repo the template…



No description provided.