Skip to content

feat: report the pull request's commit when CI checks out a merge commit - #9

Merged
agoldis merged 4 commits into
masterfrom
agoldis/eng-934-pull-request-head-commit
Sep 23, 2026
Merged

agoldis merged 4 commits into
masterfrom
agoldis/eng-934-pull-request-head-commit

Conversation

@agoldis

@agoldis agoldis commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

On pull request builds, commitInfo now returns the pull request's last commit (sha, message, author, email, timestamp) instead of the merge commit the CI provider checks out. A GitHub Actions pull_request run with the default actions/checkout reports the real commit instead of "Merge into ". @currents/cmd and @currents/playwright get this with a version bump.

How it works

  • The head sha comes from pull_request.head.sha in the GitHub event file (ghaEventData, which this package already reads), or from a provider variable: CI_MERGE_REQUEST_SOURCE_BRANCH_SHA (GitLab merged results), SYSTEM_PULLREQUEST_SOURCECOMMITID (Azure), TRAVIS_PULL_REQUEST_SHA, SEMAPHORE_GIT_PR_SHA, BUILDKITE_PULL_REQUEST_HEAD_COMMIT, BITBUCKET_COMMIT.
  • It is used only when the checked-out commit is a merge (two or more parents) and the pull request's commit is one of its parents. The parents come from git cat-file commit, which works in depth-1 clones where HEAD^2 does not. This skips pull_request_target, merge queue builds, and one-parent commits a build adds on top of the pull request.
  • When the commit is missing from a shallow clone, it is fetched: git fetch --depth=1 --no-tags origin <sha>, 3s timeout, no credential prompt, one retry when another process holds .git/shallow.lock. A full clone is never fetched into, because --depth would make it shallow.
  • Any failure returns the checked-out commit, as before. CURRENTS_DISABLE_HEAD_COMMIT_FETCH=true skips the fetch. COMMIT_INFO_* variables still take priority, and COMMIT_INFO_SHA skips the lookup.
  • The message keeps the format git show -s --pretty=%B gives today, including the trailing newline.
  • engines.node goes from >=6 to >=8 for async/await. Version 1.1.0-beta.0, to publish under the beta tag first.

No flag that needs a recent git: --no-write-fetch-head needs git 2.29, and the Ubuntu 20.04 images some users run ship git 2.25.

Not covered

  • Jenkins with the merge strategy: there is no head sha variable, and the pull request commit is the first parent. Needs separate detection.
  • Azure private repos: persistCredentials defaults to false, so the fetch fails and the merge commit is reported.

Verification

  • New Pull request commit workflow runs commitInfo on this PR's own checkout from actions/checkout@v4 and compares it with git show of the PR head. All four jobs pass:
    • depth 1, git 2.55: reported the PR head, after fetching it
    • full clone (fetch-depth: 0): reported the PR head without fetching
    • depth 1, git 2.25 in mcr.microsoft.com/playwright:v1.28.1-focal: reported the PR head. The container needs safe.directory, as it already does for HEAD.
    • CURRENTS_DISABLE_HEAD_COMMIT_FETCH=true: reported the merge commit, as before
  • mocha: 39 passing (24 existing, 15 new), on macOS (git 2.50, Node 24), in the Ubuntu 20.04 image (git 2.25, Node 16) and in the repo's ci job. standard passes.
  • New unit tests run against real git repos: a local origin with a GitHub-style refs/pull/1/merge. Cases:
    • depth-1 fetch, full clone without fetch, provider variable, pull request commit as first parent
    • pull_request_target checkout, one-parent commit on top of the pull request, opt-out, failed fetch, outside a repo
    • origin that never answers: gives up after one 3s attempt
    • three processes fetching at once: two lose .git/shallow.lock on the first attempt and still return the commit
    • commitInfo with a GitHub event file, COMMIT_INFO_* priority
  • npm pack --dry-run includes src/pull-request-head.js and excludes the spec.
  • Not run on GitLab, Azure, Travis, Semaphore, Buildkite or Bitbucket; those are covered by the provider variable tests only. Not run on Windows.

Publishing needs #10 (publish workflow) on master.

Refs ENG-934

🤖 Generated with Claude Code

https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR

On pull request builds GitHub Actions checks out refs/pull/N/merge, so
commitInfo returned "Merge <sha> into <sha>" with the merge commit's author.
GitLab merged results pipelines, Azure Pipelines, Travis, Semaphore,
Bitbucket Pipelines and Buildkite with the merge refspec do the same.

The pull request's sha comes from the GitHub event file or the provider's
environment variable. When that commit is a parent of the checked-out
commit, its sha, message, author, email and timestamp are returned instead.
In a depth-1 clone, the actions/checkout default, that one commit is fetched
from origin with a 3s timeout. A failed fetch keeps the checked-out commit.

CURRENTS_DISABLE_HEAD_COMMIT_FETCH=true skips the fetch. COMMIT_INFO_*
variables still take priority, and COMMIT_INFO_SHA skips the lookup.
engines.node goes to >=8 for async/await.

Refs ENG-934

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR
@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: 1ea50da6-b14d-4115-b7b3-854fbb6588a8

📥 Commits

Reviewing files that changed from the base of the PR and between 80ffa78 and 65acdde.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (5)
  • README.md
  • package.json
  • src/index.js
  • src/pull-request-head-spec.js
  • src/pull-request-head.js
Files not reviewed due to moderation or processing errors (4)
  • src/pull-request-head.js
  • src/pull-request-head-spec.js
  • src/index.js
  • README.md

Included review availability: 0 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour.


📝 Walkthrough

Walkthrough

The change adds pull request head commit lookup to commitInfo. It verifies the head against the checkout, can fetch missing commits in shallow repositories, and respects COMMIT_INFO_* overrides. The package version and minimum supported Node.js version also change.

Changes

Pull request head metadata

Layer / File(s) Summary
Resolve and validate the pull request head
src/pull-request-head.js, src/pull-request-head-spec.js
The resolver selects a head SHA, verifies it against the checkout, fetches a missing commit when allowed, and reads its metadata. Tests cover merge types, shallow and full clones, fetch conditions, and missing or invalid head commits.
Integrate head metadata and document behavior
src/index.js, src/pull-request-head-spec.js, README.md, package.json
commitInfo uses resolved head data unless COMMIT_INFO_SHA is set, then applies environment values. Integration tests check pull request metadata and override precedence. The README documents lookup and fetch behavior; package metadata updates the version and minimum Node.js version.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Sequence Diagram(s)

sequenceDiagram
  participant commitInfo
  participant getPullRequestHeadCommit
  participant Git
  commitInfo->>getPullRequestHeadCommit: checkout SHA and GitHub event data
  getPullRequestHeadCommit->>Git: check parents and commit availability
  getPullRequestHeadCommit->>Git: fetch missing SHA when allowed
  getPullRequestHeadCommit->>Git: read head commit metadata
  getPullRequestHeadCommit-->>commitInfo: head commit data or null
Loading

Merge Risk: ⚪ Minimal · up to 65acd

Pull-request builds now report the pull request's last commit instead of the CI merge commit. The reported data has the same shape as for other builds. When the head commit cannot be found or fetched, reporting falls back to the checked-out commit without errors. The minimum Node.js version rises to 8, as documented. No merge-blocking issues were found.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 40.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 10 functions across 3 files. (2 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: reporting the pull request commit when CI checks out a merge commit.
Full details: Docstring Coverage

Explanation

Docstring coverage is 40.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 10 functions across 3 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

A pull_request workflow runs commitInfo on the checkout actions/checkout
makes: depth 1, full clone, git 2.25 in the Ubuntu 20.04 Playwright image,
and with CURRENTS_DISABLE_HEAD_COMMIT_FETCH. Unit tests cover the 3s
timeout against an origin that never answers, and three processes
fetching the same commit at once.

Version 1.1.0-beta.0 for the beta release.

Refs ENG-934

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR
Refs ENG-934

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR
@agoldis

agoldis commented Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

@baz review

@baz-reviewer

baz-reviewer Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review this PR on Baz

Baz Summary

Update commitInfo to report the pull request head commit when CI checks out a merge commit, including its SHA, message, author, email, and timestamp. Add resilient local lookup/fetch logic, provider support, documentation, tests, and a validation workflow while preserving COMMIT_INFO_* overrides and fallback behavior.

Topics

TopicDetails
PR commit reporting Report the pull request head commit from GitHub Actions and supported CI provider metadata, safely reading or fetching it from shallow clones while preserving existing overrides and failure behavior.
Modified files (6)
  • README.md
  • package-lock.json
  • package.json
  • src/index.js
  • src/pull-request-head-spec.js
  • src/pull-request-head.js
Latest Contributors(2)
UserCommitDate
agoldis@gmail.comfix: only replace a ch...September 23, 2026
dj@currents.devchore: Update npm regi...October 17, 2024
CI validation Validate merge-checkout behavior across clone depths, Git versions, fetch failures, disabled fetching, and concurrent fetches using automated tests and a GitHub Actions workflow.
Modified files (3)
  • .github/scripts/check-pull-request-commit.js
  • .github/workflows/pull-request.yml
  • src/pull-request-head-spec.js
Latest Contributors(1)
UserCommitDate
agoldis@gmail.comfix: only replace a ch...September 23, 2026

Merger  Activate to get a short verdict whether this PR is good to go or not

Skills  Activate Skill Maintainer to keep your skills up to date

Planner  This PR would have been improved with Baz Planner - Try it now

Comment thread src/pull-request-head.js
Comment thread .github/workflows/pull-request.yml
…commit

A one-parent commit that a build adds on top of the pull request is a real
commit and is reported as is. The PR workflow gets contents: read, since
it runs the pull request's code.

Refs ENG-934

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant