Skip to content

fix(github-actions): harden google-internal-tests against SHA status overwrite and 3000-file truncation - #4027

Open
josephperrott wants to merge 2 commits into
angular:mainfrom
josephperrott:fix/google-internal-tests-hardening
Open

josephperrott wants to merge 2 commits into
angular:mainfrom
josephperrott:fix/google-internal-tests-hardening

Conversation

@josephperrott

Copy link
Copy Markdown
Member

Summary

  • Preserve active pending status on commit SHAs across pull requests: Because GitHub commit statuses are globally scoped to a commit SHA rather than a pull request, opening a secondary pull request targeting a non-main branch with the same head SHA previously overwrote an active pending google-internal-tests status with a skipped success status. Extend the existing status guard to preserve any active pending status on the head SHA in addition to statuses pointing to internal CL URLs.
  • Fail closed when pull request file list reaches the 3,000-file pagination limit: GitHub's REST API caps pulls.listFiles at 3,000 files. When a pull request returns 3,000 or more files (or fewer files than pull_request.changed_files), emit a warning and set affectsGoogle = true so the action fails closed with a pending status instead of posting "Does not affect Google.".
  • Add unit tests covering google-internal-tests status resolution, overwrite protection, and file list truncation.

…tatus on non-main PRs

Because GitHub commit statuses are scoped to a commit SHA rather than a pull request, opening a secondary pull request targeting a non-main branch with the same head SHA previously overwrote an active pending google-internal-tests status with a skipped success status.

Extend the existing status guard to also preserve any active pending status on the head SHA.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces unit tests for the google-internal-tests GitHub Action by exporting the main function, allowing dependency injection of github and syncConfig, and adding a new Bazel test target. It also implements a fail-closed mechanism when the PR file list reaches the GitHub pagination limit. The reviewer feedback suggests renaming the injected parameters to avoid parameter reassignment and using nullish coalescing to simplify the initialization logic.

Comment thread github-actions/google-internal-tests/lib/main.ts
Comment thread github-actions/google-internal-tests/lib/main.ts Outdated
@josephperrott
josephperrott force-pushed the fix/google-internal-tests-hardening branch from 2896f90 to 5a020b6 Compare October 9, 2026 20:22
…GitHub 3000-file pagination limit

GitHub's REST API caps the pulls.listFiles endpoint at 3,000 files. When a pull request modifies 3,000 or more files (or returns fewer files than pull_request.changed_files), fail closed by emitting a warning and treating the pull request as affecting Google internal tests.
@josephperrott
josephperrott force-pushed the fix/google-internal-tests-hardening branch from 5a020b6 to 2f17723 Compare October 9, 2026 20:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant