Fix bot PR auto-merge and linpeas exclude matching

This commit is contained in:
Carlos Polop
2026-05-21 13:03:38 +02:00
parent e5866ca0a1
commit 1ea8107bf5
5 changed files with 115 additions and 37 deletions
+3 -3
View File
@@ -24,7 +24,7 @@ jobs:
- name: Checkout
uses: actions/checkout@v5
with:
ref: ${{ github.head_ref }}
ref: ${{ github.head_ref || github.ref_name }}
- name: Download regexes
run: |
@@ -113,7 +113,7 @@ jobs:
# Download repo
- uses: actions/checkout@v5
with:
ref: ${{ github.head_ref }}
ref: ${{ github.head_ref || github.ref_name }}
# Setup go
- uses: actions/setup-go@v6
@@ -173,7 +173,7 @@ jobs:
# Download repo
- uses: actions/checkout@v5
with:
ref: ${{ github.head_ref }}
ref: ${{ github.head_ref || github.ref_name }}
# Build linpeas (macpeas)
- name: Build macpeas
@@ -6,6 +6,82 @@ on:
types: [completed]
jobs:
auto_merge_windows_definition_bot_pr:
if: ${{ github.event.workflow_run.conclusion == 'success' }}
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
steps:
- name: Resolve and verify bot PR
id: bot_pr
env:
PR_NUMBER: ${{ github.event.workflow_run.pull_requests[0].number }}
HEAD_BRANCH: ${{ github.event.workflow_run.head_branch }}
GH_REPO: ${{ github.repository }}
GH_TOKEN: ${{ github.token }}
run: |
title="chore(winpeas): update windows version vulnerability definitions"
branch="bot/update-windows-version-definitions"
expected_file="build_lists/windows_version_exploits.json"
pr_number="${PR_NUMBER}"
if [ -z "$pr_number" ] && [ -n "$HEAD_BRANCH" ]; then
pr_number="$(gh pr list --state open --head "$HEAD_BRANCH" --base master --json number --jq '.[0].number')"
fi
if [ -z "$pr_number" ]; then
echo "No pull request found for this workflow_run; skipping."
echo "should_merge=false" >> "$GITHUB_OUTPUT"
exit 0
fi
pr_json="$(gh pr view "$pr_number" --json title,baseRefName,headRefName,author,isCrossRepository,files,mergeStateStatus)"
pr_title="$(jq -r .title <<<"$pr_json")"
base_ref="$(jq -r .baseRefName <<<"$pr_json")"
head_ref="$(jq -r .headRefName <<<"$pr_json")"
author="$(jq -r .author.login <<<"$pr_json")"
is_cross_repository="$(jq -r .isCrossRepository <<<"$pr_json")"
merge_state="$(jq -r .mergeStateStatus <<<"$pr_json")"
files="$(jq -r '.files[].path' <<<"$pr_json")"
file_count="$(jq -r '.files | length' <<<"$pr_json")"
if [ "$pr_title" != "$title" ] ||
[ "$base_ref" != "master" ] ||
[ "$head_ref" != "$branch" ] ||
[ "$author" != "app/github-actions" ] ||
[ "$is_cross_repository" != "false" ] ||
[ "$file_count" != "1" ] ||
[ "$files" != "$expected_file" ]; then
echo "PR #$pr_number is not the trusted windows definitions bot PR; skipping."
echo "should_merge=false" >> "$GITHUB_OUTPUT"
exit 0
fi
if [ "$merge_state" != "CLEAN" ] && [ "$merge_state" != "HAS_HOOKS" ]; then
echo "Refusing to merge PR #$pr_number because mergeStateStatus=$merge_state"
echo "should_merge=false" >> "$GITHUB_OUTPUT"
exit 0
fi
echo "should_merge=true" >> "$GITHUB_OUTPUT"
echo "pr_number=$pr_number" >> "$GITHUB_OUTPUT"
echo "title=$title" >> "$GITHUB_OUTPUT"
- name: Merge trusted bot PR
if: ${{ steps.bot_pr.outputs.should_merge == 'true' }}
env:
GH_TOKEN: ${{ github.token }}
PR_NUMBER: ${{ steps.bot_pr.outputs.pr_number }}
COMMIT_TITLE: ${{ steps.bot_pr.outputs.title }}
run: |
gh api \
-X PUT \
-H "Accept: application/vnd.github+json" \
"/repos/${{ github.repository }}/pulls/${PR_NUMBER}/merge" \
-f merge_method=squash \
-f commit_title="$COMMIT_TITLE"
chack_agent_triage:
if: ${{ github.event.workflow_run.conclusion == 'success' }}
runs-on: ubuntu-latest
@@ -6,6 +6,7 @@ on:
workflow_dispatch:
permissions:
actions: write
contents: write
pull-requests: write
@@ -35,7 +36,7 @@ jobs:
- name: Validate windows version definitions
run: python3 build_lists/validate_windows_version_defs.py
- name: Create and merge validated update pull request
- name: Create validated update pull request
env:
GH_TOKEN: ${{ github.token }}
run: |
@@ -67,30 +68,4 @@ jobs:
--body "Automated update of \`build_lists/windows_version_exploits.json\`. The generated JSON passed \`build_lists/validate_windows_version_defs.py\` before this PR was updated."
fi
pr_number="$(gh pr list --state open --head "$branch" --base master --json number --jq '.[0].number')"
pr_json="$(gh pr view "$pr_number" --json title,baseRefName,headRefName,author,mergeable)"
pr_title="$(jq -r .title <<<"$pr_json")"
base_ref="$(jq -r .baseRefName <<<"$pr_json")"
head_ref="$(jq -r .headRefName <<<"$pr_json")"
author="$(jq -r .author.login <<<"$pr_json")"
mergeable="$(jq -r .mergeable <<<"$pr_json")"
if [ "$pr_title" != "$title" ] || [ "$base_ref" != "master" ] || [ "$head_ref" != "$branch" ]; then
echo "Refusing to merge unexpected PR #$pr_number: title=$pr_title base=$base_ref head=$head_ref"
exit 1
fi
if [ "$author" != "app/github-actions" ] && [ "$author" != "github-actions" ] && [ "$author" != "github-actions[bot]" ]; then
echo "Refusing to merge PR #$pr_number from unexpected author: $author"
exit 1
fi
if [ "$mergeable" != "MERGEABLE" ]; then
echo "Refusing to merge PR #$pr_number because mergeable=$mergeable"
exit 1
fi
gh api \
-X PUT \
-H "Accept: application/vnd.github+json" \
"/repos/${{ github.repository }}/pulls/${pr_number}/merge" \
-f merge_method=squash \
-f commit_title="$title"
gh workflow run PR-tests.yml --ref "$branch"