Skip to content

fix(github-actions): enforce approval SHA freshness and harden post-approval review requests - #4024

Open
josephperrott wants to merge 4 commits into
angular:mainfrom
josephperrott:fix/review-gate-sha-freshness
Open

josephperrott wants to merge 4 commits into
angular:mainfrom
josephperrott:fix/review-gate-sha-freshness

Conversation

@josephperrott

Copy link
Copy Markdown
Member

Enforce commit SHA freshness on pull request approvals across post-approval-changes and assertMinimumReviews, ignore trailing COMMENTED reviews when deduplicating reviewer states, re-request all stale Googler approvers, and fail closed if the googlers org installation token cannot be obtained.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request refactors the post-approval changes GitHub Action by extracting its core logic into a separate module, adding comprehensive unit tests, and enhancing its behavior to handle reopened events, ignore comment-only reviews, and re-request reviews from all stale approvers. Additionally, it updates the pull request validation to ensure that at least one team member's review is on the latest commit. The review feedback suggests wrapping individual token revocations in separate try-catch blocks within the finally block to prevent token leaks if one revocation fails, and adding defensive null checks for the review object during validation to avoid potential runtime crashes.

Comment thread github-actions/post-approval-changes/lib/post-approval-changes.ts
Comment thread ng-dev/pr/common/validation/assert-minimum-reviews.ts
@josephperrott
josephperrott force-pushed the fix/review-gate-sha-freshness branch from 6d84029 to 8637afd Compare October 9, 2026 18:54
@josephperrott
josephperrott force-pushed the fix/review-gate-sha-freshness branch from 8637afd to 0b46e3a Compare October 9, 2026 19:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant