Skip to content

[duplicate-code] Duplicate Code: pull_request event detection duplicated across safe_update files #66295

Description

@github-actions

🔍 Duplicate Code Detected: Duplicated pull_request event detection

Analysis of commit 3fd44f8

Assignee: @copilot

Summary

Two functions in the workflow package implement identical logic (22 lines) to detect whether an on: field declares pull_request / pull_request_target events. They were copy-pasted across two files rather than shared.

Duplication Details

Pattern: on field -> (hasPR, hasPRTarget)

  • Severity: Medium
  • Occurrences: 2 (exact duplicate, different files, same package)
  • Locations:
    • pkg/workflow/safe_update_enforcement.go (lines 131-153, extractPullRequestEventPresenceFromOnField)
    • pkg/workflow/safe_update_manifest.go (lines 182-204, detectPullRequestEvents)
  • Code Sample:
    func detectPullRequestEvents(onField any) (hasPR bool, hasPRTarget bool) {
        switch v := onField.(type) {
        case string:
            return v == "pull_request", v == "pull_request_target"
        case []any:
            for _, item := range v {
                event, ok := item.(string)
                if !ok { continue }
                if event == "pull_request" { hasPR = true }
                if event == "pull_request_target" { hasPRTarget = true }
            }
        case map[string]any:
            _, hasPR = v["pull_request"]
            _, hasPRTarget = v["pull_request_target"]
        }
        return hasPR, hasPRTarget
    }
    extractPullRequestEventPresenceFromOnField is identical except for its name.

Both live in package workflow, so one can directly call the other with no import changes. Current callers: compiler.go:639 and safe_update_enforcement.go:164 use the first; safe_update_manifest.go:131 uses the second.

Impact Analysis

  • Maintainability: Event-shape handling (string / array / map) must be kept in sync in two files.
  • Bug Risk: High for a correctness-sensitive area — safe-update enforcement depends on accurate PR-event detection; divergence could weaken a security check.
  • Code Bloat: ~22 redundant lines.

Refactoring Recommendations

  1. Keep a single detection helper
    • Remove detectPullRequestEvents and route its caller to extractPullRequestEventPresenceFromOnField (or move the shared helper to a neutral location and have both files call it).
    • Estimated effort: ~20 min, low complexity.
    • Benefits: one source of truth for a security-relevant check, −22 lines.

Implementation Checklist

  • Review duplication findings
  • Choose a single canonical helper name/location
  • Update safe_update_manifest.go:131 to use it
  • Remove the duplicate function
  • Run make fmt and make test-unit
  • Verify safe-update enforcement tests still pass
Analysis Metadata
  • Analyzed Files: pkg/ (1435 non-test .go files)
  • Detection Method: Serena semantic code analysis + function-body fingerprinting
  • Commit: 3fd44f8
  • Analysis Date: 2026-10-06

Generated by 🔍 Duplicate Code Detector · pi · opus48 · 74.5 AIC · ⌖ 41.3 AIC · ⊞ 1.5K · ◷

  • expires on Oct 8, 2026, 1:56 PM UTC-08:00

Activity

  1. github-actions commented on Oct 8, 2026

    @github-actions
    ContributorAuthor

    This issue was automatically closed because it expired on 2026-10-08T21:56:33.601Z.

    Closed by Workflow

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions