Skip to content

ci: run PR Hygiene's engine from master - #5247

Merged
shumkov merged 1 commit into
v5.0-devfrom
chore/pr-hygiene-engine-from-master
Oct 2, 2026
Merged

shumkov merged 1 commit into
v5.0-devfrom
chore/pr-hygiene-engine-from-master

Conversation

@shumkov

@shumkov shumkov commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

What

This repo's PR Hygiene caller now runs the shared engine from master of dashpay/stale_prs_are_bad instead of a pinned commit:

- uses: dashpay/stale_prs_are_bad/.github/workflows/pr-review-reusable.yml@3b987722c37e91755785c031abb3f98fb08ea763
+ uses: dashpay/stale_prs_are_bad/.github/workflows/pr-review-reusable.yml@master

Why

With a pinned commit, every engine fix needs a re-pin PR here before it takes effect. The engine fixes merged this week (review bots that open PRs, "your part" per area, branch patterns) haven't reached this repo yet. Meanwhile the review policy is already read live from that same master, so pinned engines and the live policy can drift apart.

Security trade-off (please review)

Naming a branch instead of a SHA means engine upgrades are reviewed in dashpay/stale_prs_are_bad, not here. The controls there:

  • protect-master: changes need a pull request with code-owner review and the required test/check CI. Force-push and deletion are blocked.
  • no-tag-shadows-master: a master tag is forbidden, with no bypass. GitHub would resolve a tag before the branch.
  • The reusable workflow's bootstrap still refuses any commit not merged to that master (feat: a caller may run the engine from master stale_prs_are_bad#73).

Verified in a real run: dashpay/grovedb run 36953611829, caller on @master, succeeded.

🤖 Generated with Claude Code

PR Hygiene · ba8b1ae

  • Bots — coderabbitai ✓ · thepastaclaw ✓
  • Self-review — post /self-reviewed
  • Within your 5 open PRs — this one is beyond the limit; it waits until one merges
  • Build green
  • Approvals
    • github (.github/workflows/pr-review-policy.yml) — ktechmidas

When every box is checked the PR Hygiene check passes and this can merge.

Summary by CodeRabbit

  • Chores
    • Updated the automated pull request review policy to use the shared workflow’s current version. This keeps review checks aligned with the latest workflow changes; no changes to app functionality are included.

The caller pinned the shared engine to one commit, so every engine fix
needed a re-pin here before it took effect. The engine is now named by
`master` of dashpay/stale_prs_are_bad — the protected branch the review
policy is already read from — and the reusable workflow still requires
the commit it runs to be merged there (dashpay/stale_prs_are_bad#73).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added this to the v5.0.0 milestone Oct 2, 2026
@github-actions github-actions Bot added the waiting-bots Waiting for the review bots to report on this head label Oct 2, 2026
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: dashpay/platform/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 3e851845-259d-493e-b86b-0e90b06a2a43

📥 Commits

Reviewing files that changed from the base of the PR and between e1efd2a and ba8b1ae.

📒 Files selected for processing (1)
  • .github/workflows/pr-review-policy.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The policy job now references pr-review-reusable.yml at the master branch instead of a fixed commit SHA.

Changes

PR review policy

Layer / File(s) Summary
Reusable workflow reference
.github/workflows/pr-review-policy.yml
The policy job now references pr-review-reusable.yml at the master branch instead of a pinned commit.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Other

Suggested reviewers: infraclaw-dash

Merge Risk: ⚪ Minimal · up to ba8b1

The policy job now follows upstream master, allowing upstream workflow updates to take effect without a local re-pin. The claimed safeguards remain unverified, but no concrete bypass or failure is established in the available evidence.

Architecture Summary

Architecture risk: 🔵 Low · up to ba8b1

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/pr-review-policy.yml: The reusable workflow reference changes from the pinned commit 3b987722c37e91755785c031abb3f98fb08ea763 to the master branch.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: running the PR Hygiene engine from the master branch.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@thepastaclaw

thepastaclaw commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

✅ Final review complete — Phase 1 only — no blockers (commit ba8b1ae) · triage: trivial

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Final review — Phase 1 only (trivial change)

The one-line workflow change correctly switches the PR Hygiene reusable workflow to the intended master branch, and no in-scope code or architecture issue was identified. The PR title currently fails the repository's existing title-linter configuration because ci is not an allowed scope, but that is pre-existing metadata unrelated to this diff.

Review provenance

Source: reviewer 1: glm-5.3-flash (agent: phase1-reviewer, role: general); reviewer 2: glm-5.3-flash (agent: phase1-reviewer, role: architecture-layering); reviewer 3: glm-5.3-flash (agent: phase1-reviewer, role: security-auditor); final verifier: gpt-6.1-sol (agent: sol-gate-verifier, role: final-verifier)

  • Triage: trivial by gpt-6.1-sol (effort low) — This is a one-line CI workflow reference change with no application behavior, consensus, security implementation, or runtime functionality changes.
  • Phase 1 reviewers: glm-5.3-flash — general (completed, effort high); agent phase1-reviewer, glm-5.3-flash — architecture-layering (completed, effort high); agent phase1-reviewer, glm-5.3-flash — security-auditor (completed, effort high); agent phase1-reviewer
  • Phase 1 model: glm-5.3-flash — zai quota: 5h 99% left, weekly 71% left; passed over gemini-3.8-flash-high (antigravity below 15% reserve: weekly 70% left, 5h 12% left)
  • Fresh verifier: gpt-6.1-sol — final-verifier; agent sol-gate-verifier
  • Phase 2 reviewers: not run (triage rated this change trivial); this review comments and never approves
Out-of-scope follow-up suggestions (2)

These are valid observations, but they are outside this PR's scope and should be handled in separate issues or author/maintainer-requested PRs rather than blocking this review.

  • PR title uses an unrecognized ci scope — The current title, chore(ci): run PR Hygiene's engine from master, fails .github/workflows/pr.yml: ci is allowed as a type but is absent from the configured scopes. This blocks the title check, but it is unrelated to the workflow-reference change under review.
    • Follow-up: Retitle this PR without the scope, such as chore: run PR Hygiene's engine from master, or address the scope configuration in a separate PR.
  • PR title "chore(ci): ..." fails the title linter — scope "ci" is not allowed, blocking the merge gate — NOT_ACTIONABLE: .github/workflows/pr.yml confirms that ci is not in the allowed scopes list, but the PR title is outside the changed files and the failure is not caused by switching the reusable workflow reference.
    • Follow-up: Consider creating a separate issue or author/maintainer-requested PR for this.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bots are done — your move: post /self-reviewed.
Full checklist in the description.

@github-actions github-actions Bot added waiting-self-review Waiting for the author to post /self-reviewed and removed waiting-bots Waiting for the review bots to report on this head labels Oct 2, 2026
@shumkov shumkov changed the title chore(ci): run PR Hygiene's engine from master ci: run PR Hygiene's engine from master Oct 2, 2026
@shumkov
shumkov merged commit 547f5a9 into v5.0-dev Oct 2, 2026
24 of 27 checks passed
@shumkov
shumkov deleted the chore/pr-hygiene-engine-from-master branch October 2, 2026 09:28
@PastaPastaPasta PastaPastaPasta mentioned this pull request Oct 5, 2026
1 of 22 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

waiting-self-review Waiting for the author to post /self-reviewed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants