Repository navigation
Wire automatic self reviews for this repository - #416
Conversation
Add a self-review caller workflow that reviews this repo's own PRs with the reusable review workflow: general, security, auth-api, deploy-actions, db-lambda, and glm-swarm on initial review, followup on pushed commits, and maintainer /6529bot comment commands parsed with the same parser the App uses. Kind selection lives in bin/self-review-plan.cjs, guarded by check-review-workflow-kinds and smoke tests. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 2 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (4)
📝 WalkthroughWalkthroughThis PR adds a new self-review GitHub Actions workflow, a planning CLI that builds review jobs from PR/comment/dispatch events, workflow validation updates, and supporting docs and smoke tests. ChangesSelf Review Workflow
Estimated code review effort: 3 (Moderate) | ~25 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
The first self-review run failed posting comments: github.token cannot comment on PRs with pull-requests read-only, and the workflow permission contract deliberately keeps it that way. Rework the self-review workflow to mirror the production worker instead: the plan step builds full job payloads with createReviewJobs, and each matrix job mints a GitHub App installation token and runs worker:job, posting as the bot with usage ledger accounting like App-dispatched reviews. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
6529bot follow-up commit review - a672cf5Verdict: Needs changes Important
Nice-to-have
Resolved since last review
Suggested next steps
Prompt for all review comments with AI agents |
|
@coderabbitai review |
✅ Action performedReview finished.
|
Pass the pull request action through as the job trigger, resolve PR context as a JSON object instead of positional newline splitting, gate usage-ledger accounting on the AWS role variable so partially configured repos degrade cleanly, and cover the /6529bot help empty-kinds path. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
6529bot follow-up commit review - 71aa76aVerdict: No new findings The three prior findings from the last same-lane review were all addressed in commit 71aa76a. Resolved since last review
I verified the remaining resolvePullRequest JSON refactor ( |
6529bot auth/API contract review - 71aa76aVerdict: No auth/API findings This PR wires a self-review GitHub Actions workflow for the reviewbot repo. It does not touch backend API routes, OpenAPI generation, DTOs, JWT/session/wallet/Safe verification, CORS, or rate limits. The auth-relevant surface here is the workflow trigger gate and installation-token minting, which are sound:
The three prior same-lane follow-up findings were already confirmed resolved in the previous 6529bot review (trigger passthrough, JSON PR-context parsing, One observation, not a finding for this lane: the Coverage note: this is a workflow/CLI change; there is no generated-client or OpenAPI drift to assess, and the added smoke tests lock the plan contract adequately. |
6529bot general PR review - 71aa76aVerdict: Good to merge The three prior same-lane findings ( Resolved since last review
The JSON-object PR-context refactor ( Notes for future consideration (non-blocking, not new findings):
|
6529bot DB/Lambda dataflow review - 71aa76aVerdict: No DB/Lambda findings The current head (71aa76a) is the same commit the prior same-lane followup review already covered, and this DB/Lambda pass adds no new findings. The changed surface is CI/workflow plumbing ( Points I checked from the DB/Lambda-flow angle and found sound:
No migration, backfill, replay, or queue ordering concerns apply to this diff. |
6529bot crypto security analysis - 71aa76aVerdict: No security findings I reviewed this PR against the crypto/auth/token/web3 focus areas. The prior three follow-up findings were addressed; this pass looked for new security regressions in the reworked installation-token path, comment-triggered flow, and PR context resolution. Key checks and why they hold:
Non-security nit (out of scope, not blocking): the No wallet, signature, nonce, chain-id, or JWT/refresh-token surface is touched by this PR. |
6529bot deploy/actions review - 71aa76aVerdict: No deploy/action findings All three findings from the prior same-lane follow-up review (
Resolved since last review
One optional hardening note, not blocking: the |
6529bot GLM Swarm ReviewVerdict: Advisory only This GLM swarm is advisory and complements, not replaces, existing tests and existing reviewbots. Important
Nice-to-have
Testing feedback loop
Partial reviewer outputOne or more internal advisory reviewer slices were unavailable; the synthesis used the remaining reviewer output.
|
There was a problem hiding this comment.
Actionable comments posted: 3
🧹 Nitpick comments (2)
bin/self-review-plan.cjs (1)
116-138: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win
execFileSynccall has no timeout.If
gh apihangs (network stall, rate limiting), this blocks indefinitely since theplanjob inself-review.ymlhas notimeout-minutesset, relying on the default GitHub Actions job timeout (6 hours).♻️ Suggested fix
const output = execFileSync( "gh", [ "api", `repos/${repository}/pulls/${prNumber}`, "--jq", "[.head.sha, .base.sha, .head.ref] | join(\"\\n\")", ], - { encoding: "utf8" } + { encoding: "utf8", timeout: 30_000 } );🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@bin/self-review-plan.cjs` around lines 116 - 138, The gh api call in resolvePullRequestWithGh currently has no timeout, so the plan step can hang indefinitely if GitHub stalls. Update the execFileSync invocation to enforce a reasonable timeout and handle the timeout failure cleanly, using resolvePullRequestWithGh and the gh api call as the key locations to modify.scripts/check-review-workflow-kinds.cjs (1)
163-224: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueParsed YAML result from
YAML.parseis discarded; only used for a syntax check.Minor: the parsed document isn't used to look up the
INITIAL_KINDS_JSON/SYNCHRONIZE_KINDS_JSONvalues structurally — instead regex extraction against the raw text is used (lines 186, 207). This works for the current single-line quoted-array format but is more fragile to formatting changes than walking the parsed YAML AST directly.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/check-review-workflow-kinds.cjs` around lines 163 - 224, The current checkSelfReviewWorkflow function only uses YAML.parse(workflowText) for syntax validation and then relies on regex against the raw text to read INITIAL_KINDS_JSON and SYNCHRONIZE_KINDS_JSON. Update this function to use the parsed YAML structure instead of string matching, so the kind arrays are read from the workflow document itself and validated there. Keep the existing validation behavior and messages, but locate the values through the parsed workflow object in checkSelfReviewWorkflow rather than the regex-based extraction.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/self-review.yml:
- Around line 21-23: The workflow permissions are too broad at the root and
missing explicit access for the plan job; move `id-token: write` off the
top-level permissions so only the `review` job can use OIDC via
`aws-actions/configure-aws-credentials`, and add `pull-requests: read` to the
`plan` job since it calls `gh api repos/{repo}/pulls/{prNumber}`. Keep
`contents: read` enabled for both jobs, and reference the `permissions`, `plan`,
and `review` job blocks when updating the workflow.
- Around line 26-37: Add a fork safety check to the issue_comment condition in
the self-review workflow so it only runs for PRs whose head repo matches the
base repository, matching the existing pull_request guard. Update the workflow
logic around the plan job in self-review.yml and keep the check aligned with the
self-review-plan.cjs behavior, since it assumes GITHUB_REPOSITORY as the head
repo and will fail on forked PRs. Ensure the new guard uses the same PR head
repository signal already available in the workflow context and prevents
/6529bot-triggered runs from forks from reaching the checkout step.
In `@bin/self-review-plan.cjs`:
- Around line 55-83: The self-review planning logic always sets headRepoFullName
from the current repository, which breaks issue_comment runs for forked PRs.
Update the planning flow in self-review-plan.cjs around the
resolvePullRequestWithGh / resolvePullRequest path to also capture the PR head
repository full_name from the resolved PR context and use it when building the
event, or explicitly reject fork PRs there if that is the intended behavior.
Make sure the event object’s headRepoFullName matches the actual PR head repo
rather than GITHUB_REPOSITORY.
---
Nitpick comments:
In `@bin/self-review-plan.cjs`:
- Around line 116-138: The gh api call in resolvePullRequestWithGh currently has
no timeout, so the plan step can hang indefinitely if GitHub stalls. Update the
execFileSync invocation to enforce a reasonable timeout and handle the timeout
failure cleanly, using resolvePullRequestWithGh and the gh api call as the key
locations to modify.
In `@scripts/check-review-workflow-kinds.cjs`:
- Around line 163-224: The current checkSelfReviewWorkflow function only uses
YAML.parse(workflowText) for syntax validation and then relies on regex against
the raw text to read INITIAL_KINDS_JSON and SYNCHRONIZE_KINDS_JSON. Update this
function to use the parsed YAML structure instead of string matching, so the
kind arrays are read from the workflow document itself and validated there. Keep
the existing validation behavior and messages, but locate the values through the
parsed workflow object in checkSelfReviewWorkflow rather than the regex-based
extraction.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 3a9f5b34-1ec0-4b45-9c7a-9ec27fe8d640
📒 Files selected for processing (5)
.github/workflows/self-review.ymlbin/self-review-plan.cjsdocs/review-workflows.mdscripts/check-review-workflow-kinds.cjsscripts/smoke-test.cjs
Move id-token: write off the workflow root onto the review job, give the plan job explicit pull-requests: read, resolve and validate the PR head repository so /6529bot comments on fork PRs fail closed before checkout, require a resolved base SHA and head ref, and expose the trigger in plan results with smoke coverage for the fork, partial-context, and trigger semantics raised by the self reviews. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
6529bot follow-up commit review - 0c1fc9fVerdict: No new findings The 0c1fc9f commit set cleanly addresses the three CodeRabbit inline findings that were open against the prior marker, and the follow-up work introduces no regressions I can find. Resolved since last review
Verification notes
One prior GLM-swarm advisory item remains technically open but is not a regression from this commit and is out of this lane's dedup-new scope: |
Summary
.github/workflows/self-review.ymltriggers on pull request events, maintainer/6529botcomment commands, and manual dispatch, and calls./.github/workflows/review.ymlwith planned kinds.general,security,auth-api,deploy-actions,db-lambda,glm-swarmfollowupparseReviewCommandthe App uses, gated to OWNER/MEMBER/COLLABORATOR authorswcag,i18n,responsiveness,safe-write,stream-contracts, ...) stay out of the automatic set but remain available by command.bin/self-review-plan.cjsholds the kind-selection logic (validated againstREVIEW_KINDS, resolves head SHA viagh apiwhen needed);scripts/check-review-workflow-kinds.cjsnow enforces the self-review workflow contract; docs get a Self Review section.Since
pull_requestworkflows run from the PR head, this PR should review itself — the workflow run on this PR is the live test.Testing
npm run release:checkpasses (exit 0), including the extended review-workflow-kinds contract check and new smoke coverage forplanSelfReview(initial/synchronize/comment/dispatch/invalid-kind/missing-PR cases).🤖 Generated with Claude Code
Summary by CodeRabbit