Skip to content

ci: add cascading notification support - #15

Merged
mateodelnorte merged 2 commits into
mainfrom
ci/cascading-notifications
Feb 14, 2026
Merged

mateodelnorte merged 2 commits into
mainfrom
ci/cascading-notifications

Conversation

@mateodelnorte

@mateodelnorte mateodelnorte commented Feb 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds repository_dispatch trigger to CI so upstream dependency updates run the test suite
  • Updates notify-parent.yml to handle both push and dispatch triggers, forwarding upstream payload on cascade

Test plan

  • Verify CI still runs on push/PR
  • After merge, verify notify-parent dispatches to meta on both push and cascade

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Enhanced CI workflow to support automated dependency update event triggers
    • Improved dependency update event handling and notifications with better event source detection across workflows

- Add repository_dispatch trigger to CI for upstream dependency updates
- Update notify-parent.yml to handle both push and dispatch triggers,
  forwarding upstream payload on cascade

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Feb 14, 2026 •

Copy link
Copy Markdown

Warning

Rate limit exceeded

@mateodelnorte has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 5 minutes and 57 seconds before requesting another review.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

Walkthrough

Both CI and notify-parent workflows now support repository_dispatch events with dependency-updated type. The notify-parent workflow refactored its step logic to conditionally determine source information from either the dispatch event payload or derived from git commits, with outputs fed to the parent notification.

Changes

Cohort / File(s) Summary
CI Workflow Trigger
.github/workflows/ci.yml
Added repository_dispatch trigger with type dependency-updated to enable workflow execution on dependency update events.
Notify-Parent Workflow Enhancement
.github/workflows/notify-parent.yml
Replaced "Extract commit info" step with "Determine source" step that conditionally populates outputs based on event type: for repository_dispatch events, reads directly from event payload; for push events, derives information from latest commit. Updated notification payload to consume all outputs from the new source step.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Poem

🐰 A dependency update hops through the gates,
Dispatch events trigger workflows with fate,
Sources now split—payload or commit history—
Notifications flutter upward in victory!
Parent repos receive the word, swift and clear,
The rabbit approves: dependency updates are here! 🌱

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately captures the main change: adding cascading notification support via repository_dispatch triggers in CI workflows.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Merge Conflict Detection ✅ Passed ✅ No merge conflicts detected when merging into main

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch ci/cascading-notifications

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Fix all issues with AI agents
In @.github/workflows/notify-parent.yml:
- Around line 42-55: The workflow doesn't set steps.source.outputs.actor for
non-dispatch events so later consumers get an empty value; update this step to
emit an "actor" output into $GITHUB_OUTPUT (e.g., echo "actor=${{ github.actor
}}" >> $GITHUB_OUTPUT) when the event is not workflow_dispatch (or always emit
it as a fallback), ensuring steps.source.outputs.actor is populated; locate the
block that writes to $GITHUB_OUTPUT (uses MSG, repo, sha, short_sha) and add the
actor emission there.
- Around line 6-7: The workflow currently forwards repository_dispatch
client_payload to the parent repo using PARENT_REPO_PAT without validation; add
a guarding step that validates the incoming client_payload (e.g., check a shared
secret field or validate a JSON schema) and rejects/aborts the job when
validation fails before any step that uses PARENT_REPO_PAT or performs the
dispatch; reference the repository_dispatch trigger and the client_payload input
in the guard, and ensure the validation step sets a clear failure/exit so later
steps cannot run if the secret/schema check fails.

Comment thread .github/workflows/notify-parent.yml
Comment thread .github/workflows/notify-parent.yml
- Update lewagon/wait-on-check-action v1.3.4 → v1.5.0
- Use toJSON() in client-payload to prevent JSON injection
- Tighten commit type regex (^feat → ^feat[:(])
- Use shallow clone (remove fetch-depth: 0)
- Add missing actor output in push event path

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@mateodelnorte
mateodelnorte merged commit 50eb4ad into main Feb 14, 2026
7 checks passed
@mateodelnorte
mateodelnorte deleted the ci/cascading-notifications branch February 14, 2026 05:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant