Skip to content

feat(chatops): add /command for build test pr in PR - #1355

Merged
perber merged 4 commits into
perber:mainfrom
Hugo-Galley:feat/add-chatops
Sep 25, 2026
Merged

perber merged 4 commits into
perber:mainfrom
Hugo-Galley:feat/add-chatops

Conversation

@Hugo-Galley

@Hugo-Galley Hugo-Galley commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

Related issue

This PR references issue #1280.

What changed

  • Add the ChatOps command /create-test-image.
  • I wasn't sure where to document this, so I added the documentation to the PR template instead.

Checklist

  • I discussed the approach on the linked issue before starting (or this is a trivial fix: typo, docs, obvious one-liner)
  • This PR is focused on a single change
  • I ran npm run format in ui/leafwiki-ui (and in e2e if e2e tests changed)
  • I updated the documentation if needed

@Hugo-Galley
Hugo-Galley requested a review from perber as a code owner July 31, 2026 12:43
@perber

perber commented Jul 31, 2026

Copy link
Copy Markdown
Owner

@Hugo-Galley Thanks for the PR. I will take a look soon. Hopefully this is fine for you.

@perber

perber commented Jul 31, 2026

Copy link
Copy Markdown
Owner

I fixed the trivy issue already in a different PR. So it looks good so far.

@perber

perber commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Hi @Hugo-Galley could you rebase?

@Hugo-Galley

Copy link
Copy Markdown
Contributor Author

Hi @perber,

Sorry, I’m currently on vacation and don’t have access to my PC. I won’t be able to work on this until early September.

I wanted to open the PR before leaving so it was already available for review. I’ll rebase it and address any feedback once I’m back in September.

Thanks for your patience!

@perber

perber commented Aug 6, 2026

Copy link
Copy Markdown
Owner

Hi @Hugo-Galley,

Enjoy your vacation.

@perber

perber commented Sep 6, 2026

Copy link
Copy Markdown
Owner

Hi @Hugo-Galley,

I think we should built it only when a 'maintainer' is using this command.

@Hugo-Galley

Copy link
Copy Markdown
Contributor Author

Hi @perber, what do you think about using “maintainer” here?

Do you mean only repository owners, or also regular contributors and approving contributors? I’m not sure which ones you’re referring to.

@perber

perber commented Sep 19, 2026

Copy link
Copy Markdown
Owner

Hi @Hugo-Galley,
Again, sorry for the late response. I would restrict it to repository owners. I know that I can add contributors with higher permissions to the project, but not sure how to distinguish them.

@Hugo-Galley

Copy link
Copy Markdown
Contributor Author

@perber No worries at all, took me a while to reply as well ;). Sounds good to me. I'll restrict creation to the owner only. Nothing is set in stone anyway, we can always add it back later if we change our minds :)

@Hugo-Galley

Copy link
Copy Markdown
Contributor Author

@perber i push fix. It's ok for you ?

Removed instructions for building a test image from the PR template.
…ing PR-controlled Makefile

- /create-test-image no longer tags :latest on ghcr.io — it inlines the
  docker buildx build/push command instead of calling `make
  docker-build-publish`, so the PR's own Makefile is never executed on
  the runner with a packages:write token (pwn-request pattern: the
  checked-out PR code could otherwise redefine that Make target to
  exfiltrate the token that docker/login-action already wrote to disk).
- Broaden the trigger gate from author_association == 'OWNER' to also
  allow COLLABORATOR, matching "owner or someone with write access to
  the project" rather than literally only the single OWNER association.
- Add trailing newlines to both new workflow files.
…rite token

pull_request (non-target) events from a fork PR get a read-only
GITHUB_TOKEN regardless of the permissions: block, unless the repo has
opted in to write tokens for fork PRs (off by default). Since this job
never checks out or executes PR code — it only reads the PR number
from the trusted event payload to delete matching ghcr.io package
versions — pull_request_target is the safe way to get a write token
here without the checkout-and-run risk that pattern normally carries.
@perber
perber merged commit 6d71995 into perber:main Sep 25, 2026
10 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants