Repository navigation
chore(deps): update pr-size-labeler to 1.11.1 - #4267
Draft
Ricky Gummadi (Ricky-G) wants to merge 1 commit into
Draft
Ricky Gummadi (Ricky-G) wants to merge 1 commit into
Ricky Gummadi (Ricky-G) wants to merge 1 commit into
Conversation
Preserve the verified SHA update proposed by Dependabot in #4235. Add a workflow-local cspell directive for the actual upstream owner so the changed-lines spelling check can accept the action reference without a shared dictionary exemption. Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related Issue
Replacement for #4235. Credits Dependabot for the original dependency update. After the replacement's real hosted spelling and workflow gates passed, the coordinator explicitly authorized closing #4235 as superseded; the thank-you and replacement comment was posted and closure verified. The original head and retained Dependabot branch remain at
9c86e877e08c82be43a8de0ac13bd833b7f49129; nothing was merged and future dependency updates were not disabled.Summary
Update
codelytv/pr-size-labelerfrom v1.10.4 to the verified, full-SHA-pinned v1.11.1 release and recognize only the actual upstream owner name in this workflow's spelling input. This independent, human-owned replacement targetsmainand remains a draft pending remaining hosted checks and human review; the actual hosted spelling and relevant workflow gates have passed.Problem & Solution
Problem: #4235 was blocked by
Spell-check changed files, not an action build failure. Run 37443915463 reportsci-diff/spell-check-added-lines.txt:1:15 - Unknown word (codelytv)and exits 1.Solution: Preserve Dependabot's exact action SHA update and pristine
# v1.11.1annotation. Add an adjacent# cspell:ignore codelytvdirective that is included in the actual extracted added-lines input. No shared dictionary, ignored path, disabled check, workflow architecture, permission, event, or input change.The official v1.11.1 release, published
2026-09-28T22:47:19Z, is more than seven days old at verification on 2026-10-09. GitHub's tag API resolves it directly to commit4e3aa0f77f348c8066513d453515316ffa01a607; the commit API reports its signature asverified: true,reason: valid. The previous v1.10.4 tag resolves to the existing pin095a41fca88b8764fd9e008ad269bcdb82bb38b9.Inspected the upstream action inputs, Docker entry point, event-number parsing, and runtime changes between these exact commits. v1.11.1 adds the size label and removes only stale configured size labels instead of replacing all labels, preserving labels added by other automation. Intermediate releases improve API permission errors, file pagination, and XL comments. Our existing static inputs remain supported. The workflow keeps
pull_request_target, no checkout or inline shell, top-levelcontents: read, and job-scopedpull-requests: write.Impact on Your Work
Unblocks the verified labeler dependency update without weakening spelling or security checks and prevents the newer upstream action from overwriting labels managed by other automation. No published package or SDK changes.
Timeline
None. Maintainer review and approval are required before any merge. Coordinator-authorized supersession of #4235 occurred only after the replacement's scoped hosted gates passed; closing the original does not authorize merging this replacement.
Alternatives Considered
Changing a shared spelling dictionary or disabling a check would expand scope unnecessarily. Leaving the dependency unchanged would discard the requested update. A local single-token directive preserves the real upstream owner and the clean version annotation without editing shared automation or the original PR branch.
Changes
.github/workflows/pr-size.yml4e3aa0f77f348c8066513d453515316ffa01a607and add only the workflow-localcodelytvspelling directive.The action update is semantically identical to #4235; the only additional change is the spelling comment. The branch starts independently from
mainat17595e649abdfa703962c2f8c241826f68318109. Complete paginated original comments, reviews, review comments, timeline, and review threads were read, including resolved-thread coverage: 3 bot comments, 0 reviews, 0 review comments, 0 threads, and 12 timeline events before publication. Before authorized closure, these were refreshed: no substantive discussion or head/diff changes, and the only new timeline event was this replacement's cross-reference. No existing superseded comment was present. Searches by action title and4235in open PR bodies found no existing replacement before publication.Type of Change
Package(s) Affected
Core & runtime:
Governance & security:
Platform & tooling:
CLI plugins:
Shared / other:
Testing
Local workflow syntax/security/scope checks and 14 targeted tests passed. Local cspell remains unavailable, but actual hosted cspell 8.17.3 validation passed on head
6b39e1451d64f6131f242703aebedac38ac75b59. Spell Check run 37856956230 successfully executedCompute changed lines,Install cspell, andcspell on changed lines; the spelling step was not skipped. This verifies the original failure is resolved in the real extracted-diff path, not just a full-file scan.Workflow-lint run 37856956320 passed actionlint, shellcheck, and all 109 inline-script tests. The CI workflow-security job also passed. Remaining broader CI and maintainer review are not represented as complete. Latest readiness snapshot: 80 passing checks, 19 skipped, 2 pending (
test-policiesandPython E2E (Ollama)), no failed checks; the branch is mergeable, draft, and awaiting required review. Non-merging Agent merge is enabled for fixes/conflicts/reviews with merging disabled.Unit Testing
No repository tests added or changed for this dependency-and-comment-only update.
python -m pytest tests\ci\test_changed_lines.py tests\ci\test_extract_workflow_shell.py -qpassed locally: 14 tests. These existing tests cover added-line extraction/scoping and workflow shell extraction. Hostedpytest tests/ci/ -vpassed: 109 tests in workflow-lint.The upstream Tests run 36494359744 completed successfully on the exact pinned commit, including its
Testsstep. This is upstream evidence, not a claim that its Docker action was executed locally. Becausepull_request_targetruns the base workflow, this replacement's PR-size job will not exercise the changed action before merge.Manual Testing
Windows/PowerShell validation;
$ain the exact commands below denotes this session's artifacts directory, which holds isolated validation tools/scripts and is not committed:& "$a\actionlint-1.7.12\actionlint.exe" -color '.github\workflows\pr-size.yml'6e7241b51e6817ea6a047693d8e6fed13b31819c9a0dd6c5a726e1592d22f6e9.python "$a\validate_pr_size.py"ci.ymlAudit pull_request_target workflowsscript under Git Bash: all applicable workflows passed. The validation helper is a session artifact, not a repository change.python -m pytest tests\ci\test_changed_lines.py tests\ci\test_extract_workflow_shell.py -qpython scripts\ci\changed_lines.py --base origin/main --extensions '.md,.txt,.rst,.py,.ts,.js,.go,.rs,.cs,.yml,.yaml' --mode added-lines --output "$a\spell-check-added-lines.txt"git --no-pager diff --checkcspell --versioncspell "ci-diff/spell-check-added-lines.txt" --config .cspell.json --no-progress --no-summaryactionlint -color -ignore 'unknown permission scope "models"' -ignore 'undefined variable "pattern"' -ignore 'SC2016' -ignore 'SC2001' -ignore 'SC2129' -ignore 'SC2193'shellcheck -s bash workflow-shell-extracted.shpytest tests/ci/ -vThe CI-pinned
cspell@8.17.3release dates to2025-01-28T12:07:33Z. Isolated local installation failed under the corporate feed's remote-package restriction (EALLOWREMOTE); an official-registry attempt failed TLS negotiation, and preserving the configured proxy while normalizing tarball hosts exposed a feed-path 404. No TLS or package-security control was relaxed, no repository dependency/configuration was modified, and no verified sibling executable was available. The established hostedSpell-check changed filesjob has now supplied the real successful result.Live rendered body and diff were verified: all 14 template headings, 19 HTML comments, and 47 checklist items are preserved in order; the published workflow bytes match the local committed file exactly. Repository-wide builds, unrelated package suites, and local Docker-action execution were not run locally; they are not justified by this one-workflow pin/comment change. Broader hosted checks and maintainer approval remain pending.
Checklist
Attribution & Prior Art
Prior art / related projects (if any):
Dependabot's #4235 supplied the exact dependency update. CodelyTV/pr-size-labeler supplies the action; the relevant release behavior is described in CodelyTV/pr-size-labeler#110. This PR introduces no new integration or borrowed implementation. The commit includes repository-required Microsoft attribution and a DCO signoff.
AI Assistance
If AI tools materially shaped this change, briefly note what was used:
GitHub Copilot performed the user-authorized investigation, narrow workflow edit, validation, commit, and draft PR submission under explicit human direction. Human review of this specific output and the CLA/AI attestations have not been verified; the corresponding boxes remain unchecked. Maintainer approval is required before any merge. The single superseded comment and closure on the original PR were explicitly authorized by the coordinator only after scoped hosted verification and a fresh discussion/head/equivalence preflight.
IP, Patents, and Licensing