Repository navigation
fix(github-actions): harden google-internal-tests against SHA status overwrite and 3000-file truncation - #4027
Open
josephperrott wants to merge 2 commits into
Conversation
…tatus on non-main PRs Because GitHub commit statuses are scoped to a commit SHA rather than a pull request, opening a secondary pull request targeting a non-main branch with the same head SHA previously overwrote an active pending google-internal-tests status with a skipped success status. Extend the existing status guard to also preserve any active pending status on the head SHA.
There was a problem hiding this comment.
Code Review
This pull request introduces unit tests for the google-internal-tests GitHub Action by exporting the main function, allowing dependency injection of github and syncConfig, and adding a new Bazel test target. It also implements a fail-closed mechanism when the PR file list reaches the GitHub pagination limit. The reviewer feedback suggests renaming the injected parameters to avoid parameter reassignment and using nullish coalescing to simplify the initialization logic.
josephperrott
force-pushed
the
fix/google-internal-tests-hardening
branch
from
October 9, 2026 20:22
2896f90 to
5a020b6
Compare
…GitHub 3000-file pagination limit GitHub's REST API caps the pulls.listFiles endpoint at 3,000 files. When a pull request modifies 3,000 or more files (or returns fewer files than pull_request.changed_files), fail closed by emitting a warning and treating the pull request as affecting Google internal tests.
josephperrott
force-pushed
the
fix/google-internal-tests-hardening
branch
from
October 9, 2026 20:23
5a020b6 to
2f17723
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
pendingstatus on commit SHAs across pull requests: Because GitHub commit statuses are globally scoped to a commit SHA rather than a pull request, opening a secondary pull request targeting a non-mainbranch with the same head SHA previously overwrote an activependinggoogle-internal-testsstatus with a skippedsuccessstatus. Extend the existing status guard to preserve any activependingstatus on the head SHA in addition to statuses pointing to internal CL URLs.pulls.listFilesat 3,000 files. When a pull request returns 3,000 or more files (or fewer files thanpull_request.changed_files), emit a warning and setaffectsGoogle = trueso the action fails closed with apendingstatus instead of posting"Does not affect Google.".google-internal-testsstatus resolution, overwrite protection, and file list truncation.