Fix welcome action input contract and pin v3 - #2
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The welcome workflow failed before using the GitHub API because first-interaction v3 expects
repo_token,issue_messageandpr_message, while the workflow supplied hyphenated names. Correct the three inputs and pin the unchanged v3 action to independently verified commit1c4688942c71f71d4f5502a26ea67c331730fa4d.The metadata test now requires an immutable action reference and the three valid input names, replacing its obsolete expectation of a mutable
@v3tag.Validation: 31 metadata/security/license tests passed locally; actionlint, Ruff and diff checks passed. The byte-identical official Node 24 bundle was executed with isolated dummy credentials and an offline transport: both original Issue/PR cases failed on the missing input before any request, while both corrected cases exited 0 and produced the exact expected message body in the local stub. Independent review repeated those probes, confirmed the official action metadata/tag/bundle, and found no P1/P2.
Final candidate
e5af8efe52375d036f8adb07ce580379c69af9db: source CI 36871819469 passed all six Windows/Linux/macOS × Python 3.11/3.12 jobs, including metadata tests. Independent mutations confirmed that a mutable tag and old hyphenated input names fail the new assertions. Merged asdcd9df6f170a68b6f65f51779d96ecf2e86b261d; candidate and merge have the identical tree59a34fb1f06baf0476c849d7d7a1dd6790210de0. Canonical main is clean and synchronized.No real greeting comment was sent and the Welcome workflow was not rerun. Opening this PR runs the existing base-branch welcome configuration; it does not validate the candidate. Real GitHub posting permissions and delivery remain unverified. No application code, event triggers, permissions, message text, versions, binary or Store changes.