From 9478a32d22096576af869b6572bc18169670044c Mon Sep 17 00:00:00 2001 From: mateo-berri <277851410+mateo-berri@users.noreply.github.com> Date: Fri, 4 Sep 2026 23:13:18 -0700 Subject: [PATCH] fix(cost-map-sync): reconcile only sync PRs the App opened from this repo The reconciler picked the open sync PR by title and branch prefix alone, so a fork PR carrying the same title and a litellm_cost_map_sync_ branch could pass the guard with its own repricing and be merged with the App token. It now lists PRs authored by the App (--author app/) and drops cross-repository heads, and without the App it never selects a PR, which also removes the unreachable no-App warning branch. --- .github/workflows/cost-map-sync.yml | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/.github/workflows/cost-map-sync.yml b/.github/workflows/cost-map-sync.yml index 005e93b786c..8e7bf3f9699 100644 --- a/.github/workflows/cost-map-sync.yml +++ b/.github/workflows/cost-map-sync.yml @@ -42,14 +42,15 @@ jobs: - name: Reconcile the open sync PR id: open run: | - pr="$(gh pr list --repo "$GITHUB_REPOSITORY" --state open --limit 100 --json number,headRefName,mergeable \ - --search "in:title \"$PR_TITLE\"" \ - --jq "[.[] | select(.headRefName | startswith(\"$BRANCH_PREFIX\"))] | first // empty")" + pr="" + if [ -n "$BOT_LOGIN" ]; then + pr="$(gh pr list --repo "$GITHUB_REPOSITORY" --state open --limit 100 --author "app/$BOT_LOGIN" \ + --search "in:title \"$PR_TITLE\"" --json number,headRefName,mergeable,isCrossRepository \ + --jq "[.[] | select((.headRefName | startswith(\"$BRANCH_PREFIX\")) and (.isCrossRepository | not))] | first // empty")" + fi sync=false if [ -z "$pr" ]; then sync=true - elif [ -z "$BOT_APP_ID" ]; then - echo "::warning::Sync PR #$(jq -r .number <<< "$pr") is open and COST_MAP_BOT_APP_ID is not configured; leaving it to a human." elif [ "$(jq -r .mergeable <<< "$pr")" = "CONFLICTING" ]; then number="$(jq -r .number <<< "$pr")" gh pr close "$number" --repo "$GITHUB_REPOSITORY" --delete-branch \ @@ -78,6 +79,7 @@ jobs: echo "sync=$sync" >> "$GITHUB_OUTPUT" env: GH_TOKEN: ${{ steps.bot.outputs.token || github.token }} + BOT_LOGIN: ${{ steps.bot.outputs.app-slug }} - name: Explain why no PR can be opened if: steps.open.outputs.sync == 'true' && env.BOT_APP_ID == '' && !inputs.dry_run run: echo "::warning::COST_MAP_BOT_APP_ID is not configured, so no sync PR can be opened or merged; dispatch with dry_run to see the diff."