Skip to content

[sync-changelog] Assign sync PRs and always run from main - #21243

Merged
mrodm merged 4 commits into
elastic:mainfrom
mrodm:add_assignee_sync_changelog_main
Sep 15, 2026
Merged

mrodm merged 4 commits into
elastic:mainfrom
mrodm:add_assignee_sync_changelog_main

Conversation

@mrodm

@mrodm mrodm commented Sep 14, 2026 •

Copy link
Copy Markdown
Collaborator

Proposed commit message

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

What and Why

Assignee on sync PRs (cmd/backport/backports/changelog/sync.go)

Changelog sync PRs created by the sync-backport-changelog workflow had no assignee set, leaving them unowned. This change resolves the assignee automatically from the originating backport PR using the following logic:

  1. Fetch the backport PR's author and mergedBy (including is_bot flag) in a single gh pr view call.
  2. Use the author if they are not a bot and have write/maintain/admin access on the repo, checked via GET /repos/{repo}/collaborators/{login}/permission (works with the existing contents:write + pull-requests:write GITHUB_TOKEN permissions).
  3. Otherwise fall back to mergedBy, as long as they are not a bot (the merger always has repo write access by definition).
  4. If neither qualifies (e.g. both are bots), omit --assignee so PR creation is not blocked.

Always run from main (.github/workflows/sync-backport-changelog.yml, .github/actions/sync-backport-changelog/action.yml)

Previously the workflow loaded the composite action from the branch that triggered it (./.github/actions/sync-backport-changelog). Improvements merged to main would not apply to pushes on existing backport branches. This change:

  • Switches both jobs (push and issue_comment) to reference elastic/integrations/.github/actions/sync-backport-changelog@main.
  • Adds an explicit actions/checkout@v7 with ref: main inside the action so the Go binary is also always built from main's cmd/backport.
  • Removes the now-redundant actions/checkout steps from the workflow (the action does its own checkout).

Author's Checklist

How to test this PR locally

  1. Merge a PR into a backport branch that has a changelog.yml change.
  2. Observe that the sync-backport-changelog workflow creates a sync PR with the correct assignee (the PR author if not a bot and has repo write access, otherwise the merger if not a bot).
  3. Alternatively, comment /sync-changelog on a merged backport PR to trigger the retry path and verify the same.

Related issues


This PR was generated with the assistance of Claude (claude-sonnet-4-6).

mrodm and others added 2 commits September 14, 2026 15:10
When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is skipped so PR creation
is not blocked.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@mrodm mrodm self-assigned this Sep 14, 2026
…ignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@mrodm
mrodm marked this pull request as ready for review September 14, 2026 16:54
@mrodm
mrodm requested a review from a team as a code owner September 14, 2026 16:54
Copilot AI lite review requested due to automatic review settings September 14, 2026 16:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Existing backport branches are not migrated and may continue using the old workflow and action.

Pull request overview

Updates changelog sync automation to assign eligible PR owners and consistently use the main branch implementation.

Changes:

  • Adds bot-aware assignee resolution and tests.
  • References the composite action from main.
  • Checks out main before building the Go binary.
File summaries
File Description
cmd/backport/backports/changelog/sync.go Resolves and applies sync PR assignees.
cmd/backport/backports/changelog/sync_test.go Tests assignee selection scenarios.
.github/workflows/sync-backport-changelog.yml References the action from main.
.github/actions/sync-backport-changelog/action.yml Checks out main before building.
Review details

Suppressed comments (1)

.github/workflows/sync-backport-changelog.yml:31

  • This updates only the copy of the workflow on main; existing backport-* branches still execute the workflow file stored on those branches, so they will continue using the old local action (or no workflow) and will not get the promised main-built action/binary. The branch-creation script only copies .github/workflows for newly created branches, so an active-branch migration (or an equivalent bootstrap step) is needed for this change to cover existing branches.
      - uses: elastic/integrations/.github/actions/sync-backport-changelog@main
  • Files reviewed: 4/4 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI review requested due to automatic review settings September 14, 2026 16:58

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Existing active backport branches are not updated to use the action from main.

Review details

Suppressed comments (1)

.github/workflows/sync-backport-changelog.yml:31

  • Because GitHub resolves both push and issue_comment workflows from the backport branch, this change only affects branches whose copy of sync-backport-changelog.yml has already been updated. Existing active backport branches still contain the old ./.github/actions/sync-backport-changelog references and will continue running their branch-local action, so the stated “always run from main” guarantee is not true for them. Please include or run the active-branch migration described in #19262, or explicitly scope this change to new/updated branches.
      - uses: elastic/integrations/.github/actions/sync-backport-changelog@main
  • Files reviewed: 4/4 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @mrodm

@mergify

mergify Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

@mrodm
mrodm merged commit 6bba11e into elastic:main Sep 15, 2026
8 checks passed
@mrodm
mrodm deleted the add_assignee_sync_changelog_main branch September 16, 2026 07:51
@mrodm

mrodm commented Sep 16, 2026

Copy link
Copy Markdown
Collaborator Author

@Mergifyio backport backport-aws-6.x backport-aws-7.1 backport-aws-7.0 backport-aws-7.2 backport-aws-7.3 backport-security_detection_engine-9.4 backport-security_detection_engine-9.3 backport-security_detection_engine-8.19

@mergify

mergify Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

backport backport-aws-6.x backport-aws-7.1 backport-aws-7.0 backport-aws-7.2 backport-aws-7.3 backport-security_detection_engine-9.4 backport-security_detection_engine-9.3 backport-security_detection_engine-8.19

✅ Backports have been created

Details

mrodm added a commit that referenced this pull request Sep 16, 2026
…21292)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21374)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21375)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21376)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21377)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21378)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
@mrodm

mrodm commented Sep 17, 2026

Copy link
Copy Markdown
Collaborator Author

@Mergifyio backport backport-cloud_security_posture-1.0 backport-cloud_security_posture-1.1 backport-cloud_security_posture-1.2 backport-cloud_security_posture-1.3 backport-cloud_security_posture-1.4 backport-cloud_security_posture-1.5 backport-cloud_security_posture-1.7 backport-cloud_security_posture-3.0 backport-cloud_security_posture-3.1 backport-cloud_security_posture-3.2

@mergify

mergify Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

backport backport-cloud_security_posture-1.0 backport-cloud_security_posture-1.1 backport-cloud_security_posture-1.2 backport-cloud_security_posture-1.3 backport-cloud_security_posture-1.4 backport-cloud_security_posture-1.5 backport-cloud_security_posture-1.7 backport-cloud_security_posture-3.0 backport-cloud_security_posture-3.1 backport-cloud_security_posture-3.2

❌ No backport have been created

Details

GitHub error: Branch not found

mrodm added a commit to mrodm/integrations that referenced this pull request Sep 17, 2026
…tion

Add a paragraph to step 4 explaining that the sync-backport-changelog
workflow now automatically assigns the sync PR to the backport PR's
author (if not a bot and has write/maintain/admin access) or to the
merger (if not a bot). Reflects elastic#21243, merged 2026-09-15.

Add a sentence to the checklist comment section documenting that
auto-backport PRs are automatically assigned to the original PR's
author or merger using the same logic. Preemptive for elastic#21379 (open).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21382)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21383)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21384)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21385)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21386)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21387)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21388)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21389)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21390)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 17, 2026
…21391)

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------


(cherry picked from commit 6bba11e)

Co-authored-by: Mario Rodriguez Molins <mario.rodriguez@elastic.co>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
mrodm added a commit that referenced this pull request Sep 18, 2026
…er (#21379)

When the auto-backport workflow opens a PR targeting a backport branch,
resolve the assignee from the source PR that was merged into main using
the same logic introduced for sync-changelog PRs in #21243:

- Use the PR author if they are not a bot and have repo write access.
- Fall back to whoever merged the PR if the author doesn't qualify (also
  checked for write access to guard against revoked access post-merge).
- Omit --assignee entirely if neither qualifies, so PR creation is not
  blocked.

Resolution logic is centralised in a new cmd/backport/assign package
(PRActor, Resolve, Pick) shared by both the apply and changelog/sync
code paths, eliminating the duplication that existed between them.

The workflow passes the original PR number via --origin-pr-number through
backport_apply.sh to the backport binary, which performs the two API
calls (gh pr view + collaborator permission check) internally.
assign.Resolve is guarded by OpenPR && !DryRun to avoid redundant API
calls in non-PR paths.

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants