Files
market/.github/workflows/auto-request-copilot-review.yml
Yige b8101406fb ci: 引入分支保护配套工作流(path 过滤 → detect-changes,AI review 自动化) (#5)
## Summary / 概要

为了让 `main` 分支保护规则在所有 PR 上稳定生效,调整两个现有 i18n workflow 并新增两个 AI review 配套
workflow。

### 已配置的 main ruleset(ID 16298003)

- 只允许 squash merge,禁止 force push / 删除
- 必需 status check:`validate`、`translate`,require
`strict_required_status_checks_policy=true`(必须 rebase 最新)
- PR
rule:`required_approving_review_count=0`、`required_review_thread_resolution=true`、`dismiss_stale_reviews_on_push=true`
- `bypass_actors=[]`:管理员也不能绕过

### 本 PR 改动

1. **i18n-validate / i18n-translate**:移除 `on.pull_request.paths`,把过滤下移到
job 内 `detect-changes` step。路径不相关时跳过实际逻辑但 job 仍 success,避免 required
check 因 path 过滤缺失而卡死非 i18n PR。
2. **auto-request-copilot-review** (新增):PR
opened/reopened/ready_for_review 时自动 `POST
/pulls/{n}/requested_reviewers` 加 Copilot 为 reviewer。
3. **wait-for-copilot-review** (新增):PR
opened/reopened/synchronize/ready_for_review 时启动,轮询 reviews API 等待
`copilot-pull-request-reviewer[bot]` 在当前 head SHA 提交 review。超时 8 分钟则
fail。
- 选择 polling 而不是 `pull_request_review` 事件触发是因为:Copilot bot 触发的
`pull_request_review` 事件被 GitHub 视为 first-time contributor,workflow run
会卡在 `action_required` 状态需 maintainer 在 web UI 手动批准,无法自动化。

合并后会再 PATCH ruleset 16298003,把 `wait-for-copilot-review` 加入 required
status checks 作为强制门槛。

## Test plan

- [x] `i18n-validate` 在本 PR 上跑出 success(PR 仅触及
`.github/workflows/`,relevant=false,走 skip 分支)
- [x] `i18n-translate` 同上
- [x] `auto-request-copilot-review` 跑出 success,Copilot 被自动加为 reviewer
- [x] `wait-for-copilot-review` 在 polling 窗口内捕获到 Copilot review 并 pass
- [ ] 解决 Copilot 提的 conversations 后能 squash merge
- [ ] 合并后用 PATCH ruleset 把 `wait-for-copilot-review` 加入 required checks
2026-05-13 00:21:51 +08:00

40 lines
1.3 KiB
YAML

name: Auto-request Copilot review
on:
pull_request:
types: [opened, reopened, ready_for_review]
permissions:
pull-requests: write
jobs:
request:
if: github.event.pull_request.draft == false
runs-on: ubuntu-latest
timeout-minutes: 2
steps:
- name: Request Copilot reviewer
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
set -e
if gh api "repos/${{ github.repository }}/pulls/$PR_NUMBER" \
--jq '.requested_reviewers[].login' \
| grep -qE '^(Copilot|copilot-pull-request-reviewer\[bot\])$'; then
echo "Copilot already requested as reviewer."
exit 0
fi
# 422 here usually means Copilot has already submitted a review (so the
# request slot is gone). Treat that as benign.
if ! resp=$(gh api -X POST \
"repos/${{ github.repository }}/pulls/$PR_NUMBER/requested_reviewers" \
-f 'reviewers[]=copilot-pull-request-reviewer[bot]' 2>&1); then
echo "$resp"
if echo "$resp" | grep -q '"status":"422"'; then
echo "POST returned 422; Copilot likely already reviewed."
exit 0
fi
exit 1
fi