From bd3cde080018f80e9ae03d39d3931df44086a640 Mon Sep 17 00:00:00 2001 From: Matthew Watkins Date: Tue, 29 Sep 2026 11:33:02 +0100 Subject: [PATCH 1/4] CI(pre-commit): Let prettier skip ignored files .prettierignore excludes Markdown, so a commit touching only Markdown passes prettier nothing but ignored files. Prettier then reports "No files matching the given patterns were found" and exits 1, blocking documentation-only commits. Pass --no-error-on-unmatched-pattern so that case succeeds; other files are still checked as before. Co-authored-by: Claude Signed-off-by: Matthew Watkins --- .pre-commit-config.yaml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index c3612d8..e0f0669 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -61,6 +61,9 @@ repos: rev: f12edd9c7be1c20cfa42420fd0e6df71e42b51ea # frozen: v4.0.0-alpha.8 hooks: - id: prettier + # .prettierignore excludes Markdown; without this flag a + # Markdown-only commit leaves prettier no files and it fails. + args: [--no-error-on-unmatched-pattern] stages: [pre-commit] - repo: https://github.com/adrienverge/yamllint.git From ed2f0d7c24ee94a90e1c27c19ac6a32ebaf2fc99 Mon Sep 17 00:00:00 2001 From: Matthew Watkins Date: Tue, 29 Sep 2026 11:33:10 +0100 Subject: [PATCH 2/4] Docs: Deprecate in favour of github2gerrit-action This action is superseded by lfreleng-actions/github2gerrit-action and the repository is to be archived. Add a deprecation notice at the top of the README pointing to the replacement, with migration notes: the input, secret and variable names carry over, but the new action's AUTOMATION_ONLY input defaults to true and closes human-authored pull requests unless set to false. Correct the credential guidance before archiving, since the README will remain readable afterwards: - GERRIT_SSH_PRIVKEY_G2G said the *private* key is added to the Gerrit user's account settings. It is the public key that Gerrit holds; following the old text would disclose the private key. - All values, including the private key, were to be stored as organization or repository variables. The key must be a secret; variables are not masked in logs. - The prerequisites linked to the guide for registering a personal key and asked for a GitHub account that submits to Gerrit. Describe the Gerrit service account instead, and how an administrator registers its public key (REST API or gerrit set-account), since the web UI only manages the signed-in user's own keys. - REVIEWER_EMAIL is corrected to REVIEWERS_EMAIL, the input name the action and reusable workflow define. Co-authored-by: Claude Signed-off-by: Matthew Watkins --- README.md | 24 ++++++++++++++---------- 1 file changed, 14 insertions(+), 10 deletions(-) diff --git a/README.md b/README.md index 487c8d7..4ba79b2 100644 --- a/README.md +++ b/README.md @@ -5,13 +5,17 @@ # github2gerrit action +> [!WARNING] +> **This action is deprecated and will be archived.** It receives no further updates, including security fixes. Use [`lfreleng-actions/github2gerrit-action`](https://github.com/lfreleng-actions/github2gerrit-action), its maintained replacement. +> +> To migrate, replace `lfit/github2gerrit@main` with the new composite action or its reusable workflow (`lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml`), pinned to a release commit SHA. The inputs, secret and variables described below keep their names. One behavior differs: the new action's `AUTOMATION_ONLY` input defaults to `true`, which closes pull requests not raised by automation tools such as Dependabot; set it to `false` to keep accepting human-authored pull requests. See the [new action's README](https://github.com/lfreleng-actions/github2gerrit-action#readme) for setup details. + The action extracts the commits from a GitHub pull-request and submits them to an upstream Gerrit repository. This allows GitHub developers to contribute to Gerrit-based repositories that are primarily maintained on Gerrit servers and replicated onto GitHub. ## Pre-requisites -1. GitHub replication is set up on the Gerrit repository over SSH. Refer to the [Gerrit replication configuration setup guide](https://docs.releng.linuxfoundation.org/en/latest/infra/gerrit.html) maintained by the Linux Foundation release engineering team. This also requires creating ssh-keypair - and [registering the SSH keys](https://docs.releng.linuxfoundation.org/en/latest/gerrit.html#register-key-gerrit) with Gerrit. -2. Create a user account on GitHub with permissions to submit changes to Gerrit and ensure it is added to the GitHub organization or repository as a member. +1. GitHub replication is set up on the Gerrit repository over SSH. Refer to the [Gerrit replication configuration setup guide](https://docs.releng.linuxfoundation.org/en/latest/infra/gerrit.html) maintained by the Linux Foundation release engineering team. +2. A dedicated Gerrit service account for the automation (for example `.gh2gerrit`), with permission to push to `refs/for/*` on the target projects, and an SSH key pair for it without a passphrase (`ssh-keygen -t ed25519 -N '' -f gh2gerrit_key`). A Gerrit administrator registers the **public** key (`gh2gerrit_key.pub`) on the account. The Gerrit web UI only manages the signed-in user's own keys, so use the REST API (`POST /a/accounts//sshkeys`) or `ssh -p 29418 @ gerrit set-account --add-ssh-key - < gh2gerrit_key.pub`. The **private** key goes only into the `GERRIT_SSH_PRIVKEY_G2G` GitHub secret (see below); never paste it into Gerrit. 3. Use a [.gitreview](https://docs.opendev.org/opendev/git-review/latest/installation.html#gitreview-file-format) file point to the Gerrit server and repository. If this not alternatively pass the GERRIT_SERVER or GERRIT_PROJECT as inputs to the workflow. ## How the Action Works @@ -60,14 +64,14 @@ Or, submit each commit as a separate single commit preserving the git history (S - `inputs.SUBMIT_SINGLE_COMMITS` has not be tested extensively for handling large pull requests. - Code review comments on Gerrit are not synchronized back to the pull request comment, therefore requires developers to follow up on the Gerrit change request URL. Rework through the recommended changes can be done by reopening the pull request and updating to the commits through a force push. -## Required Inputs or Variables +## Required Inputs, Secrets and Variables -Set the following under Organization or repository variables. +Store the private key as an organization or repository **secret**, and the other values as organization or repository **variables**. Never store the private key in a variable: variables are not masked in logs. -- `GERRIT_KNOWN_HOSTS`: Known host of the Gerrit repository. -- `GERRIT_SSH_PRIVKEY_G2G`: SSH private key pair (The private key has to be added to the Gerrit user's account settings. Gerrit -> User Settings). -- `GERRIT_SSH_USER_G2G`: Gerrit server username (Required to connect to Gerrit). -- `GERRIT_SSH_USER_G2G_EMAIL`: Email of the Gerrit user. +- `GERRIT_KNOWN_HOSTS` (variable): Known host entries of the Gerrit server, for example from `ssh-keyscan -p 29418 `. Check the fingerprints against a trusted source before saving them. +- `GERRIT_SSH_PRIVKEY_G2G` (secret): SSH private key of the Gerrit service account. Only its matching **public** key is registered in Gerrit (see Pre-requisites). +- `GERRIT_SSH_USER_G2G` (variable): Gerrit service account username (Required to connect to Gerrit). +- `GERRIT_SSH_USER_G2G_EMAIL` (variable): Email of the Gerrit service account. ## Optional Variables @@ -82,7 +86,7 @@ Set the following under Organization or repository variables. - `GERRIT_SERVER`: Gerrit server FQDN (Default read from .gitreview). - `GERRIT_SERVER_PORT`: Gerrit server port (Default: 29418) - `ORGANIZATION`: The GitHub Organization or Project. -- `REVIEWER_EMAIL`: Committers' email list (comma-separated list without spaces). +- `REVIEWERS_EMAIL`: Committers' email list (comma-separated list without spaces). ## Full Example Usage with Composite Action From ef43e2ea420df51666256ddb0aaaa1e14eda9e94 Mon Sep 17 00:00:00 2001 From: Matthew Watkins Date: Tue, 29 Sep 2026 11:37:41 +0100 Subject: [PATCH 3/4] Docs: Address Copilot review feedback Copilot: the deprecation notice presented the replacement as a drop-in swap, but a plain "uses:" change silently alters behavior. List every difference, each verified against both action.yaml files: - AUTOMATION_ONLY defaults to true (closes human-authored PRs). - PRESERVE_GITHUB_PRS defaults to true, leaving PRs open after their changes reach Gerrit; this action always closed them. Tell users to set it to false to keep that behavior. - The ISSUEID variable and inject-issue-id-action give way to the ISSUE_ID and ISSUE_ID_LOOKUP_JSON inputs. - The composite action outputs url and change_number become gerrit_change_request_url and gerrit_change_request_num. Co-authored-by: Claude Signed-off-by: Matthew Watkins --- README.md | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 4ba79b2..c4c4de4 100644 --- a/README.md +++ b/README.md @@ -8,7 +8,14 @@ > [!WARNING] > **This action is deprecated and will be archived.** It receives no further updates, including security fixes. Use [`lfreleng-actions/github2gerrit-action`](https://github.com/lfreleng-actions/github2gerrit-action), its maintained replacement. > -> To migrate, replace `lfit/github2gerrit@main` with the new composite action or its reusable workflow (`lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml`), pinned to a release commit SHA. The inputs, secret and variables described below keep their names. One behavior differs: the new action's `AUTOMATION_ONLY` input defaults to `true`, which closes pull requests not raised by automation tools such as Dependabot; set it to `false` to keep accepting human-authored pull requests. See the [new action's README](https://github.com/lfreleng-actions/github2gerrit-action#readme) for setup details. +> To migrate, replace `lfit/github2gerrit@main` with the new composite action or its reusable workflow (`lfreleng-actions/github2gerrit-action/.github/workflows/github2gerrit.yaml`), pinned to a release commit SHA. The inputs documented below, the `GERRIT_SSH_PRIVKEY_G2G` secret and the `GERRIT_*` variables keep their names, but the new action is not a drop-in replacement: +> +> - `AUTOMATION_ONLY` defaults to `true`, which closes pull requests not raised by automation tools such as Dependabot. Set it to `false` to keep accepting human-authored pull requests. +> - `PRESERVE_GITHUB_PRS` defaults to `true`, which leaves pull requests open after their changes reach Gerrit. Set it to `false` to keep closing them, as this action does. +> - The `ISSUEID` variable and `inject-issue-id-action` give way to the `ISSUE_ID` and `ISSUE_ID_LOOKUP_JSON` inputs. +> - The composite action's `url` and `change_number` outputs become `gerrit_change_request_url` and `gerrit_change_request_num`. +> +> See the [new action's README](https://github.com/lfreleng-actions/github2gerrit-action#readme) for setup details. The action extracts the commits from a GitHub pull-request and submits them to an upstream Gerrit repository. This allows GitHub developers to contribute to Gerrit-based repositories that are primarily maintained on Gerrit servers and replicated onto GitHub. From 13a0faa2d35d28635ce9136d422e761858560185 Mon Sep 17 00:00:00 2001 From: Matthew Watkins Date: Tue, 29 Sep 2026 11:47:43 +0100 Subject: [PATCH 4/4] CI: Replace constant if conditions in examples The example caller workflows were disabled with a literal "if: false". actionlint v1.7.11 adds the if-cond rule, which rejects constant conditions, so pre-commit.ci has failed on main and on every pull request since the #57 autoupdate. Gate each job on the G2G_RUN_EXAMPLE_WORKFLOWS repository variable instead. The jobs stay skipped unless the variable is set to 'true', and the opt-in is explicit rather than "remove this line to enable". Co-authored-by: Claude Signed-off-by: Matthew Watkins --- .github/workflows/call-g2g-composite-action.yaml | 3 ++- .github/workflows/call-g2g-reusable-workflow.yaml | 3 ++- .github/workflows/example-v2-usage.yaml | 4 +++- 3 files changed, 7 insertions(+), 3 deletions(-) diff --git a/.github/workflows/call-g2g-composite-action.yaml b/.github/workflows/call-g2g-composite-action.yaml index e210b33..d17c80a 100644 --- a/.github/workflows/call-g2g-composite-action.yaml +++ b/.github/workflows/call-g2g-composite-action.yaml @@ -15,7 +15,8 @@ on: jobs: call-in-g2g-workflow: - if: false + # Example caller: skipped unless the repository opts in + if: vars.G2G_RUN_EXAMPLE_WORKFLOWS == 'true' permissions: contents: read pull-requests: write diff --git a/.github/workflows/call-g2g-reusable-workflow.yaml b/.github/workflows/call-g2g-reusable-workflow.yaml index f9a0508..cbcd422 100644 --- a/.github/workflows/call-g2g-reusable-workflow.yaml +++ b/.github/workflows/call-g2g-reusable-workflow.yaml @@ -21,7 +21,8 @@ concurrency: jobs: call-in-g2g-workflow: - if: false + # Example caller: skipped unless the repository opts in + if: vars.G2G_RUN_EXAMPLE_WORKFLOWS == 'true' permissions: contents: read pull-requests: write diff --git a/.github/workflows/example-v2-usage.yaml b/.github/workflows/example-v2-usage.yaml index 9d6af3a..6b5c6a9 100644 --- a/.github/workflows/example-v2-usage.yaml +++ b/.github/workflows/example-v2-usage.yaml @@ -24,7 +24,9 @@ concurrency: jobs: submit-to-gerrit: name: "Submit PR to Gerrit (V2)" - if: false # Disabled by default - remove this line to enable + # Disabled by default; set the G2G_RUN_EXAMPLE_WORKFLOWS repository + # variable to 'true' to enable + if: vars.G2G_RUN_EXAMPLE_WORKFLOWS == 'true' permissions: contents: read pull-requests: write