Skip to content

fix(github-actions): pin context.sha during org file sync and validate preview artifact metadata - #4025

Open
josephperrott wants to merge 2 commits into
angular:mainfrom
josephperrott:fix/sync-pinning-and-preview-validation
Open

josephperrott wants to merge 2 commits into
angular:mainfrom
josephperrott:fix/sync-pinning-and-preview-validation

Conversation

@josephperrott

Copy link
Copy Markdown
Member

Pin context.sha when reading source files in org-file-sync and validate extracted preview artifact metadata (pull-number and build-revision) against the workflow_run event payload.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces unit tests and refactors code for testability across two GitHub Actions: org-file-sync and upload-artifacts-to-firebase. Specifically, it exports core functions, adds validation for commit SHAs and artifact metadata against trusted workflow payloads, and configures Bazel targets for Jasmine testing. Feedback on these changes suggests removing .trim() from the SHA validation regex to prevent passing untrimmed strings with whitespace to the GitHub API, and using optional chaining when accessing payload.workflow_run to avoid potential runtime errors if the parsed JSON is null.

Comment thread github-actions/org-file-sync/lib/main.ts Outdated
@josephperrott
josephperrott force-pushed the fix/sync-pinning-and-preview-validation branch from f07f6a6 to b793301 Compare October 9, 2026 18:55
@josephperrott
josephperrott force-pushed the fix/sync-pinning-and-preview-validation branch from b793301 to 9bf5a3d Compare October 9, 2026 19:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant