Skip to content

fix(ci): restore pull_request_target trigger for PR gate - #1282

Merged
ryoppippi merged 1 commit into
mainfrom
fix/pr-gate-trigger
Jun 11, 2026
Merged

ryoppippi merged 1 commit into
mainfrom
fix/pr-gate-trigger

Conversation

@ryoppippi

@ryoppippi ryoppippi commented Jun 11, 2026 •

Copy link
Copy Markdown
Member

What

Restore the PR Gate workflow trigger from pull_request back to pull_request_target.

Why

The Blacksmith migration (#1249) intentionally moved the gate away from pull_request_target to avoid a privileged target workflow. That had an unintended side effect: for PRs opened by outside contributors, plain pull_request workflows are held as action_required and never run without a maintainer manually approving them. As a result the auto-close gate silently stopped firing — e.g. #1281 was opened by a non-approved contributor but stayed open instead of being auto-closed.

-  pull_request_target:
+  pull_request:

pull_request_target runs with the base repository write permissions, so the gate can close unapproved PRs automatically again.

Safety

This is the canonical safe use of pull_request_target:

  • It never checks out PR code — there is no actions/checkout, and it only calls the GitHub API via github-script.
  • It reads APPROVED_CONTRIBUTORS from the default branch, not the PR head, so the PR cannot tamper with the allowlist.
  • Untrusted payload values (e.g. the PR author login) are passed as API parameters via the context object, not interpolated into shell/script strings, so there is no script-injection vector.
  • Token permissions are scoped to contents: read, issues: write, pull-requests: write.

The classic pull_request_target token-theft / "pwn request" attacks require executing attacker-controlled PR code in the privileged context, which this workflow does not do. An inline comment was added documenting this requirement so a future edit that adds actions/checkout does not silently reintroduce the risk.

Closes the gap that left #1281 open.


View with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is enabled.


Summary by cubic

Restore the PR Gate workflow to pull_request_target so it runs on forked/outside-contributor PRs and auto-closes unapproved PRs. Fixes the regression where pull_request jobs stayed action_required and never ran.

  • Bug Fixes
    • Switched trigger back to pull_request_target and documented safe use (no checkout; uses github-script; reads allowlist from default branch; scoped permissions).

Written for commit 67ae53e. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • Chores
    • Updated internal GitHub Actions workflow configuration for pull request handling.

The Blacksmith migration (#1249) changed the PR Gate trigger from
`pull_request_target` to `pull_request`. For PRs opened by outside
contributors, `pull_request` workflows are gated as `action_required`
and do not run without a maintainer manually approving them, so the
auto-close gate silently stopped firing (e.g. #1281 stayed open).

Restore `pull_request_target` so the gate runs with the base repo's
write permissions and can close unapproved PRs automatically. This
workflow never checks out PR code — it only calls the GitHub API via
github-script — so the usual pull_request_target injection risk does
not apply. Added an inline comment documenting the requirement to
prevent the same regression in future workflow edits.
@pullfrog

pullfrog Bot commented Jun 11, 2026 •

Copy link
Copy Markdown
Contributor

This run was cancelled 🛑

The workflow was cancelled before completion. Please check the link below for details.

Pullfrog  | View workflow run | via Pullfrog | 𝕏

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
ccusage-guide 67ae53e Commit Preview URL

Branch Preview URL
Jun 11 2026, 06:55 PM

@coderabbitai

coderabbitai Bot commented Jun 11, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: a16945a6-5799-465c-baba-4a0c682f5846

📥 Commits

Reviewing files that changed from the base of the PR and between f28fa45 and 67ae53e.

📒 Files selected for processing (1)
  • .github/workflows/pr-gate.yaml

📝 Walkthrough

Walkthrough

The PR updates the PR Gate workflow's event trigger from pull_request to pull_request_target and adds inline documentation explaining the permission and gating behavior difference. The pull_request_target variant runs with base-repo write permissions for forked and outside-contributor PRs, while pull_request would silently no-op for such contributors.

Changes

PR Gate Workflow Configuration

Layer / File(s) Summary
Pull request trigger update with permission documentation
.github/workflows/pr-gate.yaml
Workflow event trigger changed from pull_request to pull_request_target, with added comments explaining permission and gating behavior for outside-contributor PRs.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

🐰 A trigger springs to life anew,
pull_request_target shines through,
With permissions wise and fortified clear,
No silent fails for guests held dear! 🔐✨

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/pr-gate-trigger

Comment @coderabbitai help to get the list of available commands and usage tips.

@ryoppippi
ryoppippi merged commit 4254918 into main Jun 11, 2026
14 of 15 checks passed
@ryoppippi
ryoppippi deleted the fix/pr-gate-trigger branch June 11, 2026 18:56
@github-actions

Copy link
Copy Markdown
Contributor

ccusage performance comparison

PR SHA: 67ae53ef18c3
Base SHA: f28fa456f0c8

This compares the PR package against the configured base package on the same CI runner.

Package runner startup

Execution setup measures any pre-benchmark package materialization used by the execution benchmark. Bunx temp cache measures one bunx -p <url> ccusage --version run with an empty Bun install cache. Warm reuses that cache and reports the median of repeated runs.

Package SHA Execution setup Bunx temp cache Bunx warm median Warm samples
Base pkg.pr.new f28fa456f0c8 967.4ms 1.057s 69.2ms 3
PR pkg.pr.new 67ae53e 1.061s 1.016s 64.6ms 3

Cached bunx execution performance

Runs the same large fixture through bunx -p <pkg.pr.new URL> ccusage after the Bun install cache has already been populated by the startup measurement. This separates cached package-runner execution from first-fetch package materialization.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2,597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2,597 files)
Base package: f28fa456f0c8; PR package: 67ae53e. Both run through bunx -p <pkg.pr.new URL> ccusage using the warmed Bun install cache from package runner startup, measured by hyperfine with 0 warmups and 1 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
bunx -p <pkg> ccusage claude --offline --json 1.01 GiB 772.1ms 874.6ms 0.88x 727.75 MiB 729.75 MiB 1.00x 1.30 GiB/s 1.15 GiB/s
bunx -p <pkg> ccusage codex --offline --json 1.01 GiB 220.8ms 205.0ms 1.08x 93.75 MiB 91.50 MiB 0.98x 4.56 GiB/s 4.91 GiB/s

Package runtime diagnostics

Compares the PR package wrapper, the installed native optional dependency binary, and the workspace release binary on the same large fixture. This identifies whether slow package results come from JavaScript wrapper overhead, the published native binary build, or the Rust core itself.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2,597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2,597 files)
All rows run --offline --json, measured by hyperfine with 0 warmups and 1 runs. This isolates wrapper overhead from the installed native optional dependency and the workspace release binary built on the runner.

Command Runtime Input Median Throughput Samples
claude --offline --json Package wrapper 1.01 GiB 914.9ms 1.10 GiB/s 1
claude --offline --json Installed native binary 1.01 GiB 850.5ms 1.18 GiB/s 1
codex --offline --json Package wrapper 1.01 GiB 183.6ms 5.48 GiB/s 1
codex --offline --json Installed native binary 1.01 GiB 150.2ms 6.70 GiB/s 1

Committed fixture performance

Committed small fixtures for stable PR-to-PR feedback and explicit Claude/Codex command coverage.

Fixtures: Claude apps/ccusage/test/fixtures/claude (0.00 MiB, 2 files), Codex apps/ccusage/test/fixtures/codex (0.00 MiB, 1 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs the published ccusage package from pkg.pr.new, installed before measurement. Both run --offline --json, measured by hyperfine with 2 warmups and 7 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude daily --offline --json 0.00 MiB 45.8ms 40.7ms 1.13x 43.00 MiB 43.00 MiB 1.00x 0.03 MiB/s 0.04 MiB/s
claude session --offline --json 0.00 MiB 49.7ms 49.6ms 1.00x 43.00 MiB 43.25 MiB 1.01x 0.03 MiB/s 0.03 MiB/s
codex daily --offline --json 0.00 MiB 50.8ms 50.2ms 1.01x 43.00 MiB 43.00 MiB 1.00x 0.02 MiB/s 0.02 MiB/s
codex session --offline --json 0.00 MiB 53.7ms 48.8ms 1.10x 43.00 MiB 43.00 MiB 1.00x 0.02 MiB/s 0.02 MiB/s

Large real-world-shaped fixture performance

Generated fixtures shaped from aggregate local log statistics: thousands of JSONL files, many small sessions, and a long tail of larger sessions. No real prompts, paths, or outputs are stored in the fixtures.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2,597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2,597 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs the published ccusage package from pkg.pr.new, installed before measurement. Both run --offline --json, measured by hyperfine with 0 warmups and 1 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude --offline --json 1.01 GiB 799.6ms 918.8ms 0.87x 741.50 MiB 739.75 MiB 1.00x 1.26 GiB/s 1.10 GiB/s
codex --offline --json 1.01 GiB 196.2ms 209.9ms 0.93x 92.75 MiB 90.25 MiB 0.97x 5.13 GiB/s 4.80 GiB/s

Artifact size

Artifact Base PR Delta Ratio
packed ccusage-*.tgz 17.32 KiB 17.32 KiB +0.00 KiB 1.00x
installed native package binary 3324.84 KiB 3324.84 KiB +0.00 KiB 1.00x

Lower medians and smaller artifacts are better. CI runner noise still applies; use same-run ratios as directional PR feedback, not release guarantees.

@github-actions

Copy link
Copy Markdown
Contributor

ccusage performance comparison

PR SHA: 67ae53ef18c3
Base SHA: f28fa456f0c8

This compares the Rust PR release binary against the configured base package on the same CI runner.

Package runner startup

Execution setup measures any pre-benchmark package materialization used by the execution benchmark. Bunx temp cache measures one bunx -p <url> ccusage --version run with an empty Bun install cache. Warm reuses that cache and reports the median of repeated runs.

Package SHA Execution setup Bunx temp cache Bunx warm median Warm samples
Base pkg.pr.new f28fa456f0c8 1.192s 900.6ms 71.0ms 3
PR pkg.pr.new 67ae53e 1.005s 925.5ms 63.2ms 3

Cached bunx execution performance

Runs the same large fixture through bunx -p <pkg.pr.new URL> ccusage after the Bun install cache has already been populated by the startup measurement. This separates cached package-runner execution from first-fetch package materialization.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2,597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2,597 files)
Base package: f28fa456f0c8; PR package: 67ae53e. Both run through bunx -p <pkg.pr.new URL> ccusage using the warmed Bun install cache from package runner startup, measured by hyperfine with 0 warmups and 1 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
bunx -p <pkg> ccusage claude --offline --json 1.01 GiB 968.2ms 942.7ms 1.03x 747.75 MiB 727.50 MiB 0.97x 1.04 GiB/s 1.07 GiB/s
bunx -p <pkg> ccusage codex --offline --json 1.01 GiB 211.5ms 207.1ms 1.02x 89.75 MiB 88.75 MiB 0.99x 4.76 GiB/s 4.86 GiB/s

Package runtime diagnostics

Compares the PR package wrapper, the installed native optional dependency binary, and the workspace release binary on the same large fixture. This identifies whether slow package results come from JavaScript wrapper overhead, the published native binary build, or the Rust core itself.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2,597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2,597 files)
All rows run --offline --json, measured by hyperfine with 0 warmups and 1 runs. This isolates wrapper overhead from the installed native optional dependency and the workspace release binary built on the runner.

Command Runtime Input Median Throughput Samples
claude --offline --json Package wrapper 1.01 GiB 965.4ms 1.04 GiB/s 1
claude --offline --json Installed native binary 1.01 GiB 921.9ms 1.09 GiB/s 1
codex --offline --json Package wrapper 1.01 GiB 189.0ms 5.33 GiB/s 1
codex --offline --json Installed native binary 1.01 GiB 139.5ms 7.22 GiB/s 1

Committed fixture performance

Committed small fixtures for stable PR-to-PR feedback and explicit Claude/Codex command coverage.

Fixtures: Claude apps/ccusage/test/fixtures/claude (0.00 MiB, 2 files), Codex apps/ccusage/test/fixtures/codex (0.00 MiB, 1 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs rust/target/release/ccusage directly. Both run --offline --json, measured by hyperfine with 2 warmups and 7 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude daily --offline --json 0.00 MiB 49.9ms 6.0ms 8.31x - 2.75 MiB - 0.03 MiB/s 0.26 MiB/s
claude session --offline --json 0.00 MiB 44.5ms 5.9ms 7.49x 43.00 MiB 2.75 MiB 0.06x 0.03 MiB/s 0.26 MiB/s
codex daily --offline --json 0.00 MiB 40.4ms 6.1ms 6.63x 42.75 MiB 2.75 MiB 0.06x 0.02 MiB/s 0.14 MiB/s
codex session --offline --json 0.00 MiB 44.1ms 5.5ms 8.05x 43.00 MiB 2.75 MiB 0.06x 0.02 MiB/s 0.16 MiB/s

Large real-world-shaped fixture performance

Generated fixtures shaped from aggregate local log statistics: thousands of JSONL files, many small sessions, and a long tail of larger sessions. No real prompts, paths, or outputs are stored in the fixtures.

Fixtures: Claude /home/runner/_work/_temp/ccusage-large-fixture (1.01 GiB, 2,597 files), Codex /home/runner/_work/_temp/ccusage-large-codex-fixture (1.01 GiB, 2,597 files)
Base runs the published ccusage package from pkg.pr.new, installed before measurement; PR runs rust/target/release/ccusage directly. Both run --offline --json, measured by hyperfine with 0 warmups and 1 runs.
Peak RSS is measured separately with /usr/bin/time using 1 runs. Lower RSS ratios are better.

Command Input Base median PR median PR vs base Base peak RSS PR peak RSS PR/base RSS Base throughput PR throughput
claude --offline --json 1.01 GiB 842.3ms 926.6ms 0.91x 731.25 MiB 731.75 MiB 1.00x 1.20 GiB/s 1.09 GiB/s
codex --offline --json 1.01 GiB 176.2ms 137.4ms 1.28x 92.75 MiB 92.25 MiB 0.99x 5.71 GiB/s 7.33 GiB/s

Artifact size

Artifact Base PR Delta Ratio
packed ccusage-*.tgz 17.32 KiB 17.32 KiB +0.00 KiB 1.00x
installed native package binary 3324.84 KiB 3324.84 KiB +0.00 KiB 1.00x

Lower medians and smaller artifacts are better. CI runner noise still applies; use same-run ratios as directional PR feedback, not release guarantees.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant