From 1d9391b85ecc2a7273a05f277d998b4882c3053d Mon Sep 17 00:00:00 2001 From: Shubham Pampattiwar Date: Thu, 3 Sep 2026 09:58:20 -0700 Subject: [PATCH] Evaluate changelog exemption labels from live PR state (#10472) The changelog check decided whether a PR was exempt using the labels in the triggering event payload (github.event.pull_request.labels). That payload is frozen at event time, so a PR that gets the kind/changelog-not-required label after its first run could not pass by re-running the failed job, and the exemption only took effect if a brand new event happened to fire afterward. Move the exemption logic into hack/changelog-check.sh and query the PR's current labels via the GitHub API instead. Re-runs and labels added after the initial run are now evaluated correctly. The workflow grants pull-requests: read and passes github.token so the script can read labels. The exempt label set (kind/changelog-not-required, Design, Website, Documentation) is unchanged. Signed-off-by: Shubham Pampattiwar --- .github/workflows/pr-changelog-check.yml | 8 +++++++- hack/changelog-check.sh | 16 ++++++++++++++++ 2 files changed, 23 insertions(+), 1 deletion(-) diff --git a/.github/workflows/pr-changelog-check.yml b/.github/workflows/pr-changelog-check.yml index 67c1a6221..8f2f59733 100644 --- a/.github/workflows/pr-changelog-check.yml +++ b/.github/workflows/pr-changelog-check.yml @@ -4,6 +4,11 @@ name: Pull Request Changelog Check on: pull_request: types: [opened, synchronize, reopened, labeled, unlabeled] + +permissions: + contents: read + pull-requests: read + jobs: build: @@ -16,5 +21,6 @@ jobs: uses: actions/checkout@v7 - name: Changelog check - if: ${{ !(contains(github.event.pull_request.labels.*.name, 'kind/changelog-not-required') || contains(github.event.pull_request.labels.*.name, 'Design') || contains(github.event.pull_request.labels.*.name, 'Website') || contains(github.event.pull_request.labels.*.name, 'Documentation'))}} + env: + GH_TOKEN: ${{ github.token }} run: ./hack/changelog-check.sh diff --git a/hack/changelog-check.sh b/hack/changelog-check.sh index f2e2fb0f9..1a3d588e1 100755 --- a/hack/changelog-check.sh +++ b/hack/changelog-check.sh @@ -28,6 +28,22 @@ CHANGELOG_PATH='changelogs/unreleased' # GITHUB_REF is something like "refs/pull/:prNumber/merge" pr_number=$(echo $GITHUB_REF | cut -d / -f 3) +# Some kinds of pull requests do not require a changelog entry. Rather than +# relying on the (frozen) event payload, query the PR's current labels so the +# check reflects the latest state. This makes re-runs and labels added after +# the initial run behave correctly. +EXEMPT_LABELS=("kind/changelog-not-required" "Design" "Website" "Documentation") + +if command -v gh > /dev/null 2>&1; then + current_labels=$(gh api "repos/${GITHUB_REPOSITORY}/pulls/${pr_number}" --jq '.labels[].name' 2>/dev/null || true) + for label in "${EXEMPT_LABELS[@]}"; do + if grep -Fxq "$label" <<< "$current_labels"; then + echo "PR ${pr_number} has the '${label}' label; changelog not required." + exit 0 + fi + done +fi + change_log_file="${CHANGELOG_PATH}/${pr_number}-*" if ls ${change_log_file} 1> /dev/null 2>&1; then