Skip to content

Consolidate and harden PR-comment GitHub Actions workflows - #148

Merged
ewels merged 1 commit into
mainfrom
consolidate-pr-comment-workflows
Jun 22, 2026
Merged

Consolidate and harden PR-comment GitHub Actions workflows#148
ewels merged 1 commit into
mainfrom
consolidate-pr-comment-workflows

Conversation

@ewels

@ewels ewels commented Jun 22, 2026

Copy link
Copy Markdown
Member

Tidies up and hardens the GitHub Actions workflows that post comments on PRs. Ported from nf-core/rnaseq#1872.

Note

This PR is opened against main as GitHub actions only run on the default branch.

What changes

  • Adds a single shared pr-comment.yml workflow as the only one that runs with a write token. It is triggered via workflow_run after a producer workflow completes, downloads a standard pr-comment artifact, and posts the comment.
  • The "producer" workflows — linting, template-version-comment, and branch — now run on pull_request with read-only tokens and just upload a pr-comment artifact (pr_number.txt, header.txt, optional comment.md). They no longer post comments directly.
  • Removes the now-redundant linting_comment.yml.

Why

  • One small, auditable workflow holds the write permission instead of several.
  • Producer jobs no longer run any PR-derived input in a privileged context, and a shell-injection vector when building the comment body is removed.
  • Sticky comment headers keep each comment type independent, so they update in place as before.

No change to the comments contributors actually see (lint results, template-version warning, branch-protection notice all still post, including on fork PRs).

🤖 Generated with Claude Code

Adds a single shared `pr-comment.yml` workflow as the only one that runs
with a write token. It is triggered via `workflow_run` after a producer
workflow completes, downloads a standard `pr-comment` artifact, and posts
the comment.

The producer workflows — `linting`, `template-version-comment`, and
`branch` — now run on `pull_request` with read-only tokens and just upload
a `pr-comment` artifact (`pr_number.txt`, `header.txt`, optional
`comment.md`). They no longer post comments directly.

Removes the now-redundant `linting_comment.yml`.

Ported from nf-core/rnaseq#1872.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Jun 22, 2026

Copy link
Copy Markdown

Warning

Newer version of the nf-core template is available.

Your pipeline is using an old version of the nf-core template: 3.5.2.
Please update your pipeline to the latest version.

For more documentation on how to update your pipeline, please see the nf-core documentation and Synchronisation documentation.

@github-actions

Copy link
Copy Markdown

nf-core pipelines lint overall result: Failed ❌

Posted for pipeline commit f9270da

+| ✅ 194 tests passed       |+
#| ❔   1 tests were ignored |#
!| ❗  27 tests had warnings |!
-| ❌   4 tests failed       |-
Details

❌ Test failures:

  • files_exist - File not found: .github/workflows/linting_comment.yml
  • files_unchanged - .github/PULL_REQUEST_TEMPLATE.md does not match the template
  • files_unchanged - .github/workflows/branch.yml does not match the template
  • files_unchanged - .github/workflows/linting.yml does not match the template

❗ Test warnings:

  • readme - README contains the placeholder zenodo.XXXXXXX. This should be replaced with the zenodo doi (after the first release).
  • pipeline_todos - TODO string in README.md: TODO nf-core:
  • pipeline_todos - TODO string in README.md: Include a figure that guides the user through the major workflow steps. Many nf-core
  • pipeline_todos - TODO string in README.md: Fill in short bullet-pointed list of the default steps in the pipeline 1. Read QC (FastQC)2. Present QC for raw reads (MultiQC)
  • pipeline_todos - TODO string in README.md: Describe the minimum required steps to execute the pipeline, e.g. how to prepare samplesheets.
  • pipeline_todos - TODO string in README.md: update the following command to include all required parameters for a minimal example
  • pipeline_todos - TODO string in README.md: If applicable, make list of people who have also contributed
  • pipeline_todos - TODO string in README.md: Add citation for pipeline after first release. Uncomment lines below and update Zenodo doi and badge at the top of this file.
  • pipeline_todos - TODO string in README.md: Add bibliography of tools and data used in your pipeline
  • pipeline_todos - TODO string in nextflow.config: Specify your pipeline's command line flags
  • pipeline_todos - TODO string in nextflow.config: Optionally, you can add a pipeline-specific nf-core config at https://github.com/nf-core/configs
  • pipeline_todos - TODO string in nextflow.config: Update the field with the details of the contributors to your pipeline. New with Nextflow version 24.10.0
  • pipeline_todos - TODO string in main.nf: Remove this line if you don't need a FASTA file
  • pipeline_todos - TODO string in main.nf: Optionally add in-text citation tools to this list.
  • pipeline_todos - TODO string in main.nf: Optionally add bibliographic entries to this list.
  • pipeline_todos - TODO string in main.nf: Only uncomment below if logic in toolCitationText/toolBibliographyText has been filled!
  • pipeline_todos - TODO string in usage.md: Add documentation about anything specific to running your pipeline. For general topics, please point to (and add to) the main nf-core website.
  • pipeline_todos - TODO string in output.md: Write this documentation describing your workflow's output
  • pipeline_todos - TODO string in methods_description_template.yml: #Update the HTML below to your preferred methods description, e.g. add publication citation for this pipeline
  • pipeline_todos - TODO string in nextflow.config: Specify any additional parameters here
  • pipeline_todos - TODO string in test_full.config: Specify the paths to your full test data ( on nf-core/test-datasets or directly in repositories, e.g. SRA)
  • pipeline_todos - TODO string in test_full.config: Give any required params for the test so that command line flags are not needed
  • pipeline_todos - TODO string in test.config: Specify the paths to your test data on nf-core/test-datasets
  • pipeline_todos - TODO string in test.config: Give any required params for the test so that command line flags are not needed
  • pipeline_todos - TODO string in base.config: Check the defaults for all processes
  • pipeline_todos - TODO string in base.config: Customise requirements for specific processes.
  • pipeline_todos - TODO string in awsfulltest.yml: You can customise AWS full pipeline tests as required

❔ Tests ignored:

  • files_unchanged - File does not exist: .github/workflows/linting_comment.yml

✅ Tests passed:

Run details

  • nf-core/tools version 3.5.2
  • Run at 2026-06-22 10:25:59

@ewels
ewels merged commit 2cbdc96 into main Jun 22, 2026
10 of 13 checks passed
@ewels
ewels deleted the consolidate-pr-comment-workflows branch June 22, 2026 20:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants