Repository navigation
fix(ci): correctly detect release tag/stable branch pipelines triggered via GitHub mirror - #450
Merged
Merged
Conversation
…ed via GitHub mirror
The mirror workflow (.github/workflows/mirror.yaml) sets
GITHUB_REPOSITORY=eic/containers for every triggered eicweb pipeline from
this repo, not just for PR builds; GITHUB_PR is only non-empty for actual
pull_request events. The version job's "trigger" branch checked
GITHUB_REPOSITORY instead of GITHUB_PR, so tag pushes (e.g.
v26.10.0-stable) and stable-branch pushes mirrored from GitHub were
misdetected as unstable PR builds ("unstable-mr-" with empty PR number),
skipping the Docker Hub push and never reaching the CI_COMMIT_TAG
detection below.
Also fix two further-down conditions that escape '(' '|' ')' as literal
characters in a bash extended regex (where they must be unescaped to mean
grouping/alternation), which meant stable branch pushes (e.g.
v26.10-stable) never matched either.
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The new regexes fail under Alpine’s BusyBox shell, and downstream PR image tags can collide.
Review effort: Balanced
Findings: 2
Open (3)
What changed in this PR
Corrects GitLab version detection for GitHub-mirrored pipelines.
Changes:
- Detects PR pipelines using
GITHUB_PR. - Separates downstream triggers from repository tag/branch pushes.
- Adjusts stable-branch regexes.
| File | Description |
|---|---|
.gitlab-ci.yml |
Updates mirrored pipeline classification and version matching. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Address review: the PR-build branch must require GITHUB_REPOSITORY == eic/containers in addition to GITHUB_PR being set, otherwise eic/epic and eic/EICrecon downstream PR triggers with the same PR number would collide on the same unstable-mr-<N> tag and (since GH_PUSH was no longer disabled for them) could overwrite each other's ghcr.io image. Restores the original downstream-trigger behavior (CI_COMMIT_BRANCH version, both GH_PUSH and DH_PUSH disabled) unchanged.
Address review: the version job runs in the top-level alpine image, whose /bin/sh is BusyBox ash. Unescaped parens after [[ =~ are parsed as shell grammar there and abort the whole script with a hard syntax error, rather than just failing to match as in bash. Reproduced locally with dash (same failure mode). Split each alternation into separate ||-joined [[ =~ ]] tests instead of using a (alpha|beta|stable) group, so no raw parens appear in the script. Also generalized a comment that named only eic/epic and eic/EICrecon as downstream triggerers; eic/EDM4eic uses the same path.
Contributor
wdconinc
approved these changes
Oct 6, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Problem
The GitLab CI
versionjob failed to recognizev26.10.0-stabletag pushes mirroredfrom GitHub (pipeline https://eicweb.phy.anl.gov/containers/eic_container/-/pipelines/150175),
causing it to tag images as
unstable-mr-(empty PR number) instead of26.10.0-stable,and to skip the Docker Hub push entirely.
Root cause
.github/workflows/mirror.yamlsetsGITHUB_REPOSITORY=eic/containersfor everyeicweb-triggered pipeline from this repo (branch pushes, tag pushes, and PRs alike),
while
GITHUB_PRis only populated for actualpull_requestevents.In
.gitlab-ci.yml'sversionjob, thetrigger-sourced branch checkedGITHUB_REPOSITORY == "eic/containers"to decide "is this a PR build?" — but that'strue for every trigger from this repo, not just PRs. So tag/stable-branch pushes were
misdetected as PR builds and never reached the
CI_COMMIT_TAGdetection logic below.Separately, two regexes further down escape
(,|,)as literal characters in abash extended regex (
[[ =~ ]]), where they need to be unescaped to meangrouping/alternation — so pushes of e.g.
v26.10-stableas a branch never matchedeither.
Fix
-n "${GITHUB_PR}"instead of the repo name to detect actual PR builds.only taken when there's no
GITHUB_PRand the repo isn'teic/containers, so thatour own tag/branch pushes fall through to the existing
CI_COMMIT_TAG/CI_COMMIT_BRANCHdetection unchanged.
(alpha|beta|stable)groups in the two stable-branch regexes.Verified both code paths (PR-triggered and tag-triggered) with a standalone bash
simulation of the relevant variables.