Repository navigation
wip: capture agent/migration-version-collision-fix (audit 2026-07-24..08-02) - #496
KooshaPari wants to merge 1 commit into
Conversation
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
|
Skipping CodeAnt AI review — this PR changes more than 100 files, which usually means a migration, codemod, or vendored drop. Line-level review on diffs this large produces duplicate findings on the same rewrite pattern and drowns out anything that actually matters. If you still want a review, comment |
|
Warning Review limit reached
Next review available in: 33 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
Note
|
|
Large PR Alert: This PR touches 496 files. Consider splitting into smaller PRs for easier review. |
Merge Protections🟢 Merge protection satisfied — ready to merge. Show 1 satisfied protection🟢 📃 Configuration Change RequirementsMergify configuration change
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 127f46d489
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| "/api/cli-tools/omp-settings", // spawns `which omp` to detect the CLI install (Hard Rules #15 + #17, #6318) | ||
| "/api/cli-tools/letta-settings", // spawns `which letta` to detect the CLI install (Hard Rules #15 + #17, #6318) |
There was a problem hiding this comment.
Add new CLI settings routes to the spawn deny-list
When these exact paths are added to LOCAL_ONLY_API_PREFIXES, they also need to be added to SPAWN_CAPABLE_PREFIXES. The settings validator only rejects manage-scope bypass prefixes that are present in that deny-list, so an operator can currently save localOnlyManageScopeBypassPrefixes: ["/api/cli-tools/omp-settings"] (or the Letta path), after which isLocalOnlyBypassableByManageScope() lets a non-loopback manage-scope request reach handlers that run which and write local CLI config. Add both new paths to the spawn-capable deny-list as well.
Useful? React with 👍 / 👎.
| }); | ||
| } catch (err) { | ||
| const error = err instanceof Error ? err : new Error(String(err)); | ||
| return errorResponse(500, `Translation request failed: ${error.message}`); |
There was a problem hiding this comment.
Sanitize translation handler failures
If multipart assembly or the upstream fetch throws here (for example due to DNS, TLS, or proxy errors), the handler returns error.message verbatim in the HTTP response body. The repo policy requires error responses to go through buildErrorBody() or sanitizeErrorMessage(), otherwise low-level provider/proxy details can leak to clients; sanitize the message before constructing the response.
AGENTS.md reference: AGENTS.md:L171-L171
Useful? React with 👍 / 👎.
|
@Mergifyio refresh |
✅ Pull request refreshed |
2121d09 to
7c4d22f
Compare
|
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
L17 Latency Budget ReportChecked against: budgets/rest-endpoints.yaml. |
L17 Latency Regression ReportThreshold: 10% p99 regression. |



Automated audit capture of local dirty state.
agent/migration-version-collision-fix