From 5ad768d3f6d7bef1f95967b9653e46e1776053ba Mon Sep 17 00:00:00 2001 From: mateo-berri <277851410+mateo-berri@users.noreply.github.com> Date: Sat, 5 Sep 2026 01:02:54 -0700 Subject: [PATCH] fix(guard-main-branch): accept a cost map sync branch only when the sync App opened the PR --- .github/workflows/guard-main-branch.yml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/.github/workflows/guard-main-branch.yml b/.github/workflows/guard-main-branch.yml index d7409d96143..47cd2522df4 100644 --- a/.github/workflows/guard-main-branch.yml +++ b/.github/workflows/guard-main-branch.yml @@ -27,7 +27,8 @@ jobs: HEAD_REF: ${{ github.head_ref }} HEAD_REPO: ${{ github.event.pull_request.head.repo.full_name }} BASE_REPO: ${{ github.repository }} - HEAD_AUTHOR_TYPE: ${{ github.event.pull_request.user.type }} + HEAD_AUTHOR: ${{ github.event.pull_request.user.login }} + SYNC_APP_SLUG: ${{ vars.COST_MAP_BOT_APP_SLUG }} run: | echo "PR head repo: $HEAD_REPO" echo "PR head branch: $HEAD_REF" @@ -35,9 +36,9 @@ jobs: echo "::error::PRs to main must originate from the canonical repository ($BASE_REPO), not a fork ($HEAD_REPO). External contributors should open PRs against 'litellm_internal_staging' instead." exit 1 fi - if [ "$HEAD_REF" = "litellm_internal_staging" ] || [[ "$HEAD_REF" == litellm_hotfix_?* ]] || { [[ "$HEAD_REF" == litellm_cost_map_sync_?* ]] && [ "$HEAD_AUTHOR_TYPE" = "Bot" ]; }; then + if [ "$HEAD_REF" = "litellm_internal_staging" ] || [[ "$HEAD_REF" == litellm_hotfix_?* ]] || { [[ "$HEAD_REF" == litellm_cost_map_sync_?* ]] && [ "$HEAD_AUTHOR" = "${SYNC_APP_SLUG}[bot]" ]; }; then echo "Allowed source branch." exit 0 fi - echo "::error::PRs to main must originate from 'litellm_internal_staging', a 'litellm_hotfix_*' branch, or a 'litellm_cost_map_sync_*' branch the sync bot opened. Got: '$HEAD_REF' by a '$HEAD_AUTHOR_TYPE' author. If this is a contribution, retarget the PR against 'litellm_internal_staging' instead." + echo "::error::PRs to main must originate from 'litellm_internal_staging', a 'litellm_hotfix_*' branch, or a 'litellm_cost_map_sync_*' branch opened by the cost map sync app ('${SYNC_APP_SLUG:-}[bot]', from the COST_MAP_BOT_APP_SLUG repository variable). Got: '$HEAD_REF' by '$HEAD_AUTHOR'. If this is a contribution, retarget the PR against 'litellm_internal_staging' instead." exit 1