Repository navigation
[backport-security_detection_engine-9.4] (backport #21243) [sync-changelog] Assign sync PRs and always run from main - #21297
Merged
Conversation
[sync-changelog] Assign sync PR to the backport PR author or merger
When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.
[sync-changelog] Always load action and binary from main
Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.
Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.
[sync-changelog] Use bot flag and write access to resolve sync PR assignee
Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.
Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
(cherry picked from commit 6bba11e)
2 tasks
💚 Build Succeeded
cc @mrodm |
mrodm
approved these changes
Sep 16, 2026
mrodm
merged commit Sep 16, 2026
7d516a8
into
backport-security_detection_engine-9.4
9 checks passed
mrodm
deleted the
mergify/bp/backport-security_detection_engine-9.4/pr-21243
branch
September 16, 2026 08:11
Contributor
|
Changelog sync skipped — all changelog versions are already present on |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Proposed commit message
What and Why
Assignee on sync PRs (
cmd/backport/backports/changelog/sync.go)Changelog sync PRs created by the
sync-backport-changelogworkflow had no assignee set, leaving them unowned. This change resolves the assignee automatically from the originating backport PR using the following logic:authorandmergedBy(includingis_botflag) in a singlegh pr viewcall.GET /repos/{repo}/collaborators/{login}/permission(works with the existingcontents:write+pull-requests:writeGITHUB_TOKENpermissions).mergedBy, as long as they are not a bot (the merger always has repo write access by definition).--assigneeso PR creation is not blocked.Always run from main (
.github/workflows/sync-backport-changelog.yml,.github/actions/sync-backport-changelog/action.yml)Previously the workflow loaded the composite action from the branch that triggered it (
./.github/actions/sync-backport-changelog). Improvements merged tomainwould not apply to pushes on existing backport branches. This change:pushandissue_comment) to referenceelastic/integrations/.github/actions/sync-backport-changelog@main.actions/checkout@v7withref: maininside the action so the Go binary is also always built frommain'scmd/backport.actions/checkoutsteps from the workflow (the action does its own checkout).Author's Checklist
pickAssigneeis covered by unit tests (TestPickAssignee) including bot-author, external-contributor, and both-bots scenarios.How to test this PR locally
changelog.ymlchange.sync-backport-changelogworkflow creates a sync PR with the correct assignee (the PR author if not a bot and has repo write access, otherwise the merger if not a bot)./sync-changelogon a merged backport PR to trigger the retry path and verify the same.Related issues
This is an automatic backport of pull request #21243 done by [Mergify](https://mergify.com).