From ac726caa5c466d04c61f2f3da18ffd6e1652bea8 Mon Sep 17 00:00:00 2001 From: Gergo Magyar Date: Tue, 9 Jun 2026 12:58:52 +0000 Subject: [PATCH] fix(ci): event-gate the aggregate open-PR condition explicitly MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `inputs.open_pr` is null on pull_request events, and the prior `inputs.open_pr != false` leg relied on GHA's direction-ambiguous null coercion (Codex F4) to decide whether to open the prebuild PR. Gate explicitly on the event: a non-fork pull_request that bumped a grammar version opens the prebuild PR (the documented flow), and `open_pr` is only consulted on workflow_dispatch — so a manual run with open_pr=false stays artifacts-only and no event's behavior rests on coercion. --- .github/workflows/build-tree-sitter-prebuilds.yml | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build-tree-sitter-prebuilds.yml b/.github/workflows/build-tree-sitter-prebuilds.yml index c84ef027b..91fc5d884 100644 --- a/.github/workflows/build-tree-sitter-prebuilds.yml +++ b/.github/workflows/build-tree-sitter-prebuilds.yml @@ -386,11 +386,17 @@ jobs: aggregate: name: Vendor prebuilds + open PR needs: [guard, build] + # Open the prebuild PR on a non-fork pull_request that bumped a grammar + # version (the documented version-change -> prebuild-PR flow), or on a manual + # dispatch with open_pr=true. Event-gating is explicit so we never rely on + # GHA coercing a null `inputs.open_pr` on pull_request events (Codex F4): + # `inputs.open_pr` is null off-dispatch, and `null != false` is direction- + # ambiguous, so `open_pr` is only consulted on workflow_dispatch. if: >- needs.guard.outputs.any == 'true' && needs.guard.outputs.release_app == 'true' && - inputs.open_pr != false && - github.event.pull_request.head.repo.fork != true + github.event.pull_request.head.repo.fork != true && + (github.event_name == 'pull_request' || inputs.open_pr == true) runs-on: ubuntu-24.04 timeout-minutes: 15 permissions: