Skip to content

chore(deps): update pr-size-labeler to 1.11.1 - #4267

Draft
Ricky Gummadi (Ricky-G) wants to merge 1 commit into
mainfrom
ricky-g-pr-size-labeler-update
Draft

Ricky Gummadi (Ricky-G) wants to merge 1 commit into
mainfrom
ricky-g-pr-size-labeler-update

Conversation

@Ricky-G

@Ricky-G Ricky Gummadi (Ricky-G) commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Related Issue

Replacement for #4235. Credits Dependabot for the original dependency update. After the replacement's real hosted spelling and workflow gates passed, the coordinator explicitly authorized closing #4235 as superseded; the thank-you and replacement comment was posted and closure verified. The original head and retained Dependabot branch remain at 9c86e877e08c82be43a8de0ac13bd833b7f49129; nothing was merged and future dependency updates were not disabled.

If no related issue is linked above, you must complete "Problem & Solution", "Impact on Your Work", and "Alternatives Considered" below.

Summary

Update codelytv/pr-size-labeler from v1.10.4 to the verified, full-SHA-pinned v1.11.1 release and recognize only the actual upstream owner name in this workflow's spelling input. This independent, human-owned replacement targets main and remains a draft pending remaining hosted checks and human review; the actual hosted spelling and relevant workflow gates have passed.

Problem & Solution

Problem: #4235 was blocked by Spell-check changed files, not an action build failure. Run 37443915463 reports ci-diff/spell-check-added-lines.txt:1:15 - Unknown word (codelytv) and exits 1.

Solution: Preserve Dependabot's exact action SHA update and pristine # v1.11.1 annotation. Add an adjacent # cspell:ignore codelytv directive that is included in the actual extracted added-lines input. No shared dictionary, ignored path, disabled check, workflow architecture, permission, event, or input change.

The official v1.11.1 release, published 2026-09-28T22:47:19Z, is more than seven days old at verification on 2026-10-09. GitHub's tag API resolves it directly to commit 4e3aa0f77f348c8066513d453515316ffa01a607; the commit API reports its signature as verified: true, reason: valid. The previous v1.10.4 tag resolves to the existing pin 095a41fca88b8764fd9e008ad269bcdb82bb38b9.

Inspected the upstream action inputs, Docker entry point, event-number parsing, and runtime changes between these exact commits. v1.11.1 adds the size label and removes only stale configured size labels instead of replacing all labels, preserving labels added by other automation. Intermediate releases improve API permission errors, file pagination, and XL comments. Our existing static inputs remain supported. The workflow keeps pull_request_target, no checkout or inline shell, top-level contents: read, and job-scoped pull-requests: write.

Impact on Your Work

Unblocks the verified labeler dependency update without weakening spelling or security checks and prevents the newer upstream action from overwriting labels managed by other automation. No published package or SDK changes.

Timeline

None. Maintainer review and approval are required before any merge. Coordinator-authorized supersession of #4235 occurred only after the replacement's scoped hosted gates passed; closing the original does not authorize merging this replacement.

Alternatives Considered

Changing a shared spelling dictionary or disabling a check would expand scope unnecessarily. Leaving the dependency unchanged would discard the requested update. A local single-token directive preserves the real upstream owner and the clean version annotation without editing shared automation or the original PR branch.

Changes

File What changed
.github/workflows/pr-size.yml Pin v1.11.1 to 4e3aa0f77f348c8066513d453515316ffa01a607 and add only the workflow-local codelytv spelling directive.

The action update is semantically identical to #4235; the only additional change is the spelling comment. The branch starts independently from main at 17595e649abdfa703962c2f8c241826f68318109. Complete paginated original comments, reviews, review comments, timeline, and review threads were read, including resolved-thread coverage: 3 bot comments, 0 reviews, 0 review comments, 0 threads, and 12 timeline events before publication. Before authorized closure, these were refreshed: no substantive discussion or head/diff changes, and the only new timeline event was this replacement's cross-reference. No existing superseded comment was present. Searches by action title and 4235 in open PR bodies found no existing replacement before publication.

