Skip to content

[backport-security_detection_engine-8.19] (backport #21243) [sync-changelog] Assign sync PRs and always run from main - #21299

Merged
mrodm merged 1 commit into
backport-security_detection_engine-8.19from
mergify/bp/backport-security_detection_engine-8.19/pr-21243
Sep 16, 2026
Merged

mrodm merged 1 commit into
backport-security_detection_engine-8.19from
mergify/bp/backport-security_detection_engine-8.19/pr-21243

Conversation

@mergify

@mergify mergify Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Proposed commit message

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

What and Why

Assignee on sync PRs (cmd/backport/backports/changelog/sync.go)

Changelog sync PRs created by the sync-backport-changelog workflow had no assignee set, leaving them unowned. This change resolves the assignee automatically from the originating backport PR using the following logic:

  1. Fetch the backport PR's author and mergedBy (including is_bot flag) in a single gh pr view call.
  2. Use the author if they are not a bot and have write/maintain/admin access on the repo, checked via GET /repos/{repo}/collaborators/{login}/permission (works with the existing contents:write + pull-requests:write GITHUB_TOKEN permissions).
  3. Otherwise fall back to mergedBy, as long as they are not a bot (the merger always has repo write access by definition).
  4. If neither qualifies (e.g. both are bots), omit --assignee so PR creation is not blocked.

Always run from main (.github/workflows/sync-backport-changelog.yml, .github/actions/sync-backport-changelog/action.yml)

Previously the workflow loaded the composite action from the branch that triggered it (./.github/actions/sync-backport-changelog). Improvements merged to main would not apply to pushes on existing backport branches. This change:

  • Switches both jobs (push and issue_comment) to reference elastic/integrations/.github/actions/sync-backport-changelog@main.
  • Adds an explicit actions/checkout@v7 with ref: main inside the action so the Go binary is also always built from main's cmd/backport.
  • Removes the now-redundant actions/checkout steps from the workflow (the action does its own checkout).

Author's Checklist

How to test this PR locally

  1. Merge a PR into a backport branch that has a changelog.yml change.
  2. Observe that the sync-backport-changelog workflow creates a sync PR with the correct assignee (the PR author if not a bot and has repo write access, otherwise the merger if not a bot).
  3. Alternatively, comment /sync-changelog on a merged backport PR to trigger the retry path and verify the same.

Related issues


This PR was generated with the assistance of Claude (claude-sonnet-4-6).


This is an automatic backport of pull request #21243 done by [Mergify](https://mergify.com).

[sync-changelog] Assign sync PR to the backport PR author or merger

When creating the changelog sync PR, resolve the assignee from the
originating backport PR: use the PR author if they are an elastic org
member, otherwise fall back to whoever merged the PR. If the lookup
fails for any reason, the --assignee flag is omitted so PR creation
is not blocked.

[sync-changelog] Always load action and binary from main

Replace the local ./.github/actions/sync-backport-changelog reference
with elastic/integrations/.github/actions/sync-backport-changelog@main
in both the push and issue_comment jobs, so the action definition is
always fetched from main regardless of which backport branch triggered
the run.

Add an explicit checkout of main inside the action so the Go binary is
also always built from main's cmd/backport, not from a potentially
older backport branch.

[sync-changelog] Use bot flag and write access to resolve sync PR assignee

Replace the elastic org membership check (which required read:org scope
not available on GITHUB_TOKEN) with a collaborator permission check via
GET /repos/{repo}/collaborators/{login}/permission, which works with the
existing contents:write + pull-requests:write permissions.

Introduce prActor{Login, IsBot} parsed directly from the gh pr view JSON
so bot detection uses the API's own is_bot flag rather than string
matching. pickAssignee now guards both the author and mergedBy paths:
- Use author if not a bot and has write/maintain/admin access.
- Fall back to mergedBy if not a bot.
- Return empty string (skip --assignee) if neither qualifies.

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
(cherry picked from commit 6bba11e)
@mergify
mergify Bot requested a review from a team as a code owner September 16, 2026 07:56
@mergify mergify Bot added the backport label Sep 16, 2026
@mergify mergify Bot assigned mrodm Sep 16, 2026
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

cc @mrodm

@mrodm
mrodm merged commit 7cf8619 into backport-security_detection_engine-8.19 Sep 16, 2026
10 checks passed
@mrodm
mrodm deleted the mergify/bp/backport-security_detection_engine-8.19/pr-21243 branch September 16, 2026 08:11
@github-actions

Copy link
Copy Markdown
Contributor

Changelog sync skipped — all changelog versions are already present on main.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant