Skip to content

fix(deploy): recover webhook rollouts from checkout drift - #250

Closed
LucasSantana-Dev wants to merge 7 commits into
mainfrom
fix/deploy-checkout-hygiene
Closed

LucasSantana-Dev wants to merge 7 commits into
mainfrom
fix/deploy-checkout-hygiene

Conversation

@LucasSantana-Dev

@LucasSantana-Dev LucasSantana-Dev commented Mar 14, 2026 •

Copy link
Copy Markdown
Owner

Superseded by #251 — branch had unresolvable merge conflicts after #248 squash-merge. Fresh branch created from current main with all CodeRabbit fixes applied.

@netlify

netlify Bot commented Mar 14, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for regal-bunny-0c8efe ready!

Name Link
🔨 Latest commit 5aa2dd4
🔍 Latest deploy log https://app.netlify.com/projects/regal-bunny-0c8efe/deploys/69b63a8129b6870009e9adfe
😎 Deploy Preview https://deploy-preview-250--regal-bunny-0c8efe.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@vercel

vercel Bot commented Mar 14, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lucky Ready Ready Preview, Comment Mar 15, 2026 4:50am

Request Review

@coderabbitai

coderabbitai Bot commented Mar 14, 2026 •

Copy link
Copy Markdown
📝 Walkthrough

Walkthrough

Adds deploy-recovery skills and documentation; implements checkout-hygiene (archive + sync) and new error codes in scripts/deploy.sh; enhances webhook failure classification in .github/workflows/deploy.yml; tweaks policy helper to avoid adding repo-root env paths when repoRoot is missing or '/'.

Changes

Cohort / File(s) Summary
Recovery Skill Documentation
.cursor/skills/lucky-deploy-recovery/SKILL.md, .cursor/skills/lucky-ci-gate-recovery/SKILL.md
New guided Lucky Deploy recovery skill with triage commands, remediation, and rerun policy; CI-gate skill extended with deploy-checkout-drift failure bucket and remediation guidance.
Deployment Script Enhancements
scripts/deploy.sh
Added archive_local_checkout_state() and sync_checkout_to_origin_main(); replaced simple pull with stash/archive + fetch/reset/clean flow; introduced failure codes (CHECKOUT_RECOVERY_FAILED, CHECKOUT_FETCH_FAILED, MIGRATION_FAILED, RUNTIME_PRECHECK_FAILED, LOCK_CONTENTION) and updated logging/notifications.
CI/CD Workflow Updates
.github/workflows/deploy.yml
Post-call failure analysis: compacted webhook body and conditional classification branches for LOCK_CONTENTION, CHECKOUT_RECOVERY_FAILED, and RUNTIME_PRECHECK_FAILED; annotated failures include compacted body.
Policy Helper Change
.opencode/plugins/lucky-policy-lib.mjs
commandTouchesSensitivePath now only includes repoRoot-based env candidates when repoRoot is truthy and not '/'; prevents adding invalid root paths.
Hooks & Config
deploy/hooks.json
Replaced array with object and enabled include-command-output-in-response and ...-on-error flags (true).
Docs & Metadata
AGENTS.md, CHANGELOG.md, README.md
Registered new skill in AGENTS.md; documented checkout-hygiene, failure classification, and added deploy-recovery references in README and CHANGELOG.

Sequence Diagram

sequenceDiagram
    actor User
    participant GHA as "GitHub Actions"
    participant Script as "deploy.sh"
    participant Git as "Git / Origin"
    participant Host as "Homelab Host"
    participant Health as "Health Checks"

    User->>GHA: Trigger deploy webhook
    GHA->>Script: Execute deploy script
    Script->>Script: archive_local_checkout_state()
    Script->>Git: Fetch origin/main
    Script->>Git: Reset --hard origin/main
    Script->>Git: Clean -fd
    Script->>Script: Validate clean state

    alt Checkout Recovery Failed
        Script->>GHA: Notify CHECKOUT_RECOVERY_FAILED
        GHA->>GHA: Annotate failure (compact body)
    else Lock Contention
        Script->>GHA: Notify LOCK_CONTENTION
        GHA->>GHA: Annotate failure (compact body)
    else Runtime Precheck Failed
        Script->>GHA: Notify RUNTIME_PRECHECK_FAILED
        GHA->>GHA: Annotate failure (compact body)
    else Success
        Script->>Host: Pull images & start services
        Script->>Health: Run post-deploy health checks
        Health->>GHA: Report success
    end
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 2 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The PR title 'fix(deploy): recover webhook rollouts from checkout drift' directly and clearly summarizes the main change: adding checkout drift recovery to webhook deployments through archive+reset hygiene.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/deploy-checkout-hygiene
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot added the size/l label Mar 14, 2026
@sonarqubecloud

Copy link
Copy Markdown

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.opencode/plugins/lucky-policy-lib.mjs (1)

73-96: ⚠️ Potential issue | 🟡 Minor

Edge case: empty repoRoot produces root-relative paths.

When repoRoot is undefined or null, the template literals on lines 85-86 produce paths like /.env and /.cursor/.env.mcp. These are truthy strings that pass the .filter(Boolean) check, so the function will match commands containing /.env — which could produce false positives for commands operating on the filesystem root.

Consider guarding against this:

🛡️ Proposed fix
   const candidates = [
     '.env',
     '.cursor/.env.mcp',
     '~/.ssh/',
     '~/.aws/',
     '~/.config/fish/config.fish',
     '~/.local/share/opencode/auth.json',
-    `${repoRoot ?? ''}/.env`,
-    `${repoRoot ?? ''}/.cursor/.env.mcp`,
-  ].filter(Boolean)
+    ...(repoRoot ? [`${repoRoot}/.env`, `${repoRoot}/.cursor/.env.mcp`] : []),
+  ]
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In @.opencode/plugins/lucky-policy-lib.mjs around lines 73 - 96, The candidates
list in commandTouchesSensitivePath currently always adds template strings
`${repoRoot ?? ''}/.env` and `${repoRoot ?? ''}/.cursor/.env.mcp`, which produce
root-relative paths like "/.env" when repoRoot is null/undefined and cause false
positives; update the logic so those repoRoot-based entries are only added when
repoRoot is a non-empty, non-root string (e.g., typeof repoRoot === 'string' &&
repoRoot.trim() !== '' && repoRoot !== '/'), otherwise omit them — modify the
candidates array construction in commandTouchesSensitivePath to conditionally
push the `${repoRoot}/.env` and `${repoRoot}/.cursor/.env.mcp` entries only when
that guard passes.
🧹 Nitpick comments (1)
scripts/deploy.sh (1)

185-222: Well-structured archive function with good error handling.

The archive_local_checkout_state function properly:

  • Creates timestamped archives for forensic recovery
  • Captures multiple dimensions of checkout state (status, tracked, staged, untracked)
  • Handles the "no changes" case gracefully

One minor observation on the stash output check (line 215):

💡 Consider more robust stash output detection

The Saved* prefix check works for typical cases, but git stash output can vary by locale/version. A more defensive approach:

-    if [[ "$stash_output" != Saved* ]]; then
+    if ! git stash list | head -1 | grep -q "$stash_label"; then
         log "ERROR: CHECKOUT_RECOVERY_FAILED (stash failed: $stash_output)"
         return 1
     fi

However, the current approach is pragmatic and the error path captures the actual output for debugging.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@scripts/deploy.sh` around lines 185 - 222, The stash success check in
archive_local_checkout_state is brittle (it relies on stash_output starting with
"Saved"); instead, after running git stash push (stash_label/stash_output),
verify the stash was actually created by checking git stash list for the created
stash_label (e.g. run git stash list and grep -F "$stash_label" or use git stash
list --format to match the message), and use that result to decide
success/failure (replace the [[ "$stash_output" != Saved* ]] branch with a check
that the stash_label appears in git stash list and include stash_output in the
error log if not found).
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In @.github/workflows/deploy.yml:
- Around line 116-128: The webhook response body is always the static
"response-message": "Deploy triggered", so the failure classification in the
deploy workflow (the grep checks against failure_body_compact) never sees the
real deploy.sh output; update the webhook configuration entry in
deploy/hooks.json (the object that currently contains "response-message":
"Deploy triggered") to enable capturing command output on error (e.g., add
"capture-command-output-on-error": true or specify an "output-file" path) so
that deploy.sh stderr/stdout (or the specified output file) is returned as the
HTTP response body; also ensure deploy.sh writes its ERROR lines to stderr or to
the configured output file so the grep patterns (LOCK_CONTENTION,
CHECKOUT_RECOVERY_FAILED, RUNTIME_PRECHECK_FAILED) match the response.

---

Outside diff comments:
In @.opencode/plugins/lucky-policy-lib.mjs:
- Around line 73-96: The candidates list in commandTouchesSensitivePath
currently always adds template strings `${repoRoot ?? ''}/.env` and `${repoRoot
?? ''}/.cursor/.env.mcp`, which produce root-relative paths like "/.env" when
repoRoot is null/undefined and cause false positives; update the logic so those
repoRoot-based entries are only added when repoRoot is a non-empty, non-root
string (e.g., typeof repoRoot === 'string' && repoRoot.trim() !== '' && repoRoot
!== '/'), otherwise omit them — modify the candidates array construction in
commandTouchesSensitivePath to conditionally push the `${repoRoot}/.env` and
`${repoRoot}/.cursor/.env.mcp` entries only when that guard passes.

---

Nitpick comments:
In `@scripts/deploy.sh`:
- Around line 185-222: The stash success check in archive_local_checkout_state
is brittle (it relies on stash_output starting with "Saved"); instead, after
running git stash push (stash_label/stash_output), verify the stash was actually
created by checking git stash list for the created stash_label (e.g. run git
stash list and grep -F "$stash_label" or use git stash list --format to match
the message), and use that result to decide success/failure (replace the [[
"$stash_output" != Saved* ]] branch with a check that the stash_label appears in
git stash list and include stash_output in the error log if not found).

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: de665608-22f2-4c98-9846-219c273f69fe

📥 Commits

Reviewing files that changed from the base of the PR and between 8a2403d and aac28f9.

📒 Files selected for processing (8)
  • .cursor/skills/lucky-ci-gate-recovery/SKILL.md
  • .cursor/skills/lucky-deploy-recovery/SKILL.md
  • .github/workflows/deploy.yml
  • .opencode/plugins/lucky-policy-lib.mjs
  • AGENTS.md
  • CHANGELOG.md
  • README.md
  • scripts/deploy.sh
📜 Review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
  • GitHub Check: Quality Gates
  • GitHub Check: SonarCloud Scan
🧰 Additional context used
📓 Path-based instructions (13)
**/{.scripts,scripts}/**/*.{sh,bash,js,ts}

📄 CodeRabbit inference engine (.cursor/rules/scripts-terminal.mdc)

Use cross-platform deletion utilities instead of OS-specific rm -rf

Files:

  • scripts/deploy.sh
{scripts/**,packages/scripts/**}

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

Prefer packages/scripts or root scripts/ for one-off automation; avoid maintaining one-time scripts in the repository long term

Files:

  • scripts/deploy.sh
{**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}

📄 CodeRabbit inference engine (.cursor/rules/workflow.mdc)

{**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}: Use cross-platform environment handling in scripts, cross-platform deletion utilities instead of OS-specific commands, pass non-interactive flags (--yes, --ci) by default in automation, and avoid OS-specific commands
Ensure logs are stream-friendly (no pagers) in scripts; when a pager might be used, pipe to cat

Files:

  • scripts/deploy.sh
  • .github/workflows/deploy.yml
**/{.github/workflows,}/*.{yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)

**/{.github/workflows,}/*.{yml,yaml}: CI pipeline must include setup step (node install, environment)
CI pipeline must include lint step (TypeScript typecheck + linter)
CI pipeline must include build step (production build)
CI pipeline must include test step (unit + integration) with coverage report
CI pipeline must include quality step (static analysis, vulnerability scan)

Files:

  • .github/workflows/deploy.yml
**/{.github/workflows,dependabot.yml}/*.{yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)

Configure dependency update bot with PR templates and tests (recommended)

Files:

  • .github/workflows/deploy.yml
**/.github/workflows/*.{yml,yaml}

📄 CodeRabbit inference engine (.cursor/rules/ci-cd.mdc)

**/.github/workflows/*.{yml,yaml}: Configure SAST / secrets scan on PRs (recommended)
Publish artifacts only from protected pipeline steps

Files:

  • .github/workflows/deploy.yml
{jest.config.*,*.coverage.*,.nycrc*,nyc.config.*,coveragerc,.github/workflows/*.yml,.github/workflows/*.yaml}

📄 CodeRabbit inference engine (.cursor/rules/testing-quality.mdc)

Minimum recommended coverage threshold: 85% (raise per project risk)

Files:

  • .github/workflows/deploy.yml
{.github/workflows/*.{yml,yaml},*.github/workflows/*.{yml,yaml},.gitlab-ci.yml,.circleci/config.yml,bitbucket-pipelines.yml}

📄 CodeRabbit inference engine (.cursor/rules/testing-quality.mdc)

CI must run in order: lint → build → test → quality checks

Files:

  • .github/workflows/deploy.yml
{.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}

📄 CodeRabbit inference engine (.cursor/rules/workflow.mdc)

{.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}: CI/CD pipeline must include in order: Setup (Node install, env config) → Lint (TypeScript typecheck, linter) → Build (production build, artifacts) → Test (unit, integration, coverage) → Quality (static analysis, vulnerability scan)
Publish artifacts only from protected pipeline steps in CI/CD

Files:

  • .github/workflows/deploy.yml
{CHANGELOG.md,README.md}

📄 CodeRabbit inference engine (.cursor/rules/agent-rules.mdc)

ALWAYS update CHANGELOG.md and README.md as changes are made.

Files:

  • README.md
  • CHANGELOG.md
README.md

📄 CodeRabbit inference engine (.cursor/rules/templates-examples.mdc)

README.md must be updated if behavior changed

Update README.md if behavior changed

Files:

  • README.md
CHANGELOG.md

📄 CodeRabbit inference engine (.cursor/rules/templates-examples.mdc)

CHANGELOG.md must be updated with all changes in pull requests

Always update CHANGELOG.md with all code changes

Update CHANGELOG.md with all changes, include breaking changes documentation, and reference issues and PRs

Files:

  • CHANGELOG.md
{CHANGELOG.md,docs/**}

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

Update CHANGELOG.md and relevant docs/ files when behavior or setup changes

Files:

  • CHANGELOG.md
🧠 Learnings (19)
📚 Learning: 2026-03-09T20:22:25.255Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/workflow.mdc:0-0
Timestamp: 2026-03-09T20:22:25.255Z
Learning: Applies to {.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml} : CI/CD pipeline must include in order: Setup (Node install, env config) → Lint (TypeScript typecheck, linter) → Build (production build, artifacts) → Test (unit, integration, coverage) → Quality (static analysis, vulnerability scan)

Applied to files:

  • .cursor/skills/lucky-ci-gate-recovery/SKILL.md
  • AGENTS.md
📚 Learning: 2026-03-09T20:22:25.255Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/workflow.mdc:0-0
Timestamp: 2026-03-09T20:22:25.255Z
Learning: Applies to {.husky/**,**/.githooks/**,.pre-commit-config.yaml} : Run format → lint autofix → type-check → fast tests in pre-commit hooks before allowing commits

Applied to files:

  • .cursor/skills/lucky-ci-gate-recovery/SKILL.md
📚 Learning: 2026-03-09T20:21:31.459Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/quality.mdc:0-0
Timestamp: 2026-03-09T20:21:31.459Z
Learning: CI must run quality checks in order: lint → build → test → quality checks

Applied to files:

  • .cursor/skills/lucky-ci-gate-recovery/SKILL.md
📚 Learning: 2026-03-09T20:22:25.255Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/workflow.mdc:0-0
Timestamp: 2026-03-09T20:22:25.255Z
Learning: Use squash merge for small single-purpose PRs, rebase merge when preserving commits matters, and require CI pass + at least 1 reviewer for all merges to protected branches

Applied to files:

  • .cursor/skills/lucky-ci-gate-recovery/SKILL.md
📚 Learning: 2026-03-09T20:21:31.459Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/quality.mdc:0-0
Timestamp: 2026-03-09T20:21:31.459Z
Learning: Enforce pre-commit quality with format → lint autofix → type-check → fast tests

Applied to files:

  • .cursor/skills/lucky-ci-gate-recovery/SKILL.md
📚 Learning: 2026-03-09T20:21:46.291Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-data.mdc:0-0
Timestamp: 2026-03-09T20:21:46.291Z
Learning: Use `.cursor/skills/prisma-redis-lucky/SKILL.md` for Prisma schema, migrations, Redis client, and key patterns

Applied to files:

  • .cursor/skills/lucky-deploy-recovery/SKILL.md
  • AGENTS.md
📚 Learning: 2026-03-09T20:21:46.291Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-data.mdc:0-0
Timestamp: 2026-03-09T20:21:46.291Z
Learning: Use `npm run db:deploy` command from repo root for deploying migrations

Applied to files:

  • scripts/deploy.sh
📚 Learning: 2026-03-09T20:21:15.595Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-shared.mdc:0-0
Timestamp: 2026-03-09T20:21:15.595Z
Learning: Applies to packages/shared/**/*.ts : Use the single Prisma client located at `packages/shared/src/utils/database/prismaClient.ts`; maintain schema in repo root at `prisma/schema.prisma`; run migrations from root using `npm run db:migrate`

Applied to files:

  • scripts/deploy.sh
  • CHANGELOG.md
📚 Learning: 2026-03-09T20:21:46.291Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-data.mdc:0-0
Timestamp: 2026-03-09T20:21:46.291Z
Learning: Applies to prisma/migrations/**/* : Database migrations must be located in `prisma/migrations/`

Applied to files:

  • scripts/deploy.sh
📚 Learning: 2026-03-14T16:53:29.998Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T16:53:29.998Z
Learning: Use ecosystem skills from `.agent-skills/` for cross-cutting concerns: `systematic-debugging` for bugs/test failures, `test-driven-development` for features/bugfixes, `verification-before-completion` before marking work complete, `brainstorming` before new features, `requesting-code-review` before merging

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:20:23.892Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: CLAUDE.md:0-0
Timestamp: 2026-03-09T20:20:23.892Z
Learning: Use Conventional Commits format: feat, fix, refactor, chore, docs, style, ci, test

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:21:15.595Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-shared.mdc:0-0
Timestamp: 2026-03-09T20:21:15.595Z
Learning: Applies to packages/shared/**/*.ts : Organize the Lucky Shared Package with the following directory structure: Config in `packages/shared/src/config/` (environment, constants, feature toggles, YouTube config); Services in `packages/shared/src/services/` (DatabaseService, Redis client/operations, FeatureToggleService, ReactionRoles, RoleManagement); Types in `packages/shared/src/types/` (errors, commands, common, discord, music); Utils in `packages/shared/src/utils/` (error handling, retry, embeds, log, monitoring, composables, prismaClient)

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:21:52.065Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-discord.mdc:0-0
Timestamp: 2026-03-09T20:21:52.065Z
Learning: Applies to packages/bot/src/**/*.ts : Use `lucky/shared` for database, Redis, logging, and embed utilities instead of implementing them locally

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:20:32.245Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/documentation.mdc:0-0
Timestamp: 2026-03-09T20:20:32.245Z
Learning: Applies to README.md : Update README.md if behavior changed

Applied to files:

  • README.md
  • CHANGELOG.md
📚 Learning: 2026-03-14T16:53:29.998Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T16:53:29.998Z
Learning: Use the appropriate project skill from `.cursor/skills/` based on the task type (e.g., `discord-commands` for slash commands, `music-queue-player` for player operations, `prisma-redis-lucky` for schema/migrations)

Applied to files:

  • README.md
📚 Learning: 2026-03-09T20:22:25.255Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/workflow.mdc:0-0
Timestamp: 2026-03-09T20:22:25.255Z
Learning: Applies to {.github/workflows/**/*release*.{yml,yaml},.github/workflows/**/*changelog*.{yml,yaml},**/.gitlab-ci.yml} : Use automated or manual changelog flows driven from commit messages and tag releases with semantic versions

Applied to files:

  • CHANGELOG.md
📚 Learning: 2026-03-09T20:21:08.612Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.612Z
Learning: Applies to {CHANGELOG.md,docs/**} : Update `CHANGELOG.md` and relevant `docs/` files when behavior or setup changes

Applied to files:

  • CHANGELOG.md
📚 Learning: 2026-03-09T20:22:25.255Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/workflow.mdc:0-0
Timestamp: 2026-03-09T20:22:25.255Z
Learning: Applies to CHANGELOG.md : Update CHANGELOG.md with all changes, include breaking changes documentation, and reference issues and PRs

Applied to files:

  • CHANGELOG.md
📚 Learning: 2026-03-14T16:53:29.998Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T16:53:29.998Z
Learning: Update `CHANGELOG.md` and relevant `docs/` when behavior or setup changes

Applied to files:

  • CHANGELOG.md
🔇 Additional comments (7)
AGENTS.md (1)

38-38: LGTM!

The new skill entry for lucky-deploy-recovery is correctly added and properly aligned with the existing table format. This provides clear discoverability for the new deploy recovery workflow.

.cursor/skills/lucky-deploy-recovery/SKILL.md (1)

1-62: LGTM!

This new skill document provides comprehensive operational guidance for deploy recovery. The structure is well-organized with:

  • Clear trigger conditions for when to use
  • Properly categorized failure buckets matching the deploy script classifications
  • Actionable triage sequence with concrete commands
  • Sensible rerun policy preventing blind retry loops
README.md (1)

335-336: LGTM!

The README updates accurately document:

  1. The new deploy-recovery skill reference for incident triage
  2. The three-step checkout hygiene workflow (archive drift, stash for recovery, fetch/reset/clean)

This provides clear operational guidance aligned with the actual implementation.

Also applies to: 360-363

.cursor/skills/lucky-ci-gate-recovery/SKILL.md (1)

45-45: LGTM!

The CI gate recovery skill is properly extended with:

  • New deploy-checkout-drift failure bucket for classification
  • Clear remediation guidance (clean target host checkout before rerun)
  • Well-defined rerun policy distinguishing transient lock contention from persistent checkout issues

This complements the new deploy-recovery skill with consistent terminology and policy.

Also applies to: 53-53, 74-78

scripts/deploy.sh (2)

224-254: LGTM!

The sync_checkout_to_origin_main function implements a robust checkout synchronization with:

  • Proper sequencing: archive → fetch → reset → clean → verify
  • Distinct error codes for fetch vs recovery failures
  • Post-reset verification ensuring a truly clean tree

This deterministic approach eliminates the race conditions possible with git pull.


344-349: LGTM!

The integration point correctly:

  • Replaces the previous git pull approach with the new deterministic sync
  • Provides clear error logging on failure
  • Notifies via Discord webhook on checkout recovery failures
CHANGELOG.md (1)

15-23: LGTM!

The changelog entries accurately document all three aspects of this PR:

  1. The archive+reset hygiene workflow for checkout sync
  2. Failure classification in CI annotations (with the caveat noted in the deploy.yml review)
  3. New and expanded SKILL.md documentation

The entries follow the existing changelog format and provide clear descriptions.

Comment thread .github/workflows/deploy.yml
…bustify stash check

- lucky-policy-lib.mjs: add cwd+home params to commandTouchesSensitivePath,
  replace filter(Boolean) with conditional spread to prevent /.env false positive
  when repoRoot is null/undefined/root
- scripts/deploy.sh: replace brittle [[ stash_output != Saved* ]] with
  git stash list | grep -qF to reliably verify stash creation"
CodeRabbit review fix: the static "Deploy triggered" response body
prevented CI grep patterns (LOCK_CONTENTION, CHECKOUT_RECOVERY_FAILED,
RUNTIME_PRECHECK_FAILED) from ever matching. Enable command output
passthrough so deploy.yml failure classification actually works.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
scripts/deploy.sh (1)

202-205: Consider: Grouped error handling for archive writes.

If disk space exhausts mid-archive, partial files remain without clear indication. While set -e will exit on failure, the error message won't indicate which specific write failed.

This is a minor resilience improvement—the current approach is functional.

♻️ Optional: Add grouped error handling
-    git status --short >"${archive_prefix}-status.txt"
-    git diff >"${archive_prefix}-tracked.diff"
-    git diff --cached >"${archive_prefix}-staged.diff"
-    git ls-files --others --exclude-standard >"${archive_prefix}-untracked.txt"
+    if ! {
+        git status --short >"${archive_prefix}-status.txt" &&
+        git diff >"${archive_prefix}-tracked.diff" &&
+        git diff --cached >"${archive_prefix}-staged.diff" &&
+        git ls-files --others --exclude-standard >"${archive_prefix}-untracked.txt"
+    }; then
+        log "WARN: Partial archive at ${archive_prefix}-* (write failed)"
+    fi
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@scripts/deploy.sh` around lines 202 - 205, Wrap each redirected git command
(git status --short >"${archive_prefix}-status.txt", git diff
>"${archive_prefix}-tracked.diff", git diff --cached
>"${archive_prefix}-staged.diff", git ls-files --others --exclude-standard
>"${archive_prefix}-untracked.txt") with explicit error handling so failures
produce a clear message and clean up partial files: implement a small helper
(e.g. write_or_fail) that runs the git command, checks its exit status, echoes
"Failed writing <target-file> from <git-command>" on error, removes the
incomplete "${archive_prefix}-*.txt/.diff" that were created, and exits
non‑zero; call that helper for each of the four commands (or inline the same ||
{ echo ...; rm ...; exit 1; } checks) so you get an explicit, file-specific
error instead of relying solely on set -e.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Nitpick comments:
In `@scripts/deploy.sh`:
- Around line 202-205: Wrap each redirected git command (git status --short
>"${archive_prefix}-status.txt", git diff >"${archive_prefix}-tracked.diff", git
diff --cached >"${archive_prefix}-staged.diff", git ls-files --others
--exclude-standard >"${archive_prefix}-untracked.txt") with explicit error
handling so failures produce a clear message and clean up partial files:
implement a small helper (e.g. write_or_fail) that runs the git command, checks
its exit status, echoes "Failed writing <target-file> from <git-command>" on
error, removes the incomplete "${archive_prefix}-*.txt/.diff" that were created,
and exits non‑zero; call that helper for each of the four commands (or inline
the same || { echo ...; rm ...; exit 1; } checks) so you get an explicit,
file-specific error instead of relying solely on set -e.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: b79dd57d-c989-4378-adb2-121eedd7affb

📥 Commits

Reviewing files that changed from the base of the PR and between aac28f9 and 2357f5f.

📒 Files selected for processing (2)
  • .opencode/plugins/lucky-policy-lib.mjs
  • scripts/deploy.sh
📜 Review details
🧰 Additional context used
📓 Path-based instructions (4)
{opencode.jsonc,.opencode/**}

📄 CodeRabbit inference engine (AGENTS.md)

Repo-local OpenCode behavior lives in opencode.jsonc, .opencode/plugins, and .opencode/skills

Files:

  • .opencode/plugins/lucky-policy-lib.mjs
**/{.scripts,scripts}/**/*.{sh,bash,js,ts}

📄 CodeRabbit inference engine (.cursor/rules/scripts-terminal.mdc)

Use cross-platform deletion utilities instead of OS-specific rm -rf

Files:

  • scripts/deploy.sh
{scripts/**,packages/scripts/**}

📄 CodeRabbit inference engine (.cursor/rules/lucky-project.mdc)

Prefer packages/scripts or root scripts/ for one-off automation; avoid maintaining one-time scripts in the repository long term

Files:

  • scripts/deploy.sh
{**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}

📄 CodeRabbit inference engine (.cursor/rules/workflow.mdc)

{**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml}: Use cross-platform environment handling in scripts, cross-platform deletion utilities instead of OS-specific commands, pass non-interactive flags (--yes, --ci) by default in automation, and avoid OS-specific commands
Ensure logs are stream-friendly (no pagers) in scripts; when a pager might be used, pipe to cat

Files:

  • scripts/deploy.sh
🧠 Learnings (8)
📓 Common learnings
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `lucky-deploy-recovery` skill when workflow is green but production is stale with deploy drift
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `lucky-ci-gate-recovery` skill for CI gate triage and required-check recovery
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/workflow.mdc:0-0
Timestamp: 2026-03-09T20:22:25.255Z
Learning: Applies to {**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml} : Use cross-platform environment handling in scripts, cross-platform deletion utilities instead of OS-specific commands, pass non-interactive flags (--yes, --ci) by default in automation, and avoid OS-specific commands
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use `scripts/opencode-sync-project-skills.sh` after changing project skills or OpenCode skill bridges
📚 Learning: 2026-03-09T20:20:38.694Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-backend-api.mdc:0-0
Timestamp: 2026-03-09T20:20:38.694Z
Learning: Applies to packages/backend/src/**/*.{ts,tsx} : Use shared config and env from `lucky/shared` when needed; avoid duplicating env parsing in backend code

Applied to files:

  • .opencode/plugins/lucky-policy-lib.mjs
📚 Learning: 2026-03-09T20:22:25.255Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/workflow.mdc:0-0
Timestamp: 2026-03-09T20:22:25.255Z
Learning: Applies to {.husky/**,**/.githooks/**,.pre-commit-config.yaml} : Enforce conventional commit message format through pre-commit hooks before allowing commits

Applied to files:

  • scripts/deploy.sh
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `database-migration` ecosystem skill for Prisma schema changes and migrations

Applied to files:

  • scripts/deploy.sh
📚 Learning: 2026-03-09T20:21:46.291Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-data.mdc:0-0
Timestamp: 2026-03-09T20:21:46.291Z
Learning: Use `npm run db:deploy` command from repo root for deploying migrations

Applied to files:

  • scripts/deploy.sh
📚 Learning: 2026-03-09T20:21:15.595Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-shared.mdc:0-0
Timestamp: 2026-03-09T20:21:15.595Z
Learning: Applies to packages/shared/**/*.ts : Use the single Prisma client located at `packages/shared/src/utils/database/prismaClient.ts`; maintain schema in repo root at `prisma/schema.prisma`; run migrations from root using `npm run db:migrate`

Applied to files:

  • scripts/deploy.sh
📚 Learning: 2026-03-09T20:21:46.291Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-data.mdc:0-0
Timestamp: 2026-03-09T20:21:46.291Z
Learning: Applies to prisma/migrations/**/* : Database migrations must be located in `prisma/migrations/`

Applied to files:

  • scripts/deploy.sh
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use `npm run db:generate`, `npm run db:migrate`, `npm run db:deploy`, or `npm run db:studio` for database operations

Applied to files:

  • scripts/deploy.sh
🔇 Additional comments (8)
.opencode/plugins/lucky-policy-lib.mjs (1)

85-86: Nice fix for repo-root candidate guarding.

This avoids generating invalid sensitive-path probes when repoRoot is empty or /, reducing false positives in command checks.

scripts/deploy.sh (7)

90-90: LGTM - Display format improvement.

The change to use single quotes around the commit SHA in Discord notifications is cleaner.


185-222: Well-designed drift capture with robust stash verification.

The function correctly handles:

  • Early return on clean checkouts
  • Archive directory creation failure
  • Stash edge cases (changes disappearing, stash failures)

The use of git stash list | grep -qF "$stash_label" at line 215 is more reliable than string matching on stash output—good improvement.


224-254: Solid deterministic sync workflow.

The function properly:

  1. Archives drift before destructive operations
  2. Uses distinct error codes (CHECKOUT_FETCH_FAILED vs CHECKOUT_RECOVERY_FAILED)
  3. Verifies clean state post-reset—important safeguard

The git clean -fd is appropriate here as a git-native cross-platform command.


344-349: LGTM - Clean integration of deterministic sync.

The replacement of git pull with the new sync_checkout_to_origin_main function properly handles failure with consistent error classification and notification.


318-318: LGTM - Standardized error classification.

The LOCK_CONTENTION, MIGRATION_FAILED, CHECKOUT_RECOVERY_FAILED, and RUNTIME_PRECHECK_FAILED codes enable reliable webhook failure classification as mentioned in the PR objectives.


366-377: LGTM - Migration error classification.

Both prisma migrate deploy and prisma migrate status failures are correctly tagged with MIGRATION_FAILED for consistent classification.


397-400: LGTM - Runtime precheck classification.

Database relation guard failures correctly use RUNTIME_PRECHECK_FAILED to distinguish from migration issues.

@sonarqubecloud

Copy link
Copy Markdown

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@README.md`:
- Around line 337-339: The README asserts that mcp-github-recovery has replaced
`@modelcontextprotocol/server-github` with the github-mcp-server binary, but the
skill still contains wrapper-based calls (e.g., npx
`@modelcontextprotocol/server-github`) and gh auth token wrapper logic; either
update the skill code to replace usages of `@modelcontextprotocol/server-github`
with github-mcp-server and align Codex/OpenCode/Cursor wrappers to use gh auth
token with env fallback, or soften the README sentence to a non-assertive
statement (e.g., "can be configured to use" or "is being updated to use") so it
no longer directs operators to nonexistent behavior; search for
mcp-github-recovery, `@modelcontextprotocol/server-github`, github-mcp-server, and
wrapper calls to make the change.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 5cf6d922-11db-4d97-8a18-1f6ed52c4ede

📥 Commits

Reviewing files that changed from the base of the PR and between 2357f5f and 5aa2dd4.

📒 Files selected for processing (4)
  • AGENTS.md
  • CHANGELOG.md
  • README.md
  • deploy/hooks.json
📜 Review details
🧰 Additional context used
📓 Path-based instructions (2)
{CHANGELOG.md,README.md}

📄 CodeRabbit inference engine (.cursor/rules/agent-rules.mdc)

ALWAYS update CHANGELOG.md and README.md as changes are made.

Files:

  • README.md
README.md

📄 CodeRabbit inference engine (.cursor/rules/templates-examples.mdc)

README.md must be updated if behavior changed

Update README.md if behavior changed

Files:

  • README.md
🧠 Learnings (41)
📓 Common learnings
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `lucky-deploy-recovery` skill when workflow is green but production is stale with deploy drift
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `lucky-ci-gate-recovery` skill for CI gate triage and required-check recovery
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/workflow.mdc:0-0
Timestamp: 2026-03-09T20:22:25.255Z
Learning: Applies to {**/scripts/**,scripts/**,.github/workflows/**/*.{yml,yaml},**/.gitlab-ci.yml,.circleci/config.yml} : Use cross-platform environment handling in scripts, cross-platform deletion utilities instead of OS-specific commands, pass non-interactive flags (--yes, --ci) by default in automation, and avoid OS-specific commands
📚 Learning: 2026-03-09T20:20:32.245Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/documentation.mdc:0-0
Timestamp: 2026-03-09T20:20:32.245Z
Learning: Applies to README.md : Update README.md if behavior changed

Applied to files:

  • AGENTS.md
  • README.md
📚 Learning: 2026-03-09T20:21:52.065Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-discord.mdc:0-0
Timestamp: 2026-03-09T20:21:52.065Z
Learning: Applies to packages/bot/src/functions/{general,music,download}/commands/**/*.ts : Use `.cursor/skills/discord-commands/SKILL.md` for implementing slash commands

Applied to files:

  • AGENTS.md
  • README.md
📚 Learning: 2026-03-09T20:21:46.291Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-data.mdc:0-0
Timestamp: 2026-03-09T20:21:46.291Z
Learning: Use `.cursor/skills/prisma-redis-lucky/SKILL.md` for Prisma schema, migrations, Redis client, and key patterns

Applied to files:

  • AGENTS.md
  • README.md
📚 Learning: 2026-03-09T20:21:38.098Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-backend.mdc:0-0
Timestamp: 2026-03-09T20:21:38.098Z
Learning: Applies to packages/backend/**/*.ts : Use `.cursor/skills/backend-express/SKILL.md` for Express routes, middleware, and services when acting as backend specialist

Applied to files:

  • AGENTS.md
  • README.md
📚 Learning: 2026-03-09T20:21:52.065Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-discord.mdc:0-0
Timestamp: 2026-03-09T20:21:52.065Z
Learning: Applies to packages/bot/src/functions/music/commands/**/*.ts : Use `.cursor/skills/music-queue-player/SKILL.md` for play, queue, skip, volume commands and player lifecycle management

Applied to files:

  • AGENTS.md
  • README.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `discord-commands` skill when adding or changing slash commands

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:21:38.098Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-backend.mdc:0-0
Timestamp: 2026-03-09T20:21:38.098Z
Learning: Prefer **user-Context7** MCP for Express, Node, TypeScript tasks when acting as backend specialist

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `opencode-lucky-workflows` skill for OpenCode config, plugins, attach, and verification

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `mcp-docs-search` skill for docs lookup, web search, and MCP usage

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `prisma-redis-lucky` skill for schema, migrations, and DB/Redis operations in shared package

Applied to files:

  • AGENTS.md
  • README.md
📚 Learning: 2026-03-09T20:21:52.065Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-discord.mdc:0-0
Timestamp: 2026-03-09T20:21:52.065Z
Learning: Applies to packages/bot/src/functions/{general,music,download}/commands/**/*.ts : Apply `.cursor/rules/lucky-discord-bot.mdc` rules for Discord bot commands and player implementation

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:21:46.291Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-data.mdc:0-0
Timestamp: 2026-03-09T20:21:46.291Z
Learning: Prefer **user-Context7** MCP for Prisma, Redis, Node work; use **user-sequential-thinking** MCP for migration or key-design decisions

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:21:38.098Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-backend.mdc:0-0
Timestamp: 2026-03-09T20:21:38.098Z
Learning: Prefer **user-sequential-thinking** MCP for multi-step API or auth design when acting as backend specialist

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Prefer the smallest change that solves the problem; avoid refactoring unrelated code or adding abstractions 'for the future'

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:21:08.612Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.612Z
Learning: Applies to **/*.{js,ts,tsx,jsx} : Avoid redundant or decorative AI comments; code should be self-explanatory and only commented when logic is non-obvious; prefer refactoring over lengthy comments

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Applies to **/*.{js,ts,tsx,jsx} : Avoid redundant or decorative AI comments; code should be clear from names and structure; comment only when logic is non-obvious

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:20:32.245Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/documentation.mdc:0-0
Timestamp: 2026-03-09T20:20:32.245Z
Learning: Applies to **/*.{js,ts,tsx,jsx} : Minimize comments in code; explain the 'why' when non-obvious, let code express the 'what' through clear naming

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:22:09.954Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/typescript.mdc:0-0
Timestamp: 2026-03-09T20:22:09.954Z
Learning: Applies to **/*.{ts,tsx,js,jsx} : Avoid commenting code unless extremely necessary - code should explain itself with descriptive names

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Applies to **/*.{js,ts,tsx,jsx} : No hardcoded secrets, IPs, or ports in code; use `.env` and `docs/` for required environment variables

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:22:09.954Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/typescript.mdc:0-0
Timestamp: 2026-03-09T20:22:09.954Z
Learning: Applies to **/*.{ts,tsx,js,jsx} : Leave NO todos, placeholders or missing pieces in the code

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Applies to {opencode.jsonc,.opencode/**} : Repo-local OpenCode behavior lives in `opencode.jsonc`, `.opencode/plugins`, and `.opencode/skills`

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use `scripts/opencode-sync-project-skills.sh` after changing project skills or OpenCode skill bridges

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use Docker for local development when available via `docker-compose.dev.yml`

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:21:08.612Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.612Z
Learning: Applies to docker-compose.dev.yml : Use Docker for local environment setup when available via `docker-compose.dev.yml`

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `lucky-docker-dev` skill for Docker compose and local run tasks

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use `scripts/opencode-verify.sh` after OpenCode config/plugin changes

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use `scripts/opencode-install-community-plugins.sh` to prime approved OpenCode community add-ons locally or on `server-do-luk`

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Prefer scripts in `scripts/` for documented operations

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-09T20:21:08.612Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-project.mdc:0-0
Timestamp: 2026-03-09T20:21:08.612Z
Learning: Applies to {scripts/**,packages/scripts/**} : Prefer `packages/scripts` or root `scripts/` for one-off automation; avoid maintaining one-time scripts in the repository long term

Applied to files:

  • AGENTS.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `mcp-github-recovery` skill to recover GitHub MCP transport/auth failures

Applied to files:

  • README.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `lucky-ci-gate-recovery` skill for CI gate triage and required-check recovery

Applied to files:

  • README.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `frontend-react-vite` skill for React, Vite, and Tailwind frontend work

Applied to files:

  • README.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `lucky-deploy-recovery` skill when workflow is green but production is stale with deploy drift

Applied to files:

  • README.md
📚 Learning: 2026-03-09T20:21:58.991Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-frontend.mdc:0-0
Timestamp: 2026-03-09T20:21:58.991Z
Learning: Use `.cursor/skills/frontend-react-vite/SKILL.md` for React, Vite, and Tailwind patterns and paths

Applied to files:

  • README.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `vercel-react-best-practices` ecosystem skill for React components, performance, and bundle size

Applied to files:

  • README.md
📚 Learning: 2026-03-09T20:21:58.991Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-frontend.mdc:0-0
Timestamp: 2026-03-09T20:21:58.991Z
Learning: Prefer user-Context7 for React, Vite, Tailwind, and TypeScript documentation; use user-browser-tools or cursor-ide-browser for E2E testing; use user-v0 or user-magicuidesign/mcp for UI ideas only

Applied to files:

  • README.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `testing-lucky` skill for unit tests, Jest ESM mocks, and fixing disabled tests

Applied to files:

  • README.md
📚 Learning: 2026-03-09T20:21:38.098Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/subagent-backend.mdc:0-0
Timestamp: 2026-03-09T20:21:38.098Z
Learning: Applies to packages/backend/**/*.ts : Use `lucky/shared` for config and DB/Redis when needed in backend code

Applied to files:

  • README.md
📚 Learning: 2026-03-09T20:20:38.694Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: .cursor/rules/lucky-backend-api.mdc:0-0
Timestamp: 2026-03-09T20:20:38.694Z
Learning: Applies to packages/backend/src/**/*.{ts,tsx} : Use shared config and env from `lucky/shared` when needed; avoid duplicating env parsing in backend code

Applied to files:

  • README.md
📚 Learning: 2026-03-14T23:37:46.576Z
Learnt from: CR
Repo: LucasSantana-Dev/Lucky PR: 0
File: AGENTS.md:0-0
Timestamp: 2026-03-14T23:37:46.576Z
Learning: Use the `music-queue-player` skill for play, queue, skip, volume, and player lifecycle tasks

Applied to files:

  • README.md
🔇 Additional comments (4)
README.md (1)

389-391: Good docs alignment for deploy recovery + operator diagnostics.

These additions improve incident triage discoverability and make /music health operational output expectations clearer.

Based on learnings: "Use the lucky-deploy-recovery skill when workflow is green but production is stale with deploy drift"

Also applies to: 500-502

AGENTS.md (1)

23-40: Looks good — skill routing and agent guidance are clearer.

The new deploy-drift skill mapping and wording cleanups are coherent and actionable.

Based on learnings: "Use the lucky-deploy-recovery skill when workflow is green but production is stale with deploy drift" and "Use the lucky-ci-gate-recovery skill for CI gate triage and required-check recovery"

Also applies to: 98-98, 102-102, 131-131

deploy/hooks.json (2)

6-7: Security: Command output exposure in HTTP responses.

Enabling include-command-output-in-response and include-command-output-in-response-on-error will return full deploy script output in webhook responses. This is intentional for failure-pattern matching, but could leak sensitive information (internal paths, git output, environment details, error messages) if the webhook endpoint is accessible to untrusted parties.

Verify that:

  1. The webhook endpoint requires authentication before reaching this hook.
  2. The script output is sanitized or the endpoint is network-restricted.

[raise_major_issue, request_verification]

#!/bin/bash
# Description: Check if deploy.sh validates the webhook secret before executing sensitive operations

# Search for secret validation logic in deploy.sh
rg -n -C5 'X-Webhook-Secret|WEBHOOK_SECRET|secret' scripts/deploy.sh

# Check for any authentication/validation at the start of deploy.sh
head -50 scripts/deploy.sh

8-8: Webhook secret validation is already implemented.

The deploy.sh script properly validates the X-Webhook-Secret argument at lines 307-314: it checks that DEPLOY_WEBHOOK_SECRET is configured, compares the received secret against the expected value, and exits with code 1 if validation fails. This prevents any deployment operations from proceeding if the secret is invalid or missing.

			> Likely an incorrect or invalid review comment.

Comment thread README.md
Comment on lines +337 to +339
That runbook now replaces the deprecated `@modelcontextprotocol/server-github`
runtime with the official `github-mcp-server` binary and aligns Codex,
OpenCode, and Cursor wrappers around `gh auth token` with env fallback.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major

README claim conflicts with the current recovery runbook implementation.

This states the mcp-github-recovery runbook already replaced @modelcontextprotocol/server-github, but the referenced skill still shows wrapper-based npx @modelcontextprotocol/server-github`` commands. Please either update the skill file in this PR or soften this README statement to avoid incorrect operator guidance.

📝 Suggested README-only correction (if skill update is deferred)
-That runbook now replaces the deprecated `@modelcontextprotocol/server-github`
-runtime with the official `github-mcp-server` binary and aligns Codex,
-OpenCode, and Cursor wrappers around `gh auth token` with env fallback.
+That runbook documents migration from deprecated
+`@modelcontextprotocol/server-github` usage to the official
+`github-mcp-server` binary, with Codex/OpenCode/Cursor auth sourced from
+`gh auth token` (with env fallback).
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
That runbook now replaces the deprecated `@modelcontextprotocol/server-github`
runtime with the official `github-mcp-server` binary and aligns Codex,
OpenCode, and Cursor wrappers around `gh auth token` with env fallback.
That runbook documents migration from deprecated
`@modelcontextprotocol/server-github` usage to the official
`github-mcp-server` binary, with Codex/OpenCode/Cursor auth sourced from
`gh auth token` (with env fallback).
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@README.md` around lines 337 - 339, The README asserts that
mcp-github-recovery has replaced `@modelcontextprotocol/server-github` with the
github-mcp-server binary, but the skill still contains wrapper-based calls
(e.g., npx `@modelcontextprotocol/server-github`) and gh auth token wrapper logic;
either update the skill code to replace usages of
`@modelcontextprotocol/server-github` with github-mcp-server and align
Codex/OpenCode/Cursor wrappers to use gh auth token with env fallback, or soften
the README sentence to a non-assertive statement (e.g., "can be configured to
use" or "is being updated to use") so it no longer directs operators to
nonexistent behavior; search for mcp-github-recovery,
`@modelcontextprotocol/server-github`, github-mcp-server, and wrapper calls to
make the change.

This branch was successfully deployed

1 active deployment
Preview — 5aa2dd40 Deployed Mar 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant