ci: adopt the inline pr-agent lane — a public repo cannot call a private reusable workflow - #59
Conversation
🤖 CodeAnt AI — Review Status
|
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_e79b57be-3720-4adb-b95f-c802d07e28d6) |
Reviewer's GuideThis PR replaces the broken reusable GitHub Actions workflow invocation for pr-agent in a public repo with an inline, self-contained workflow that mirrors the private reusable lane, adds concurrency-key and timeout fixes, and introduces explicit retry and verdict logic so pr-agent is advisory and resilient to failures and rate limits. Sequence diagram for the inline PR-Agent review with retry and verdictsequenceDiagram
participant GitHub
participant Workflow
participant Qodo as PR-Agent Qodo Merge
participant Router as LLM Router
participant Verdict
GitHub->>Workflow: Trigger pull_request or trusted /review comment
Workflow->>Workflow: Evaluate pr_agent condition
Workflow->>Qodo: Run PR-Agent attempt 1
Qodo->>Router: Request review
alt Attempt 1 succeeds
Router-->>Qodo: Review result
Qodo-->>Workflow: success
else Attempt 1 fails
Router-->>Qodo: Error or timeout
Qodo-->>Workflow: failure
Workflow->>Workflow: backoff before retry
Workflow->>Qodo: Run PR-Agent retry attempt 2
Qodo->>Router: Request review
Router-->>Qodo: Review result or failure
Qodo-->>Workflow: Retry outcome
end
Workflow->>Verdict: Run verdict
Verdict-->>GitHub: Advisory check result
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
Warning Review limit reachedNext included review available in 57 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 91 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
Comment |
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This PR turns a previously non-running reference into a secret-bearing, write-enabled inline workflow with new retry, timeout, and slash-command behavior. Its issue-comment path does not exclude fork pull requests, leaving a concrete risk that trusted commands could run the external action against untrusted content with repository secrets. Not approved because:
Review your spending limits in Billing settings. You can add or adjust custom eligibility rules. Learn more. |
PR Reviewer Guide 🔍(Review updated until commit 98632f7)Here are some key observations to aid the review process:
|
PR Summary by QodoCI: inline pr-agent workflow for public repos (avoid private reusable call)
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
There was a problem hiding this comment.
Hey - I've reviewed your changes and they look great!
Sourcery assessment
Needs a human reviewer. If the workflow or pinned action is wrong, it can send pull-request contents to the configured external API and use the repository token to add comments or commits, with potential API cost and changes that outlive a revert. Those effects are bounded and can generally be removed or corrected, but any information disclosure or unwanted external request cannot be undone by reverting this workflow.
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
|
Note Automatic reviews are paused because your team has used its included automatic processing for this billing period (headroom scales with your seat count). You can still comment "Gitar review" to run one anytime, and automatic reviews resume on their own by September 1. Add seats for more headroom. Code Review ✅ ApprovedAdopts the self-contained inline PR-Agent workflow to resolve private reusable workflow failures in public repositories. No issues found. OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
…ate reusable workflow This repo's pr-agent.yml calls `wave-av/wave-foundation/.github/workflows/reusable-pr-agent.yml`, and wave-foundation is PRIVATE. GitHub does not permit a PUBLIC repository to call a reusable workflow from a private one, so the `uses:` never resolves: the run dies before any job is created — conclusion: failure, total_count: 0, no log, and no check run on the head sha to read. Every PR here has carried a red check that reports nothing, and external contributors see it. Measured across the org 2026-08-22: 7 public repos / 176 runs / 100% failure; 9 private repos / zero failures — a clean 16/16 split on visibility alone. Three competing hypotheses (missing OPENAI_KEY, dead pinned ref, @main vs a pinned sha) were each tested and refuted. THE FIX already existed and was never adopted: wave-foundation-public/.github/workflows/pr-agent.yml is an INLINE copy of the same lane with no reference to the private repo. This adopts it verbatim. PROVEN BEFORE FANNING OUT. wave-certify#44 took this exact change first and its pr_agent run returned SUCCESS on the pull_request event — a job with a real log, where the broken form produced no job at all. 27 repos were not changed on hope. Two prerequisites named in wave-pen#388 are cleared as of wave-foundation-public#71: the shared concurrency key that let any bot comment cancel a live review ~10s in (wave-pen#386) now keys on github.event_name, and the lane carries step-level timeouts. The job id stays `pr_agent`, so the check-run context is unchanged and no branch protection rule needs touching. Refs wave-pen#388 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Code Review by Qodo
1.
