ci: add cascading notification support - #15
Conversation
- Add repository_dispatch trigger to CI for upstream dependency updates - Update notify-parent.yml to handle both push and dispatch triggers, forwarding upstream payload on cascade Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
Warning Rate limit exceeded
⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. WalkthroughBoth CI and notify-parent workflows now support repository_dispatch events with dependency-updated type. The notify-parent workflow refactored its step logic to conditionally determine source information from either the dispatch event payload or derived from git commits, with outputs fed to the parent notification. Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Poem
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Fix all issues with AI agents
In @.github/workflows/notify-parent.yml:
- Around line 42-55: The workflow doesn't set steps.source.outputs.actor for
non-dispatch events so later consumers get an empty value; update this step to
emit an "actor" output into $GITHUB_OUTPUT (e.g., echo "actor=${{ github.actor
}}" >> $GITHUB_OUTPUT) when the event is not workflow_dispatch (or always emit
it as a fallback), ensuring steps.source.outputs.actor is populated; locate the
block that writes to $GITHUB_OUTPUT (uses MSG, repo, sha, short_sha) and add the
actor emission there.
- Around line 6-7: The workflow currently forwards repository_dispatch
client_payload to the parent repo using PARENT_REPO_PAT without validation; add
a guarding step that validates the incoming client_payload (e.g., check a shared
secret field or validate a JSON schema) and rejects/aborts the job when
validation fails before any step that uses PARENT_REPO_PAT or performs the
dispatch; reference the repository_dispatch trigger and the client_payload input
in the guard, and ensure the validation step sets a clear failure/exit so later
steps cannot run if the secret/schema check fails.
- Update lewagon/wait-on-check-action v1.3.4 → v1.5.0 - Use toJSON() in client-payload to prevent JSON injection - Tighten commit type regex (^feat → ^feat[:(]) - Use shallow clone (remove fetch-depth: 0) - Add missing actor output in push event path Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Summary
repository_dispatchtrigger to CI so upstream dependency updates run the test suitenotify-parent.ymlto handle both push and dispatch triggers, forwarding upstream payload on cascadeTest plan
🤖 Generated with Claude Code
Summary by CodeRabbit