Skip to content

fix(ng-dev/pr): harden CLA status check, automation target validation, TGP comment freshness, and log symlink guard - #4030

Open
josephperrott wants to merge 4 commits into
angular:mainfrom
josephperrott:fix/pr-merge-validation-hardening
Open

josephperrott wants to merge 4 commits into
angular:mainfrom
josephperrott:fix/pr-merge-validation-hardening

Conversation

@josephperrott

Copy link
Copy Markdown
Member

Summary

Hardens PR merge validation and local CLI logging against edge-case status, label, comment timestamp, and symlink checks:

  1. CLA commit status verification (assertSignedCla & getStatusesForPullRequest):
    • Require type === "status" in assertSignedCla when verifying cla/google.
    • Prefix statusMap keys in getStatusesForPullRequest with check: and status: and add the missing break; statement under case "CheckRun": so a CheckRun cannot overwrite a StatusContext with the same name.
  2. Automation target label bot-author check (assertChangesAllowForTargetLabel):
    • Enforce the automationBots author allowlist for target: automation before the merge: fix commit message early return.
  3. TGP comment freshness check (assertEnforceTested):
    • Include commit committedDate/pushedDate and comment createdAt in GraphQL schemas and verify in pullRequestHasValidTestedComment that TESTED= comments from Googlers were created at or after the latest commit timestamp when timestamps are available.
  4. Dangling symlink detection in .ng-dev.log guard (captureLogOutputForCommand):
    • Use lstatSync(logFilePath, {throwIfNoEntry: false})?.isSymbolicLink() so dangling symlinks are also rejected before opening .ng-dev.log.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request enhances pull request validation by ensuring that TESTED comments are fresh (created after the latest commit), preventing CheckRuns from overwriting failing CLA StatusContexts, and ensuring automation target label checks are not bypassed by commit message fixup labels. It also refactors the logging utility to securely handle symbolic links. The review feedback suggests keeping the comment creation date as a required property to avoid correctness bypasses, and explicitly handling cases where the comment creation date is missing during freshness checks to prevent stale comments from being incorrectly treated as fresh.

Comment thread ng-dev/pr/common/validation/assert-enforce-tested.ts
Comment thread ng-dev/pr/common/fetch-pull-request.ts Outdated
@josephperrott
josephperrott force-pushed the fix/pr-merge-validation-hardening branch from 88b5c9f to 52c2687 Compare October 9, 2026 20:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant