Allow overriding the base ref used for comparison - #248
Merged
mateuszkwiecinski merged 1 commit intoAug 7, 2026
Merged
Conversation
|
Test2 +--- org.jetbrains.kotlin:kotlin-stdlib:2.4.10
-| \--- org.jetbrains:annotations:13.0 -> 23.0.0
+| +--- org.jetbrains:annotations:13.0
+| +--- org.jetbrains.kotlin:kotlin-stdlib-jdk8:1.8.0 (c)
+| +--- org.jetbrains.kotlin:kotlin-stdlib-common:2.4.10 (c)
+| \--- org.jetbrains.kotlin:kotlin-stdlib-jdk7:1.8.0 (c)
-\--- androidx.paging:paging-common-ktx:3.5.0
- +--- androidx.paging:paging-common:3.5.0
- | \--- androidx.paging:paging-common-desktop:3.5.0
- | +--- androidx.annotation:annotation:1.9.1
- | | \--- androidx.annotation:annotation-jvm:1.9.1
- | | \--- org.jetbrains.kotlin:kotlin-stdlib:1.9.24 -> 2.4.10 (*)
- | +--- androidx.arch.core:core-common:2.2.0
- | | \--- androidx.annotation:annotation:1.1.0 -> 1.9.1 (*)
- | +--- org.jetbrains.kotlin:kotlin-stdlib:2.1.20 -> 2.4.10 (*)
- | +--- org.jetbrains.kotlinx:kotlinx-coroutines-core:1.9.0
- | | \--- org.jetbrains.kotlinx:kotlinx-coroutines-core-jvm:1.9.0
- | | +--- org.jetbrains:annotations:23.0.0
- | | +--- org.jetbrains.kotlinx:kotlinx-coroutines-bom:1.9.0
- | | | +--- org.jetbrains.kotlinx:kotlinx-coroutines-core-jvm:1.9.0 (c)
- | | | \--- org.jetbrains.kotlinx:kotlinx-coroutines-core:1.9.0 (c)
- | | \--- org.jetbrains.kotlin:kotlin-stdlib:2.0.0 -> 2.4.10 (*)
- | \--- androidx.paging:paging-common-ktx:3.5.0 (c)
- +--- org.jetbrains.kotlin:kotlin-stdlib:2.1.20 -> 2.4.10 (*)
- \--- androidx.paging:paging-common:3.5.0 (c)
+\--- androidx.paging:paging-common-ktx:3.2.0
+ +--- androidx.paging:paging-common:3.2.0
+ | +--- androidx.annotation:annotation:1.3.0
+ | +--- androidx.arch.core:core-common:2.2.0
+ | | \--- androidx.annotation:annotation:1.1.0 -> 1.3.0
+ | +--- org.jetbrains.kotlin:kotlin-stdlib:1.8.21 -> 2.4.10 (*)
+ | +--- org.jetbrains.kotlinx:kotlinx-coroutines-core:1.6.4
+ | | \--- org.jetbrains.kotlinx:kotlinx-coroutines-core-jvm:1.6.4
+ | | +--- org.jetbrains.kotlinx:kotlinx-coroutines-bom:1.6.4
+ | | | +--- org.jetbrains.kotlinx:kotlinx-coroutines-core-jvm:1.6.4 (c)
+ | | | \--- org.jetbrains.kotlinx:kotlinx-coroutines-core:1.6.4 (c)
+ | | +--- org.jetbrains.kotlin:kotlin-stdlib-jdk8:1.6.21 -> 1.8.0
+ | | | +--- org.jetbrains.kotlin:kotlin-stdlib:1.8.0 -> 2.4.10 (*)
+ | | | \--- org.jetbrains.kotlin:kotlin-stdlib-jdk7:1.8.0
+ | | | \--- org.jetbrains.kotlin:kotlin-stdlib:1.8.0 -> 2.4.10 (*)
+ | | \--- org.jetbrains.kotlin:kotlin-stdlib-common:1.6.21 -> 2.4.10
+ | | \--- org.jetbrains.kotlin:kotlin-stdlib:2.4.10 (*)
+ | \--- androidx.paging:paging-common-ktx:3.2.0 (c)
+ \--- androidx.paging:paging-common:3.2.0 (c) |
|
Test1 +--- org.jetbrains.kotlin:kotlin-stdlib:2.4.10
-| \--- org.jetbrains:annotations:13.0 -> 23.0.0
+| +--- org.jetbrains:annotations:13.0
+| +--- org.jetbrains.kotlin:kotlin-stdlib-jdk8:1.8.0 (c)
+| +--- org.jetbrains.kotlin:kotlin-stdlib-common:2.4.10 (c)
+| \--- org.jetbrains.kotlin:kotlin-stdlib-jdk7:1.8.0 (c)
-\--- androidx.paging:paging-common-ktx:3.5.0
- +--- androidx.paging:paging-common:3.5.0
- | \--- androidx.paging:paging-common-desktop:3.5.0
- | +--- androidx.annotation:annotation:1.9.1
- | | \--- androidx.annotation:annotation-jvm:1.9.1
- | | \--- org.jetbrains.kotlin:kotlin-stdlib:1.9.24 -> 2.4.10 (*)
- | +--- androidx.arch.core:core-common:2.2.0
- | | \--- androidx.annotation:annotation:1.1.0 -> 1.9.1 (*)
- | +--- org.jetbrains.kotlin:kotlin-stdlib:2.1.20 -> 2.4.10 (*)
- | +--- org.jetbrains.kotlinx:kotlinx-coroutines-core:1.9.0
- | | \--- org.jetbrains.kotlinx:kotlinx-coroutines-core-jvm:1.9.0
- | | +--- org.jetbrains:annotations:23.0.0
- | | +--- org.jetbrains.kotlinx:kotlinx-coroutines-bom:1.9.0
- | | | +--- org.jetbrains.kotlinx:kotlinx-coroutines-core-jvm:1.9.0 (c)
- | | | \--- org.jetbrains.kotlinx:kotlinx-coroutines-core:1.9.0 (c)
- | | \--- org.jetbrains.kotlin:kotlin-stdlib:2.0.0 -> 2.4.10 (*)
- | \--- androidx.paging:paging-common-ktx:3.5.0 (c)
- +--- org.jetbrains.kotlin:kotlin-stdlib:2.1.20 -> 2.4.10 (*)
- \--- androidx.paging:paging-common:3.5.0 (c)
+\--- androidx.paging:paging-common-ktx:3.2.0
+ +--- androidx.paging:paging-common:3.2.0
+ | +--- androidx.annotation:annotation:1.3.0
+ | +--- androidx.arch.core:core-common:2.2.0
+ | | \--- androidx.annotation:annotation:1.1.0 -> 1.3.0
+ | +--- org.jetbrains.kotlin:kotlin-stdlib:1.8.21 -> 2.4.10 (*)
+ | +--- org.jetbrains.kotlinx:kotlinx-coroutines-core:1.6.4
+ | | \--- org.jetbrains.kotlinx:kotlinx-coroutines-core-jvm:1.6.4
+ | | +--- org.jetbrains.kotlinx:kotlinx-coroutines-bom:1.6.4
+ | | | +--- org.jetbrains.kotlinx:kotlinx-coroutines-core-jvm:1.6.4 (c)
+ | | | \--- org.jetbrains.kotlinx:kotlinx-coroutines-core:1.6.4 (c)
+ | | +--- org.jetbrains.kotlin:kotlin-stdlib-jdk8:1.6.21 -> 1.8.0
+ | | | +--- org.jetbrains.kotlin:kotlin-stdlib:1.8.0 -> 2.4.10 (*)
+ | | | \--- org.jetbrains.kotlin:kotlin-stdlib-jdk7:1.8.0
+ | | | \--- org.jetbrains.kotlin:kotlin-stdlib:1.8.0 -> 2.4.10 (*)
+ | | \--- org.jetbrains.kotlin:kotlin-stdlib-common:1.6.21 -> 2.4.10
+ | | \--- org.jetbrains.kotlin:kotlin-stdlib:2.4.10 (*)
+ | \--- androidx.paging:paging-common-ktx:3.2.0 (c)
+ \--- androidx.paging:paging-common:3.2.0 (c)output path: |
The action resolved the comparison base from `github.base_ref` with no way to override it. For GitHub's stacked pull requests that produces false positives: the merge commit CI checks out is built on top of the parent PR's merge commit (which already contains recent `main`), while `github.base_ref` points at the stack base. Both sides then hold a different version of `main`, and dependency changes that landed there get reported as introduced by the pull request. Add an optional `base-ref` input falling back to `github.base_ref`, so the default behaviour is unchanged, and resolve it as any commit-ish instead of a remote branch name only. The ref is still fetched from `origin` first, so branch names keep resolving to the freshest remote state; refs that only exist locally (`HEAD^1`, an unpushed commit) fall back to the local repository. Fetching a sha into a branch of the same name is not possible, hence the dropped refspec destination and the detached switch, which covers branch names and shas alike. Closes #247 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
mateuszkwiecinski
force-pushed
the
mateuszkwiecinski/dependency-tree-diff-247-b0a5d5
branch
from
August 7, 2026 12:01
a357ae0 to
29dedf8
Compare
mateuszkwiecinski
marked this pull request as ready for review
August 7, 2026 12:03
mateuszkwiecinski
deleted the
mateuszkwiecinski/dependency-tree-diff-247-b0a5d5
branch
August 7, 2026 12:11
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #247
Why
The comparison base was resolved from
github.base_refwith no way to override it. With GitHub's stacked pull requests that produces false positives: the merge commit CI checks out is built on top of the parent PR's merge commit (which already contains recentmain), whilegithub.base_refpoints at the stack base. Both sides of the comparison then hold a different version ofmain, and dependency changes that landed there get reported as introduced by the pull request.What changed
New
base-refinput, defaulting to''so it falls back togithub.base_ref— existing setups behave exactly as before:The base ref is now resolved as any commit-ish, not just a remote branch name:
Fetch-first keeps the default path identical to today (always the freshest remote state, never a stale local branch); the fallback is what makes
HEAD^1and unpushed commits work. The:refspecdestination had to go — a sha cannot be fetched into a branch of the same name — and--detachcovers branch names and shas uniformly.There is also an upfront guard for an empty base ref, which previously failed deep in the script with
couldn't find remote reffrom a":"refspec.The stacked-PR fix is then a one-liner, no
resolve_basestep needed:Notes for the reviewer
HEAD^1, and an explicit sha (with and withoutuploadpack.allowAnySHA1InWant) all land on the intended commit; an unresolvable ref exits 128 before any diffing happens.entrypoint.ps1is verified by inspection only — nopwshon the machine this was written on. Thetry/catcharoundgit fetchcovers PowerShell 7.4's throw-on-native-error in addition to the$LASTEXITCODEcheck. The Windows CI job should confirm the unchanged default path.test-job-with-custom-base-refjob runs the action twice, once per resolution path (local-onlyHEAD^1, thengithub.event.pull_request.base.shavia origin). The version downgrade is re-applied between the two runs becausegit switch --forcediscards it — pre-existing behaviour, but without re-applying it the second assertion would be vacuous.🤖 Generated with Claude Code