|
PR Code Suggestions ✨No code suggestions found for the PR. |
889c2a6 to
98632f7
Compare
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_b7048554-675c-4387-a035-79a81b73c93c) |
|
Persistent review updated to latest commit 98632f7 |
Qodo Fixer✅ Merged (0) · ☑ Fixed (0) Process
|
…t classification Picks up wave-foundation-public#72, which landed after this PR was opened. The template this PR originally copied classified timeouts on TOTAL job time (attempt 1 + 45s backoff + attempt 2) against STEP_BUDGET_S=360, a PER-ATTEMPT budget. Two healthy-but-slow attempts (~180s each) were therefore reported as "TIMED OUT ... A hang, NOT a rate limit", and the else-branch claimed the run was "well inside the budget" from the same misused total. Found by qodo review on wave-monitor#48 and confirmed against the file. Now stamps each attempt separately and classifies on the LONGEST attempt, with if: always() end stamps so an attempt killed BY its step timeout still records one. Verified by dry-running both cases before the template landed. Updated in place rather than as a follow-up PR because this has not merged yet — cheaper, and it keeps the repo from ever carrying the defective version. Refs wave-av/wave-pen#417, wave-av/wave-pen#388
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_232e8cc9-6487-4e73-8820-c76cc6d24394) |
…s step cap Re-syncs this PR to the hardened template before it merges, so it cannot land carrying the two defects it was opened with (wave-pen#418, wave-foundation-public#73). 1. Fork status is now RESOLVED, not assumed. The job-level `if:` refuses forks on the `pull_request` arm; it structurally cannot on `issue_comment`, because fork status is absent from that payload — measured, with a positive control: `issues/<n>.pull_request` carries exactly [diff_url, html_url, merged_at, patch_url, url], while `pulls/<n>.head.repo.fork` answers. A `fork gate` step asks the pulls endpoint and FAILS CLOSED: only a literal `false` proceeds; a 404, a revoked token, a rate limit and `.head.repo = null` all skip. Scope: this lane runs no `actions/checkout`, so fork code is never fetched or executed and no exfiltration path existed. The durable defect was the comment claiming "Forks skipped (no secrets there)" — true of one arm, false of the other, and exactly what would mislead whoever adds a checkout step later. 2. CONFIG__AI_TIMEOUT 600 -> 300, in both env blocks. 600s inside a 360s step is unreachable: the runner killed the step first, so pr-agent never reached its own timeout and never fell back to CONFIG__FALLBACK_MODELS. 3. A latent classifier bug the gate exposed: `stamp attempt 2 end` runs under `if: always()`, so when attempt 2 never ran the arithmetic subtracted from zero and reported a 1787580408-second attempt as a confident TIMED OUT. Fixed at the arithmetic; the verdict also gains an explicit `skipped` branch. The job id stays `pr_agent`, so the check-run context is unchanged and no branch protection rule needs touching. Refs wave-pen#418, wave-pen#417, wave-pen#388 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_88f9a8c1-4d4f-4daa-847b-e813ebf85256) |
User description
User description
User description
Part of the fan-out tracked in wave-pen#388, proven first on wave-certify#44 where
pr_agentreturned success.The defect
pr-agent.ymlhere callswave-av/wave-foundation/.github/workflows/reusable-pr-agent.yml@main, and wave-foundation is private. GitHub does not permit a public repository to call a reusable workflow from a private one, so theuses:never resolves: the run dies before any job is created —conclusion: failure,total_count: 0, no log, and no check run on the head sha at all.That is worse than a normal failure. There is nothing to click through to. Every PR on this repo has been carrying a red check that reports nothing, and external contributors see it.
Measured on this repo today — the last 5
pr-agentruns:Measured across the org on 2026-08-22: 7 public repos / 176 runs / 100% failure; 9 private repos / zero failures. A clean 16/16 split on visibility alone. Three competing hypotheses were each tested and refuted — missing
OPENAI_KEY(present in both populations), a dead pinned ref (150ffae2resolves, file exists at it), and@mainvs a pinned sha (wave-realtime-edgepins@mainand fails,wave-penpins@mainand works).The fix already existed and was never adopted
wave-foundation-public/.github/workflows/pr-agent.ymlis an inline copy of the same lane with no reference to the private repo. Its own header says it was written for exactly this. This PR adopts it verbatim.So this is an adoption gap, not a design gap.
Why now, and not when #388 was filed
#388 named two blockers, and both are cleared as of wave-foundation-public#71:
pr-agent-${{ github.event.pull_request.number || … }}, shared betweenpull_requestandissue_comment, so any bot comment cancelled a live review ~10s in (wave-pen#386). It now keys ongithub.event_name.Fanning out before those landed would have traded a red-with-no-log lane for a cancelled-on-every-comment lane — a different failure, not a fix.
Verified before opening this
wave-foundation/mentions are in comments, not in auses:. Checked rather than assumed, since that is the whole property this depends on.pr_agent. A job's id is its check-run context and branch protection matches on(context, app_id), so nothing needs touching on the protection side.wave-foundation-public's default branch — not from a local checkout that might be parked on another branch.The receipt is this PR, not the diff
A red lane and a working lane are indistinguishable until one actually runs — that is the whole reason 176 failures went unexamined. So the proof is
pr-agentgoing green on this PR. If it does, the remaining 27 repos get the same change with evidence behind it. If it does not, we learn that here, on one low-traffic repo, instead of across the org's entire public surface.Proven before fanning out. wave-certify#44 took this exact change first and its
pr_agentrun returned success on thepull_requestevent — a job with a real log, where the broken form produced no job at all. The other repos were not changed on hope.Refs wave-pen#388
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Note
Medium Risk
CI-only, but it posts on PRs with GITHUB_TOKEN/OPENAI_KEY and changes how an advisory check succeeds or stays green. Misclassification could hide real failures or still flake checks.
Overview
Stops calling the private
wave-foundationreusable workflow (which GitHub never resolves from a public repo) and inlines the pr-agent job so reviews actually start and produce logs.Concurrency now includes
github.event_name, so slash-command comments no longer cancel in-flight push reviews. The job skips bots, drafts, forks, and untrusted comments.Runs pinned
The-PR-Agent/pr-agentv0.42.0 twice (6-minute step budget, 45s backoff,continue-on-error). A verdict step classifies success, cancel, hang vs rate-limit and exits 0 on advisory flakes so a 429 cannot block the PR.Reviewed by Cursor Bugbot for commit bf8a3b7. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by Sourcery
Adopt the self-contained public pr-agent workflow so advisory reviews run reliably and safely on this repository.
Bug Fixes:
Enhancements:
CI:
PR Type
Bug fix
Description
Replaced private workflow reference with inline public version
Added concurrency controls for event-specific grouping
Implemented fork detection gate for security
Added retry logic with timeout management
Enhanced verdict classification for failure analysis
Diagram Walkthrough
File Walkthrough
pr-agent.yml
Migrated to inline pr-agent workflow with enhanced reliability.github/workflows/pr-agent.yml