Skip to content

chore: add release-readiness checklist reminder workflow - #3952

Open
michaelmalave wants to merge 5 commits into
v12.0.0from
worker/production-readiness-checklist-bot-task-1
Open

michaelmalave wants to merge 5 commits into
v12.0.0from
worker/production-readiness-checklist-bot-task-1

Conversation

@michaelmalave

@michaelmalave michaelmalave commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a small, advisory GitHub Actions workflow that leaves a friendly reminder on pull requests that change something customers see or use. When an internal contributor opens such a PR, the bot posts a single sticky comment — greeting the author by name — linking the Dev Tools Release Readiness Checklist (get a CX review; optionally share the PRD/roadmap, Dev Center docs, and a target release date). It never blocks the PR and cleans the comment up if the PR later stops touching customer-facing files.

  • Add .github/workflows/release-readiness-checklist.yml.
  • Post a sticky, de-duplicated comment on customer-facing PRs, removing it if the PR no longer qualifies.
  • Show the reminder only to internal contributors (MEMBER/OWNER); external PRs are skipped entirely.
  • @-mention the PR author, using only trusted context — no elevated token, no GitHub App, no checkout of PR code.

Type of Change

Breaking Changes (major semver update)

  • Add a ! after your change type to denote a change that breaks current behavior

Feature Additions (minor semver update)

  • feat: Introduces a new feature to the codebase

Patch Updates (patch semver update)

  • fix: Bug fix
  • deps: Dependency upgrade
  • revert: Revert a previous commit
  • chore: Change that does not affect production code
  • refactor: Refactoring existing code without changing behavior
  • test: Add/update/remove tests

Testing

Notes:
The workflow triggers on pull_request_target in this repo, so it cannot run from a fork PR's CI before merge. It was validated statically.

Steps:

  1. ruby -ryaml -e "YAML.load_file('.github/workflows/release-readiness-checklist.yml')" — Expect: parses without error.
  2. Confirm there is no uses:/checkout step (pure bash, so no PR-head code is ever checked out).
  3. Confirm the job is gated on author_association (MEMBER/OWNER) and that only trusted context (repository, PR number, author association/login) is passed via env: — never interpolated into run:.

Screenshots (if applicable)

Related Issues

The linked checklist lives in heroku/engineering-docs (teams/developer-tooling/release-readiness-checklist.md); its link resolves once that doc merges.

Advisory, non-blocking GitHub Action that posts a sticky comment linking
the Dev Tools Release Readiness Checklist on customer-facing PRs, visible
only to internal Heroku contributors (MEMBER/OWNER), greeting the author
by GitHub login. No elevated token, no GitHub App, no PR-head checkout.
AUTHOR is passed via env: and referenced only as the bash var $AUTHOR in
run: (never as a raw ${{ }} expression) — safe because the job already
gates on MEMBER/OWNER and a GitHub login is charset-constrained
([a-zA-Z0-9-], <=39 chars), so it cannot inject markdown or shell.
Mirrors the pr-size-label.yml house pattern for pull_request_target
safety and try()-guarded advisory writes.
@michaelmalave
michaelmalave requested a review from a team as a code owner September 25, 2026 19:45
@michaelmalave
michaelmalave deployed to AcceptanceTests September 25, 2026 19:45 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 25, 2026 19:45 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 25, 2026 19:45 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests September 25, 2026 19:45 — with GitHub Actions Active
@github-actions github-actions Bot added the size/M Medium PR (code churn < 500) label Sep 25, 2026
@michaelmalave michaelmalave changed the title Task 1: Add the release-readiness checklist reminder workflow chore: add release-readiness checklist reminder workflow Sep 25, 2026
@michaelmalave
michaelmalave deployed to AcceptanceTests October 6, 2026 16:05 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests October 6, 2026 16:05 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests October 6, 2026 16:05 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests October 6, 2026 16:05 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests October 6, 2026 17:27 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests October 6, 2026 17:27 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests October 6, 2026 17:27 — with GitHub Actions Active
@michaelmalave
michaelmalave deployed to AcceptanceTests October 6, 2026 17:27 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
AcceptanceTests — 8c964e71 Deployed Oct 6, 2026 by michaelmalave via acceptance (22.x, ubuntu-latest) #9399
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/M Medium PR (code churn < 500)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants