[pull] main from jason5ng32:main - #123
Merged
Merged
Conversation
Co-authored-by: jason5ng32 <1546290+jason5ng32@users.noreply.github.com>
Co-authored-by: jason5ng32 <1546290+jason5ng32@users.noreply.github.com>
Add Brazilian Portuguese beta UI translation
A source declining with 403 is a fail-over, not a defect — keep it below the level error monitoring captures, while every other failure stays an error so a real outage still surfaces.
Post-merge polish on #426: 'Visitor share' and the persona-check header/script labels named the wrong referent, and the service-status banner read as 'operating systems'; keep the banner short enough for its card. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
CI renders the i18n-status dashboard into the run summary and, when a PR touches locale data, hands it to a workflow_run job as an artifact; that job upserts one sticky PR comment. Split in two on purpose: the report is computed under the read-only token fork PRs get, and only trusted default-branch code holds the write token. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
First-time contributors get the full onboarding message, returning contributors a shorter welcome back; maintainer and bot PRs are skipped. No PR code is ever checked out or executed here, which is what makes pull_request_target safe for this job. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Four labels wrapped to two lines and misaligned the desktop navbar; bring them down to the length the fr/ru packs already fit in. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The report is produced by the PR's own code, so the privileged comment workflow no longer republishes its Markdown: the artifact now carries raw text, and the trusted side strips backticks, caps the size and renders it inside a code fence it authors itself. Also paginate the sticky-comment lookup past 100 comments, and move both new workflows' purpose headers to line one per the file-header convention. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Even fenced plain text from the PR's run let a hostile PR speak in the bot's voice. The artifact now carries a structured --json snapshot (counts, locale codes, key paths); the privileged side validates every field against enums, integer bounds and tight regexes, then renders the comment text entirely with trusted code. A hostile PR can at most misstate its own coverage numbers — it cannot emit prose, links or instructions as the bot. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Republishing PR-computed content under the bot identity needed ever more laundering (fences, then schema validation) and the residue was still reviewer-flagged — the data originates from code the PR controls, so no amount of validation closes that. The convenience isn't worth the privileged surface: the CI job summary already shows the same dashboard from inside the PR's own sandbox, so the sticky comment, its artifact hand-off and the --json mode all go. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot] (v2.0.0-alpha.4)
Can you help keep this open source service alive? 💖 Please sponsor : )