Skip to content

[pull] main from jason5ng32:main - #123

Merged
pull[bot] merged 19 commits into
Cosr-Backup:mainfrom
jason5ng32:main
Aug 23, 2026
Merged

pull[bot] merged 19 commits into
Cosr-Backup:mainfrom
jason5ng32:main

Conversation

@pull

@pull pull Bot commented Aug 23, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Copilot AI and others added 19 commits August 22, 2026 16:39
Co-authored-by: jason5ng32 <1546290+jason5ng32@users.noreply.github.com>
Co-authored-by: jason5ng32 <1546290+jason5ng32@users.noreply.github.com>
Add Brazilian Portuguese beta UI translation
A source declining with 403 is a fail-over, not a defect — keep it below
the level error monitoring captures, while every other failure stays an
error so a real outage still surfaces.
Post-merge polish on #426: 'Visitor share' and the persona-check
header/script labels named the wrong referent, and the service-status
banner read as 'operating systems'; keep the banner short enough for
its card.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
CI renders the i18n-status dashboard into the run summary and, when a
PR touches locale data, hands it to a workflow_run job as an artifact;
that job upserts one sticky PR comment. Split in two on purpose: the
report is computed under the read-only token fork PRs get, and only
trusted default-branch code holds the write token.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
First-time contributors get the full onboarding message, returning
contributors a shorter welcome back; maintainer and bot PRs are
skipped. No PR code is ever checked out or executed here, which is
what makes pull_request_target safe for this job.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Four labels wrapped to two lines and misaligned the desktop navbar;
bring them down to the length the fr/ru packs already fit in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The report is produced by the PR's own code, so the privileged comment
workflow no longer republishes its Markdown: the artifact now carries
raw text, and the trusted side strips backticks, caps the size and
renders it inside a code fence it authors itself. Also paginate the
sticky-comment lookup past 100 comments, and move both new workflows'
purpose headers to line one per the file-header convention.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Even fenced plain text from the PR's run let a hostile PR speak in the
bot's voice. The artifact now carries a structured --json snapshot
(counts, locale codes, key paths); the privileged side validates every
field against enums, integer bounds and tight regexes, then renders the
comment text entirely with trusted code. A hostile PR can at most
misstate its own coverage numbers — it cannot emit prose, links or
instructions as the bot.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Republishing PR-computed content under the bot identity needed ever more
laundering (fences, then schema validation) and the residue was still
reviewer-flagged — the data originates from code the PR controls, so no
amount of validation closes that. The convenience isn't worth the
privileged surface: the CI job summary already shows the same dashboard
from inside the PR's own sandbox, so the sticky comment, its artifact
hand-off and the --json mode all go.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@pull pull Bot locked and limited conversation to collaborators Aug 23, 2026
@pull pull Bot added the ⤵️ pull label Aug 23, 2026
@pull
pull Bot merged commit 5fe62ba into Cosr-Backup:main Aug 23, 2026
3 of 4 checks passed
@4everland
4everland Bot requested a deployment to production August 23, 2026 06:27 Abandoned

This branch had an error being deployed

1 abandoned deployment
production — 5fe62ba0 Deployed Aug 23, 2026 by 4everland[bot]
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants