🔍 Duplicate Code Detected: Duplicated pull_request event detection
Analysis of commit 3fd44f8
Assignee: @copilot
Summary
Two functions in the workflow package implement identical logic (22 lines) to detect whether an on: field declares pull_request / pull_request_target events. They were copy-pasted across two files rather than shared.
Duplication Details
Pattern: on field -> (hasPR, hasPRTarget)
- Severity: Medium
- Occurrences: 2 (exact duplicate, different files, same package)
- Locations:
pkg/workflow/safe_update_enforcement.go (lines 131-153, extractPullRequestEventPresenceFromOnField)
pkg/workflow/safe_update_manifest.go (lines 182-204, detectPullRequestEvents)
- Code Sample:
func detectPullRequestEvents(onField any) (hasPR bool, hasPRTarget bool) {
switch v := onField.(type) {
case string:
return v == "pull_request", v == "pull_request_target"
case []any:
for _, item := range v {
event, ok := item.(string)
if !ok { continue }
if event == "pull_request" { hasPR = true }
if event == "pull_request_target" { hasPRTarget = true }
}
case map[string]any:
_, hasPR = v["pull_request"]
_, hasPRTarget = v["pull_request_target"]
}
return hasPR, hasPRTarget
}
extractPullRequestEventPresenceFromOnField is identical except for its name.
Both live in package workflow, so one can directly call the other with no import changes. Current callers: compiler.go:639 and safe_update_enforcement.go:164 use the first; safe_update_manifest.go:131 uses the second.
Impact Analysis
- Maintainability: Event-shape handling (string / array / map) must be kept in sync in two files.
- Bug Risk: High for a correctness-sensitive area — safe-update enforcement depends on accurate PR-event detection; divergence could weaken a security check.
- Code Bloat: ~22 redundant lines.
Refactoring Recommendations
- Keep a single detection helper
- Remove
detectPullRequestEvents and route its caller to extractPullRequestEventPresenceFromOnField (or move the shared helper to a neutral location and have both files call it).
- Estimated effort: ~20 min, low complexity.
- Benefits: one source of truth for a security-relevant check, −22 lines.
Implementation Checklist
Analysis Metadata
- Analyzed Files: pkg/ (1435 non-test .go files)
- Detection Method: Serena semantic code analysis + function-body fingerprinting
- Commit: 3fd44f8
- Analysis Date: 2026-10-06
Generated by 🔍 Duplicate Code Detector · pi · opus48 · 74.5 AIC · ⌖ 41.3 AIC · ⊞ 1.5K · ◷
🔍 Duplicate Code Detected: Duplicated pull_request event detection
Analysis of commit 3fd44f8
Assignee:
@copilotSummary
Two functions in the
workflowpackage implement identical logic (22 lines) to detect whether anon:field declarespull_request/pull_request_targetevents. They were copy-pasted across two files rather than shared.Duplication Details
Pattern:
onfield -> (hasPR, hasPRTarget)pkg/workflow/safe_update_enforcement.go(lines 131-153,extractPullRequestEventPresenceFromOnField)pkg/workflow/safe_update_manifest.go(lines 182-204,detectPullRequestEvents)extractPullRequestEventPresenceFromOnFieldis identical except for its name.Both live in package
workflow, so one can directly call the other with no import changes. Current callers:compiler.go:639andsafe_update_enforcement.go:164use the first;safe_update_manifest.go:131uses the second.Impact Analysis
Refactoring Recommendations
detectPullRequestEventsand route its caller toextractPullRequestEventPresenceFromOnField(or move the shared helper to a neutral location and have both files call it).Implementation Checklist
safe_update_manifest.go:131to use itmake fmtandmake test-unitAnalysis Metadata