fix: check out privileged test commits from base repo pull refs - #487
Merged
Conversation
✅ Deploy Preview for lando-core ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What does this do?
Fixes the privileged Leia test dispatch failing with
Version 6209 must be semver valid!(https://github.com/lando/core/actions/runs/31334820529).The job checked out the fork repository directly, but forks don't carry upstream tags, so
prepare-release-actionhad nov*tag to derive a dev version from and choked on the raw commit SHA.Now the job checks out the base repository (tags present) and fetches the reviewed commit via
pull/N/head, which lives in the base repo. This also removes the head-repo API lookup and keeps working if the fork is deleted. The security property is unchanged: the job still checks out the exact maintainer-reviewed SHA, validated against the current PR head.Testing
git fetch origin pull/474/head, checkout of the fork head SHA, unshallow,git describeresolvesv3.26.7