From 067fce7f25c2de1de425951f5679799e0c790651 Mon Sep 17 00:00:00 2001 From: Eric Kerfoot <17726042+ericspod@users.noreply.github.com> Date: Thu, 1 Oct 2026 15:00:39 +0100 Subject: [PATCH 1/4] Add update action Signed-off-by: Eric Kerfoot <17726042+ericspod@users.noreply.github.com> --- .github/workflows/pr_autoupdate.yml | 53 +++++++++++++++++++++++++++++ 1 file changed, 53 insertions(+) create mode 100644 .github/workflows/pr_autoupdate.yml diff --git a/.github/workflows/pr_autoupdate.yml b/.github/workflows/pr_autoupdate.yml new file mode 100644 index 00000000000..07df1c62aa7 --- /dev/null +++ b/.github/workflows/pr_autoupdate.yml @@ -0,0 +1,53 @@ + +# This action will keep PRs branches updated which have been approved and have automerge enabled. This is meant to +# automate the integration of PRs which have been reviewed but will be stopped from merging when something else gets +# merged first. Needing to manually update branches whenever this happens slows the review process so this action +# should speed things along, but a PR with failed tests will stop this automation from helping. The key control is that +# reviewers must approve AND enable automerge, a PR that's approved but should wait will be left alone if automerge +# isn't on. This action updates the oldest approved-automerging PR only to avoid wasting compute. + +# IMPORTANT: requires a personal access token (PAT_UPDATE_TOKEN) with contents and pull request read/write access. + +name: Auto-Update PRs + +on: + push: + branches: + - dev + workflow_dispatch: # Allows manual triggering if needed + +permissions: + contents: write + pull-requests: write + +jobs: + update-prs: + runs-on: ubuntu-latest + steps: + - name: Checkout target branch + uses: actions/checkout@v6 + with: + fetch-depth: 0 # Fetches all history so branches can be merged locally + + - name: Update the oldest PR which is approved and automerging-enabled + env: + GH_TOKEN: ${{ secrets.PAT_UPDATE_TOKEN }} # PAT with read/write access to Contents and PullRequests + run: | + # Find all open PRs targeting this branch which are open and approved + PR_DATA=$(gh pr list --state open --search 'review:approved' --base ${{ github.ref_name }} --json number,reviewDecision,autoMergeRequest) + + echo '================================' + echo "PR_DATA:" + echo $PR_DATA + echo '================================' + + # select the oldest open approved PR with automerge enabled + OLDEST_APPROVED=$(echo $PR_DATA | jq -r '.[] | select(.reviewDecision == "APPROVED") | select(.autoMergeRequest != null) | "\(.number)"'|head -n 1) + + if [ -z "$OLDEST_APPROVED" ] + then + echo "No approved PRs to update." + else + echo "Updating PR $OLDEST_APPROVED ..." + gh pr update-branch "$OLDEST_APPROVED" || echo "Failed to update PR #$OLDEST_APPROVED (merge conflicts?)." + fi From 307239c84a725c3443842cb5ab17b52ef5a76d78 Mon Sep 17 00:00:00 2001 From: Eric Kerfoot <17726042+ericspod@users.noreply.github.com> Date: Thu, 1 Oct 2026 15:08:18 +0100 Subject: [PATCH 2/4] " " Signed-off-by: Eric Kerfoot <17726042+ericspod@users.noreply.github.com> --- .github/workflows/pr_autoupdate.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/pr_autoupdate.yml b/.github/workflows/pr_autoupdate.yml index 07df1c62aa7..6094de510a4 100644 --- a/.github/workflows/pr_autoupdate.yml +++ b/.github/workflows/pr_autoupdate.yml @@ -1,10 +1,10 @@ -# This action will keep PRs branches updated which have been approved and have automerge enabled. This is meant to +# This action will keep PRs branches updated which have been approved and have automerge enabled. This is meant to # automate the integration of PRs which have been reviewed but will be stopped from merging when something else gets # merged first. Needing to manually update branches whenever this happens slows the review process so this action # should speed things along, but a PR with failed tests will stop this automation from helping. The key control is that -# reviewers must approve AND enable automerge, a PR that's approved but should wait will be left alone if automerge -# isn't on. This action updates the oldest approved-automerging PR only to avoid wasting compute. +# reviewers must approve AND enable automerge, a PR that's approved but should wait will be left alone if automerge +# isn't on. This action updates the oldest approved-automerging PR only to avoid wasting compute. # IMPORTANT: requires a personal access token (PAT_UPDATE_TOKEN) with contents and pull request read/write access. From d943fe781771324386d87cb9bed7741ba12c28f3 Mon Sep 17 00:00:00 2001 From: Eric Kerfoot <17726042+ericspod@users.noreply.github.com> Date: Thu, 1 Oct 2026 15:25:02 +0100 Subject: [PATCH 3/4] Ordering Signed-off-by: Eric Kerfoot <17726042+ericspod@users.noreply.github.com> --- .github/workflows/pr_autoupdate.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/pr_autoupdate.yml b/.github/workflows/pr_autoupdate.yml index 6094de510a4..52c1bd12d9c 100644 --- a/.github/workflows/pr_autoupdate.yml +++ b/.github/workflows/pr_autoupdate.yml @@ -34,7 +34,7 @@ jobs: GH_TOKEN: ${{ secrets.PAT_UPDATE_TOKEN }} # PAT with read/write access to Contents and PullRequests run: | # Find all open PRs targeting this branch which are open and approved - PR_DATA=$(gh pr list --state open --search 'review:approved' --base ${{ github.ref_name }} --json number,reviewDecision,autoMergeRequest) + PR_DATA=$(gh pr list --state open --search 'review:approved sort:created-asc' --base ${{ github.ref_name }} --json number,reviewDecision,autoMergeRequest) echo '================================' echo "PR_DATA:" From 49fc34dfec96f22ab47e4d7aea02b61524b81f0a Mon Sep 17 00:00:00 2001 From: Eric Kerfoot <17726042+ericspod@users.noreply.github.com> Date: Thu, 1 Oct 2026 15:37:22 +0100 Subject: [PATCH 4/4] CWE-78 mitigation Signed-off-by: Eric Kerfoot <17726042+ericspod@users.noreply.github.com> --- .github/workflows/pr_autoupdate.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/pr_autoupdate.yml b/.github/workflows/pr_autoupdate.yml index 52c1bd12d9c..81f385fd277 100644 --- a/.github/workflows/pr_autoupdate.yml +++ b/.github/workflows/pr_autoupdate.yml @@ -32,9 +32,10 @@ jobs: - name: Update the oldest PR which is approved and automerging-enabled env: GH_TOKEN: ${{ secrets.PAT_UPDATE_TOKEN }} # PAT with read/write access to Contents and PullRequests + BASE_REF: ${{ github.ref_name }} # neutralizes CWE-78 command injection through branch names with shell syntax run: | # Find all open PRs targeting this branch which are open and approved - PR_DATA=$(gh pr list --state open --search 'review:approved sort:created-asc' --base ${{ github.ref_name }} --json number,reviewDecision,autoMergeRequest) + PR_DATA=$(gh pr list --state open --search 'review:approved sort:created-asc' --base $BASE_REF --json number,reviewDecision,autoMergeRequest) echo '================================' echo "PR_DATA:"