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update
  • Maintenance (dependency updates, CI/CD, refactoring)
  • Security fix

Package(s) Affected

Core & runtime:

  • agent-governance-toolkit-core
  • agent-primitives
  • agent-os
  • agent-mesh
  • agent-runtime
  • agent-sre
  • agent-compliance

Governance & security:

  • agent-mcp-governance
  • agent-rag-governance
  • agent-sandbox
  • agent-discovery
  • agt-policies
  • policy-engine

Platform & tooling:

  • agent-hypervisor
  • agent-lightning
  • agent-marketplace
  • agent-governance-toolkit-cli
  • agent-governance-toolkit-integrations
  • agent-governance-toolkit-protocols
  • agentmesh-integrations (framework integrations)

CLI plugins:

  • agent-governance CLI plugins (copilot-cli / claude-code / opencode / antigravity-cli)

Shared / other:

  • schemas
  • action (GitHub Action)
  • examples
  • docs / root

Testing

Local workflow syntax/security/scope checks and 14 targeted tests passed. Local cspell remains unavailable, but actual hosted cspell 8.17.3 validation passed on head 6b39e1451d64f6131f242703aebedac38ac75b59. Spell Check run 37856956230 successfully executed Compute changed lines, Install cspell, and cspell on changed lines; the spelling step was not skipped. This verifies the original failure is resolved in the real extracted-diff path, not just a full-file scan.

Workflow-lint run 37856956320 passed actionlint, shellcheck, and all 109 inline-script tests. The CI workflow-security job also passed. Remaining broader CI and maintainer review are not represented as complete. Latest readiness snapshot: 80 passing checks, 19 skipped, 2 pending (test-policies and Python E2E (Ollama)), no failed checks; the branch is mergeable, draft, and awaiting required review. Non-merging Agent merge is enabled for fixes/conflicts/reviews with merging disabled.

Unit Testing

No repository tests added or changed for this dependency-and-comment-only update. python -m pytest tests\ci\test_changed_lines.py tests\ci\test_extract_workflow_shell.py -q passed locally: 14 tests. These existing tests cover added-line extraction/scoping and workflow shell extraction. Hosted pytest tests/ci/ -v passed: 109 tests in workflow-lint.

The upstream Tests run 36494359744 completed successfully on the exact pinned commit, including its Tests step. This is upstream evidence, not a claim that its Docker action was executed locally. Because pull_request_target runs the base workflow, this replacement's PR-size job will not exercise the changed action before merge.

Manual Testing

Windows/PowerShell validation; $a in the exact commands below denotes this session's artifacts directory, which holds isolated validation tools/scripts and is not committed:

$a = 'C:\Users\rickygummadi\.copilot\session-state\a7d79c4a-e4c7-4778-bdeb-818013a6956b\files'
Exact command Result
& "$a\actionlint-1.7.12\actionlint.exe" -color '.github\workflows\pr-size.yml' Passed with actionlint 1.7.12, matching CI. Official Windows release ZIP SHA-256 verified as 6e7241b51e6817ea6a047693d8e6fed13b31819c9a0dd6c5a726e1592d22f6e9.
python "$a\validate_pr_size.py" Passed YAML parsing, exact SHA/version and original-update equivalence assertions, unchanged events/permissions/inputs/labels/thresholds, no checkout/run, trailing newline and one-file scope. Also executed the exact existing ci.yml Audit pull_request_target workflows script under Git Bash: all applicable workflows passed. The validation helper is a session artifact, not a repository change.
python -m pytest tests\ci\test_changed_lines.py tests\ci\test_extract_workflow_shell.py -q Passed locally: 14 tests.
python scripts\ci\changed_lines.py --base origin/main --extensions '.md,.txt,.rst,.py,.ts,.js,.go,.rs,.cs,.yml,.yaml' --mode added-lines --output "$a\spell-check-added-lines.txt" Passed; output contains exactly the spelling directive followed by the updated action reference.
git --no-pager diff --check Passed.
cspell --version Failed locally: executable absent. No local spelling pass is claimed.
cspell "ci-diff/spell-check-added-lines.txt" --config .cspell.json --no-progress --no-summary Passed on the hosted runner with cspell 8.17.3 in run 37856956230, on the exact replacement head; step executed successfully, not skipped.
actionlint -color -ignore 'unknown permission scope "models"' -ignore 'undefined variable "pattern"' -ignore 'SC2016' -ignore 'SC2001' -ignore 'SC2129' -ignore 'SC2193' Passed on the hosted runner in workflow-lint run 37856956320.
shellcheck -s bash workflow-shell-extracted.sh Passed on the hosted runner in workflow-lint run 37856956320.
pytest tests/ci/ -v Passed on the hosted runner: 109 tests in 4.47 seconds, run 37856956320.

