diff --git a/.github/aw/review/ROUTING b/.github/aw/review/ROUTING index b92dbf59..8ec41d5a 100644 --- a/.github/aw/review/ROUTING +++ b/.github/aw/review/ROUTING @@ -22,7 +22,12 @@ enable holistic,completeness,test-adequacy,first-principles,conventions,document # whole-change reviewers, not only the correctness pass. Graduate to # flip-gated once re-reviews here show scoped is overpaying (see # workflows/review/README.md for the dial). -re-review scoped +# +# blocking-only: repeat reviews keep the full scoped roster (blocking recall +# unchanged) but post only blocking findings inline; validated non-blocking +# findings collapse to one line each in the review body. First full reviews, +# tripwire re-arms, and guard-degraded full runs still post everything. +re-review scoped blocking-only # Shipped composite actions run inside consuming repos' CI with their credentials. actions/** tier=high diff --git a/.github/workflows/review.lock.yml b/.github/workflows/review.lock.yml index a1948d6e..f3afac38 100644 --- a/.github/workflows/review.lock.yml +++ b/.github/workflows/review.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"fde0e146255b3ab5e4e93a114db58f7b0833384c57f6a21b0a83c23ca59563d7","body_hash":"7919a80762428ac52f767f4b645e0f5f5fca8e7912bc5ef161a09b4392838cbb","compiler_version":"v0.83.4","strict":true,"agent_id":"claude","agent_model":"claude-opus-4-8","engine_versions":{"claude":"2.1.220"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"c718668e2aee2b35a49bb16375f3519bada2c914b4d68d94c0bfcd89bf83b1b6","body_hash":"6928f8872147abf6f16a03ff09be04e4312cc73533ea087ab9fbc811314b65ae","compiler_version":"v0.83.4","strict":true,"agent_id":"claude","agent_model":"claude-opus-4-8","engine_versions":{"claude":"2.1.220"}} # gh-aw-manifest: {"version":1,"secrets":["ANTHROPIC_API_KEY","COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN","KHAN_ACTIONS_BOT_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/checkout","sha":"93cb6efe18208431cddfb8368fd83d5badbf9bfd","version":"93cb6efe18208431cddfb8368fd83d5badbf9bfd"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"e89c65e17eb281bbd5ff2ff9e9199a03e96654c7","version":"v0.83.4"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.42","digest":"sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.42@sha256:26a8af4e5566485b02f52af59ee03803ae798271a9619d4767e94d07806deb9b"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42","digest":"sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.42@sha256:944f2686c9ab9bec338fd14b662461662f77cd12cd0ea8a3e7cb8c0987cd1607"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.42","digest":"sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.42@sha256:42dfeb649c680a8558cd5423dbc530b653a69413e35ffbe5e71da5d48c94bdf0"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.6","digest":"sha256:fecabec51bbc41f2ad61076d6bcd9a36ef23b142e672a444e054d37fc29de93c","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.6@sha256:fecabec51bbc41f2ad61076d6bcd9a36ef23b142e672a444e054d37fc29de93c"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748","pinned_image":"ghcr.io/github/gh-aw-node@sha256:a8082161d7dceda14b68f32eb39d0eaa96b825d07f5895b096afab9d9e0c7748"},{"image":"ghcr.io/github/github-mcp-server:v1.7.0","digest":"sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308","pinned_image":"ghcr.io/github/github-mcp-server:v1.7.0@sha256:c491ffdf6f4c85cb5397021bc655edb8ab825c6f5f568e7597d77a1bd7c4d308"}],"has_pull_request":true} # This file was automatically generated by gh-aw (v0.83.4). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -17,7 +17,7 @@ # \/ \/ \___/|_| |_|\_\|_| |_|\___/ \_/\_/ |___/ # # -# To update this file, edit Khan/actions/workflows/review/review.md@review-v1.12.0 and run: +# To update this file, edit Khan/actions/workflows/review/review.md@review-v1.13.0 and run: # gh aw compile # Not all edits will cause changes to this file. # @@ -25,7 +25,7 @@ # # Reviews PR code changes for correctness, conventions, and risk on every push. Leaves actionable per-line feedback, and on approval posts the risk summary and common patterns as a separate PR comment and requests the owning teams as reviewers. # -# Source: Khan/actions/workflows/review/review.md@review-v1.12.0 +# Source: Khan/actions/workflows/review/review.md@review-v1.13.0 # # Resolved workflow manifest: # Imports: @@ -142,7 +142,7 @@ jobs: GH_AW_INFO_AWF_VERSION: "v0.27.42" GH_AW_INFO_AWMG_VERSION: "" GH_AW_INFO_FIREWALL_TYPE: "squid" - GH_AW_INFO_FRONTMATTER_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.12.0" + GH_AW_INFO_FRONTMATTER_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.13.0" GH_AW_INFO_BODY_MODIFIED: "false" GH_AW_COMPILED_STRICT: "true" uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -536,7 +536,7 @@ jobs: with: path: gh-aw-review-lib persist-credentials: false - ref: review-v1.12.0 + ref: review-v1.13.0 repository: Khan/actions - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1322,8 +1322,8 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_NOOP_MAX: "1" GH_AW_WORKFLOW_NAME: "PR Reviewer" - GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.12.0" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.12.0/workflows/review/review.md" + GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.13.0" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.13.0/workflows/review/review.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} GH_AW_NOOP_REPORT_AS_ISSUE: "true" @@ -1344,8 +1344,8 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_WORKFLOW_NAME: "PR Reviewer" - GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.12.0" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.12.0/workflows/review/review.md" + GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.13.0" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.13.0/workflows/review/review.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} @@ -1363,8 +1363,8 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_MISSING_TOOL_CREATE_ISSUE: "true" GH_AW_WORKFLOW_NAME: "PR Reviewer" - GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.12.0" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.12.0/workflows/review/review.md" + GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.13.0" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.13.0/workflows/review/review.md" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1379,8 +1379,8 @@ jobs: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_REPORT_INCOMPLETE_CREATE_ISSUE: "true" GH_AW_WORKFLOW_NAME: "PR Reviewer" - GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.12.0" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.12.0/workflows/review/review.md" + GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.13.0" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.13.0/workflows/review/review.md" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1395,8 +1395,8 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_WORKFLOW_NAME: "PR Reviewer" - GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.12.0" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.12.0/workflows/review/review.md" + GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.13.0" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.13.0/workflows/review/review.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} GH_AW_WORKFLOW_ID: "review" @@ -1710,8 +1710,8 @@ jobs: GH_AW_THREAT_DETECTION_AIC: ${{ needs.detection.outputs.aic }} GH_AW_WORKFLOW_ID: "review" GH_AW_WORKFLOW_NAME: "PR Reviewer" - GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.12.0" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.12.0/workflows/review/review.md" + GH_AW_WORKFLOW_SOURCE: "Khan/actions/workflows/review/review.md@review-v1.13.0" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Khan/actions/blob/review-v1.13.0/workflows/review/review.md" outputs: add_reviewer_reviewers_added: ${{ steps.process_safe_outputs.outputs.reviewers_added }} code_push_failure_count: ${{ steps.process_safe_outputs.outputs.code_push_failure_count }} diff --git a/.github/workflows/review.md b/.github/workflows/review.md index d15ddca2..09b85181 100644 --- a/.github/workflows/review.md +++ b/.github/workflows/review.md @@ -244,7 +244,7 @@ pre-agent-steps: # `source:` below, so the prompt and the lib it invokes come from one version. # Even though this IS Khan/actions, the reviewer runs the released lib, not # the PR head; a PR must not be able to change the code that reviews it. - ref: review-v1.12.0 + ref: review-v1.13.0 path: gh-aw-review-lib persist-credentials: false @@ -336,7 +336,7 @@ max-daily-ai-credits: -1 max-ai-credits: 2500 env: REVIEW_MAX_AI_CREDITS: "2500" -source: Khan/actions/workflows/review/review.md@review-v1.12.0 +source: Khan/actions/workflows/review/review.md@review-v1.13.0 --- # PR Reviewer @@ -1574,8 +1574,11 @@ proximity: wrong, even when one calls it a wrong cap, one quotes the comment, and one cites a doc-comment convention: one rewritten comment satisfies all three. - **Group** across lines. A defect is routinely flagged at different anchors (the - function, its doc comment, its test), and the pipeline keeps one anchor. Distance in - the file is not evidence of two defects. + function, its doc comment, the call site below it), and the pipeline keeps one anchor. + Distance in the file is not evidence of two defects. (A twin anchored in another FILE + — e.g. the test in `_test.go` — stays ungrouped under the same-`path` rule below, + however clearly it describes the same defect; the pipeline prices that as a duplicate + comment, not a wrong merge.) - **Do NOT group** a bug and the missing test for that bug. "The cutoff subtracts months instead of days" and "no test asserts a stale entry is deleted" cite the same facts and need two different edits; they are two defects.