Repository navigation
[sync-changelog] Assign sync PRs and always run from main - #21243
Conversation
When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is skipped so PR creation is not blocked. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…ignee
Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.
Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
🔵 Needs a closer look
Existing backport branches are not migrated and may continue using the old workflow and action.
Pull request overview
Updates changelog sync automation to assign eligible PR owners and consistently use the main branch implementation.
Changes:
- Adds bot-aware assignee resolution and tests.
- References the composite action from
main. - Checks out
mainbefore building the Go binary.
File summaries
| File | Description |
|---|---|
cmd/backport/backports/changelog/sync.go |
Resolves and applies sync PR assignees. |
cmd/backport/backports/changelog/sync_test.go |
Tests assignee selection scenarios. |
.github/workflows/sync-backport-changelog.yml |
References the action from main. |
.github/actions/sync-backport-changelog/action.yml |
Checks out main before building. |
Review details
Suppressed comments (1)
.github/workflows/sync-backport-changelog.yml:31
- This updates only the copy of the workflow on
main; existingbackport-*branches still execute the workflow file stored on those branches, so they will continue using the old local action (or no workflow) and will not get the promised main-built action/binary. The branch-creation script only copies.github/workflowsfor newly created branches, so an active-branch migration (or an equivalent bootstrap step) is needed for this change to cover existing branches.
- uses: elastic/integrations/.github/actions/sync-backport-changelog@main
- Files reviewed: 4/4 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
🔵 Needs a closer look
Existing active backport branches are not updated to use the action from main.
Review details
Suppressed comments (1)
.github/workflows/sync-backport-changelog.yml:31
- Because GitHub resolves both
pushandissue_commentworkflows from the backport branch, this change only affects branches whose copy ofsync-backport-changelog.ymlhas already been updated. Existing active backport branches still contain the old./.github/actions/sync-backport-changelogreferences and will continue running their branch-local action, so the stated “always run from main” guarantee is not true for them. Please include or run the active-branch migration described in #19262, or explicitly scope this change to new/updated branches.
- uses: elastic/integrations/.github/actions/sync-backport-changelog@main
- Files reviewed: 4/4 changed files
- Comments generated: 0 new
- Review effort level: Lite
💚 Build Succeeded
History
cc @mrodm |
|
Tick the box to add this pull request to the merge queue (same as
|
|
@Mergifyio backport backport-aws-6.x backport-aws-7.1 backport-aws-7.0 backport-aws-7.2 backport-aws-7.3 backport-security_detection_engine-9.4 backport-security_detection_engine-9.3 backport-security_detection_engine-8.19 |
…21292) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21374) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21375) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21376) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21377) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21378) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
|
@Mergifyio backport backport-cloud_security_posture-1.0 backport-cloud_security_posture-1.1 backport-cloud_security_posture-1.2 backport-cloud_security_posture-1.3 backport-cloud_security_posture-1.4 backport-cloud_security_posture-1.5 backport-cloud_security_posture-1.7 backport-cloud_security_posture-3.0 backport-cloud_security_posture-3.1 backport-cloud_security_posture-3.2 |
…tion Add a paragraph to step 4 explaining that the sync-backport-changelog workflow now automatically assigns the sync PR to the backport PR's author (if not a bot and has write/maintain/admin access) or to the merger (if not a bot). Reflects elastic#21243, merged 2026-09-15. Add a sentence to the checklist comment section documenting that auto-backport PRs are automatically assigned to the original PR's author or merger using the same logic. Preemptive for elastic#21379 (open). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…21382) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21383) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21384) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21385) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21386) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21387) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21388) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21389) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21390) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…21391) [sync-changelog] Assign sync PR to the backport PR author or merger When creating the changelog sync PR, resolve the assignee from the originating backport PR: use the PR author if they are an elastic org member, otherwise fall back to whoever merged the PR. If the lookup fails for any reason, the --assignee flag is omitted so PR creation is not blocked. [sync-changelog] Always load action and binary from main Replace the local ./.github/actions/sync-backport-changelog reference with elastic/integrations/.github/actions/sync-backport-changelog@main in both the push and issue_comment jobs, so the action definition is always fetched from main regardless of which backport branch triggered the run. Add an explicit checkout of main inside the action so the Go binary is also always built from main's cmd/backport, not from a potentially older backport branch. [sync-changelog] Use bot flag and write access to resolve sync PR assignee Replace the elastic org membership check (which required read:org scope not available on GITHUB_TOKEN) with a collaborator permission check via GET /repos/{repo}/collaborators/{login}/permission, which works with the existing contents:write + pull-requests:write permissions. Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON so bot detection uses the API's own is_bot flag rather than string matching. pickAssignee now guards both the author and mergedBy paths: - Use author if not a bot and has write/maintain/admin access. - Fall back to mergedBy if not a bot. - Return empty string (skip --assignee) if neither qualifies. --------- (cherry picked from commit 6bba11e) Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…er (#21379) When the auto-backport workflow opens a PR targeting a backport branch, resolve the assignee from the source PR that was merged into main using the same logic introduced for sync-changelog PRs in #21243: - Use the PR author if they are not a bot and have repo write access. - Fall back to whoever merged the PR if the author doesn't qualify (also checked for write access to guard against revoked access post-merge). - Omit --assignee entirely if neither qualifies, so PR creation is not blocked. Resolution logic is centralised in a new cmd/backport/assign package (PRActor, Resolve, Pick) shared by both the apply and changelog/sync code paths, eliminating the duplication that existed between them. The workflow passes the original PR number via --origin-pr-number through backport_apply.sh to the backport binary, which performs the two API calls (gh pr view + collaborator permission check) internally. assign.Resolve is guarded by OpenPR && !DryRun to avoid redundant API calls in non-PR paths. --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Proposed commit message
What and Why
Assignee on sync PRs (
cmd/backport/backports/changelog/sync.go)Changelog sync PRs created by the
sync-backport-changelogworkflow had no assignee set, leaving them unowned. This change resolves the assignee automatically from the originating backport PR using the following logic:authorandmergedBy(includingis_botflag) in a singlegh pr viewcall.GET /repos/{repo}/collaborators/{login}/permission(works with the existingcontents:write+pull-requests:writeGITHUB_TOKENpermissions).mergedBy, as long as they are not a bot (the merger always has repo write access by definition).--assigneeso PR creation is not blocked.Always run from main (
.github/workflows/sync-backport-changelog.yml,.github/actions/sync-backport-changelog/action.yml)Previously the workflow loaded the composite action from the branch that triggered it (
./.github/actions/sync-backport-changelog). Improvements merged tomainwould not apply to pushes on existing backport branches. This change:pushandissue_comment) to referenceelastic/integrations/.github/actions/sync-backport-changelog@main.actions/checkout@v7withref: maininside the action so the Go binary is also always built frommain'scmd/backport.actions/checkoutsteps from the workflow (the action does its own checkout).Author's Checklist
pickAssigneeis covered by unit tests (TestPickAssignee) including bot-author, external-contributor, and both-bots scenarios.How to test this PR locally
changelog.ymlchange.sync-backport-changelogworkflow creates a sync PR with the correct assignee (the PR author if not a bot and has repo write access, otherwise the merger if not a bot)./sync-changelogon a merged backport PR to trigger the retry path and verify the same.Related issues