The CI-pinned cspell@8.17.3 release dates to 2025-01-28T12:07:33Z. Isolated local installation failed under the corporate feed's remote-package restriction (EALLOWREMOTE); an official-registry attempt failed TLS negotiation, and preserving the configured proxy while normalizing tarball hosts exposed a feed-path 404. No TLS or package-security control was relaxed, no repository dependency/configuration was modified, and no verified sibling executable was available. The established hosted Spell-check changed files job has now supplied the real successful result.

Live rendered body and diff were verified: all 14 template headings, 19 HTML comments, and 47 checklist items are preserved in order; the published workflow bytes match the local committed file exactly. Repository-wide builds, unrelated package suites, and local Docker-action execution were not run locally; they are not justified by this one-workflow pin/comment change. Broader hosted checks and maintainer approval remain pending.

Checklist

  • I have linked a related issue above, or completed "Problem & Solution", "Impact on Your Work", and "Alternatives Considered"
  • My code follows the project style guidelines (ruff check)
  • I have added tests that prove my fix/feature works
  • All new and existing tests pass (pytest)
  • I have updated documentation as needed
  • I have signed the Microsoft CLA

Attribution & Prior Art

  • This contribution does not contain code copied or derived from other projects without attribution
  • Any external projects that inspired this design are credited in code comments or documentation
  • If this PR implements functionality similar to an existing open-source project, I have listed it below

Prior art / related projects (if any):

Dependabot's #4235 supplied the exact dependency update. CodelyTV/pr-size-labeler supplies the action; the relevant release behavior is described in CodelyTV/pr-size-labeler#110. This PR introduces no new integration or borrowed implementation. The commit includes repository-required Microsoft attribution and a DCO signoff.

AI Assistance

  • I can explain every meaningful change in this PR: what it does, why, and what tradeoffs were considered
  • I have run tests and verification appropriate for this change
  • No part of this PR was autonomously submitted by an AI agent without my review
  • I have not used AI to generate review comments on others' PRs

If AI tools materially shaped this change, briefly note what was used:

GitHub Copilot performed the user-authorized investigation, narrow workflow edit, validation, commit, and draft PR submission under explicit human direction. Human review of this specific output and the CLA/AI attestations have not been verified; the corresponding boxes remain unchecked. Maintainer approval is required before any merge. The single superseded comment and closure on the original PR were explicitly authorized by the coordinator only after scoped hosted verification and a fresh discussion/head/equivalence preflight.

IP, Patents, and Licensing

  • This contribution does not implement patent-pending or patent-encumbered techniques
  • This contribution does not require an NDA or licensing agreement to understand or use
  • Any AI tools used have terms compatible with the MIT License

Preserve the verified SHA update proposed by Dependabot in #4235. Add a workflow-local cspell directive for the actual upstream owner so the changed-lines spelling check can accept the action reference without a shared dictionary exemption.

Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions github-actions Bot added scripts/ci/cd size/XS Extra small PR (< 10 lines) labels Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/codelytv/pr-size-labeler 4e3aa0f77f348c8066513d453515316ffa01a607 UnknownUnknown

Scanned Files

  • .github/workflows/pr-size.yml

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

scripts/ci/cd size/XS Extra small PR (< 10 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant