Skip to content

ci: replace actions-cool/issues-helper with official GitHub actions - #37

Open
oiorain wants to merge 1 commit into
mainfrom
ci/replace-issues-helper
Open

oiorain wants to merge 1 commit into
mainfrom
ci/replace-issues-helper

Conversation

@oiorain

@oiorain oiorain commented Sep 25, 2026

Copy link
Copy Markdown

What does it do?

Replaces actions-cool/issues-helper@v3 with official GitHub actions, pinned to commit SHAs (same versions as strapi/strapi):

  • issues_handleLabel.yml: uses actions/github-script. Same behaviour: comment on status: can not reproduce, comment and close on flag: invalid template and flag: question.
  • issues_dailyCron.yml: uses actions/stale. status: can not reproduce issues are still closed after 14 days without activity.

Workflow permissions are reduced to issues: write. Message text is unchanged.

Why is it needed?

actions-cool/issues-helper was compromised: all tags were repointed to a commit that steals CI secrets and ignores the action's filters. GitHub has blocked the repository, so these workflows now fail. No runs were found here during the compromise windows.

How to test it?

After merge:

  • Add status: can not reproduce, flag: invalid template or flag: question to a test issue and check the comment / close.
  • Run Daily Cron manually from the Actions tab and check the logs.

Related issue(s)/PR(s)

Same fix as strapi/sdk-plugin#240 and strapi/design-system#2062.

🤖 Generated with Claude Code

actions-cool/issues-helper was compromised (all tags repointed to a
credential-stealing commit) and has been blocked by GitHub. Use pinned
actions/stale and actions/github-script instead, and reduce workflow
permissions to issues: write.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Sep 25, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: d0d8068

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant