Repository navigation
fix(ci): restore pull_request_target trigger for PR gate - #1282
Conversation
The Blacksmith migration (#1249) changed the PR Gate trigger from `pull_request_target` to `pull_request`. For PRs opened by outside contributors, `pull_request` workflows are gated as `action_required` and do not run without a maintainer manually approving them, so the auto-close gate silently stopped firing (e.g. #1281 stayed open). Restore `pull_request_target` so the gate runs with the base repo's write permissions and can close unapproved PRs automatically. This workflow never checks out PR code — it only calls the GitHub API via github-script — so the usual pull_request_target injection risk does not apply. Added an inline comment documenting the requirement to prevent the same regression in future workflow edits.
|
This run was cancelled 🛑 The workflow was cancelled before completion. Please check the link below for details. |
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
ccusage-guide | 67ae53e | Commit Preview URL Branch Preview URL |
Jun 11 2026, 06:55 PM |
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe PR updates the ChangesPR Gate Workflow Configuration
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Poem
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
ccusage performance comparisonPR SHA: This compares the PR package against the configured base package on the same CI runner. Package runner startupExecution setup measures any pre-benchmark package materialization used by the execution benchmark. Bunx temp cache measures one
Cached bunx execution performanceRuns the same large fixture through Fixtures: Claude
Package runtime diagnosticsCompares the PR package wrapper, the installed native optional dependency binary, and the workspace release binary on the same large fixture. This identifies whether slow package results come from JavaScript wrapper overhead, the published native binary build, or the Rust core itself. Fixtures: Claude
Committed fixture performanceCommitted small fixtures for stable PR-to-PR feedback and explicit Claude/Codex command coverage. Fixtures: Claude
Large real-world-shaped fixture performanceGenerated fixtures shaped from aggregate local log statistics: thousands of JSONL files, many small sessions, and a long tail of larger sessions. No real prompts, paths, or outputs are stored in the fixtures. Fixtures: Claude
Artifact size
Lower medians and smaller artifacts are better. CI runner noise still applies; use same-run ratios as directional PR feedback, not release guarantees. |
ccusage performance comparisonPR SHA: This compares the Rust PR release binary against the configured base package on the same CI runner. Package runner startupExecution setup measures any pre-benchmark package materialization used by the execution benchmark. Bunx temp cache measures one
Cached bunx execution performanceRuns the same large fixture through Fixtures: Claude
Package runtime diagnosticsCompares the PR package wrapper, the installed native optional dependency binary, and the workspace release binary on the same large fixture. This identifies whether slow package results come from JavaScript wrapper overhead, the published native binary build, or the Rust core itself. Fixtures: Claude
Committed fixture performanceCommitted small fixtures for stable PR-to-PR feedback and explicit Claude/Codex command coverage. Fixtures: Claude
Large real-world-shaped fixture performanceGenerated fixtures shaped from aggregate local log statistics: thousands of JSONL files, many small sessions, and a long tail of larger sessions. No real prompts, paths, or outputs are stored in the fixtures. Fixtures: Claude
Artifact size
Lower medians and smaller artifacts are better. CI runner noise still applies; use same-run ratios as directional PR feedback, not release guarantees. |

What
Restore the PR Gate workflow trigger from
pull_requestback topull_request_target.Why
The Blacksmith migration (#1249) intentionally moved the gate away from
pull_request_targetto avoid a privileged target workflow. That had an unintended side effect: for PRs opened by outside contributors, plainpull_requestworkflows are held asaction_requiredand never run without a maintainer manually approving them. As a result the auto-close gate silently stopped firing — e.g. #1281 was opened by a non-approved contributor but stayed open instead of being auto-closed.pull_request_targetruns with the base repository write permissions, so the gate can close unapproved PRs automatically again.Safety
This is the canonical safe use of
pull_request_target:actions/checkout, and it only calls the GitHub API viagithub-script.APPROVED_CONTRIBUTORSfrom the default branch, not the PR head, so the PR cannot tamper with the allowlist.contextobject, not interpolated into shell/script strings, so there is no script-injection vector.contents: read,issues: write,pull-requests: write.The classic
pull_request_targettoken-theft / "pwn request" attacks require executing attacker-controlled PR code in the privileged context, which this workflow does not do. An inline comment was added documenting this requirement so a future edit that addsactions/checkoutdoes not silently reintroduce the risk.Closes the gap that left #1281 open.
Need help on this PR? Tag
/codesmithwith what you need. Autofix is enabled.Summary by cubic
Restore the PR Gate workflow to
pull_request_targetso it runs on forked/outside-contributor PRs and auto-closes unapproved PRs. Fixes the regression wherepull_requestjobs stayedaction_requiredand never ran.pull_request_targetand documented safe use (no checkout; usesgithub-script; reads allowlist from default branch; scoped permissions).Written for commit 67ae53e. Summary will update on new commits.
Summary by CodeRabbit