Repository navigation
ci: extend workflow triggers to release/** branches - #816
Conversation
* fix(player): harden stream bridge error handling - soundcloudMatcher: wrap playdl.stream() in try/catch so auth failures and rate limits surface with context instead of propagating as raw rejections - streamBridge: call proc.kill() in the error handler so the yt-dlp subprocess is cleaned up on spawn errors, not only on timeout - playerFactory: fix priority comment — play-dl SoundCloud init runs before YouTube extractor registration, not after * test(player): add streamBridge and soundcloudMatcher test suites streamBridge.spec.ts (28 tests): - URL validation: allowlist, https-only, ytsearch bypass - Process lifecycle: stdout resolve, error+kill, exit code with stderr, timeout+kill - streamViaYtDlpSearch: empty query guard, ytsearch1 prefix - createResilientStream: full fallback chain, circuit breaker, parenthetical stripping soundcloudMatcher.spec.ts (29 tests): - parseDurationString: MM:SS, HH:MM:SS, edge cases, invalid formats - findMatchingSoundCloudResult: 75% token threshold, duration ±30s boundary, punctuation normalization, case-insensitive, empty query handling - streamViaSoundCloud: empty query, no results, validation miss, happy path, playdl.stream error wrapping with context Also improve replenishQueue error messages in queueHandlers.ts to include actionable recovery steps for the user.
Ensures CI, SonarCloud, bundle-size, and path-portability run on PRs targeting and pushes to any release/vX.Y.Z branch. deploy.yml and docker-publish.yml remain main-only. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Warning Rate limit exceeded
To continue reviewing without waiting, purchase usage credits in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThis PR adds a backend GET /invite redirect route with UTM extraction and logging, integrates Spotify saved tracks into user seeds (new API + tests), introduces a pr-agent GitHub Actions workflow and adjusts a CI security step, updates README invite/branding, and hardens a stream test timing assertion. ChangesInvite Route Feature
Spotify Saved Tracks Integration
CI / Workflow Infrastructure
README Updates
Misc Tests & Fixes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
- Add pr-agent.yml workflow: AI-powered code review on every PR using Anthropic claude-sonnet-4-6 backend via Codium-ai/pr-agent action. Auto-describes, auto-reviews, and auto-improves PRs on open/reopen. Requires ANTHROPIC_API_KEY secret. - Add Socket.dev supply chain scan step to existing security job. Detects malicious packages, typosquats, and supply chain attacks. Requires SOCKET_SECURITY_API_KEY secret (continue-on-error until secret is wired). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Adds a public /invite redirect route that logs utm_source, utm_medium, utm_campaign, and utm_content before forwarding to the Discord OAuth URL. Updates README subtitle and "Why Lucky?" to lead with shutdown-proof positioning (Groovy/Rythm/Hydra narrative). Swaps all three bare Discord OAuth invite URLs in README for tracked lucky.lucassantana.tech/invite URLs. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- pr-agent.yml: OPENAI.API_VERSION → OPENAI.MODEL (was passing model name as API version, causing PR-Agent to fail/fall back to default model) - streamBridge.spec.ts: emit error synchronously so proc.kill() assertion runs after the handler fires, not before the setImmediate callback Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…R blocking Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Greptile Summary
Confidence Score: 5/5Safe to merge — only P2 findings present; no runtime correctness or security regressions introduced. All findings are P2 (style/best-practice). The one substantive concern — packages/bot/src/spotify/spotifyUserSeeds.ts — extra Spotify API call for unused Important Files Changed
Reviews (5): Last reviewed commit: "ci: replace unavailable SocketDev action..." | Re-trigger Greptile |
- spotifyApi.ts: add getUserSavedTracks() — fetches up to 50 liked tracks via /v1/me/tracks, returns string[] of track IDs - spotifyUserSeeds.ts: add likedTrackIds field to UserSpotifySeeds and populate it by calling getUserSavedTracks on each seed fetch - spotifyUserSeeds.spec.ts: fix beforeEach to re-set getUserSavedTracks mock after jest.clearAllMocks() wipes factory-level mockResolvedValue Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- Add rate limiting (apiLimiter) to /invite endpoint - Normalize req.query UTM values to string | undefined (guards against array/ParsedQs) - Wrap infoLog in try/catch so logging failure doesn't block redirect - Add invite.test.ts (6 tests: redirect, UTM logging, array coercion, logging failure, no open-redirect) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…ked to block Spanish gospel When Last.fm is absent, candidateTags is always [] so the cross-locale veto only has text-based signals. Spanish gospel artists (Marcos Witt, Alex Zurdo, Christine D'Clario) carry no Spanish text markers in title/author but Spotify classifies them as 'musica cristiana', 'latin gospel', 'latin worship'. - spotifyRecommender: fall back to getArtistGenres(token, author) when lastFmTags.length === 0; skip if Last.fm returns tags (no double-fetch) - languageHeuristics: add 'latin worship', 'ccm en español', 'spanish ccm' to SPANISH_GENRE_MARKERS; add 'eres', 'nuestro/a', 'siervo/a', 'digno', 'fuego', 'cielos' to SPANISH_DISTINCT_TOKENS - spotifyRecommender.spec: wire getArtistGenresMock; add two tests covering the fallback path and the no-double-fetch guarantee Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
… not linked to block Spanish gospel" This reverts commit 94b498d.
- invite.ts: replace bare catch{} with logAndSwallow() per error-handling guidelines
- pr-agent.yml: gate issue_comment trigger to PRs only to avoid running on plain issue comments
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
- spotifyApi: add warnLog when saved-tracks fetch returns non-ok status
- spotifyUserSeeds: isolate getUserSavedTracks rejection with .catch([]){} so a
network failure doesn't collapse the entire seeds fetch into null
- spotifyUserSeeds.spec: test that seeds resolve normally when getUserSavedTracks rejects
- pr-agent.yml: pin Codium-ai/pr-agent to SHA instead of floating @main
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
Actionable comments posted: 2
🧹 Nitpick comments (1)
packages/bot/src/spotify/spotifyUserSeeds.spec.ts (1)
64-85: ⚡ Quick winAlso assert saved-tracks API call shape/count in the new happy-path test.
This test validates output, but not that
getUserSavedTracksis called correctly (and only once). Adding that assertion would better protect the new integration path and cache behavior.Suggested assertion add-on
it('should populate likedTrackIds when getUserSavedTracks returns data', async () => { @@ const result = await getUserSpotifySeeds('test-user-id') expect(result?.likedTrackIds).toEqual(['liked-1', 'liked-2']) + expect(spotifyApi.getUserSavedTracks).toHaveBeenCalledTimes(1) + expect(spotifyApi.getUserSavedTracks).toHaveBeenCalledWith('token') })🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@packages/bot/src/spotify/spotifyUserSeeds.spec.ts` around lines 64 - 85, The test asserts the returned likedTrackIds but doesn't verify that spotifyApi.getUserSavedTracks was invoked correctly and only once; update the test that calls getUserSpotifySeeds('test-user-id') to also assert spotifyApi.getUserSavedTracks was called exactly once and with the expected argument(s) (e.g., the valid access token returned by spotifyLinkService.getValidAccessToken or the spotifyId from mockLink depending on how getUserSavedTracks is invoked in getUserSpotifySeeds), using toHaveBeenCalledTimes(1) and toHaveBeenCalledWith(...) to lock down the call shape/count.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/ci.yml:
- Around line 97-99: The step named "Socket.dev supply chain scan" currently
only echoes a message and performs no scan; replace the no-op with a real
Socket.dev action invocation or explicitly mark it as informational. Either (A)
restore or add the actual action invocation (e.g., use the official SocketDev
action reference instead of the echo) so the job performs the supply-chain scan,
or (B) rename the step to something like "Notice: Socket.dev scan skipped" and
update branch protection/enforcement elsewhere; target the step with the name
"Socket.dev supply chain scan" and remove the commented-out
"SocketDev/socket-security-action@v1" placeholder or replace it with the correct
action entry.
In @.github/workflows/pr-agent.yml:
- Line 21: The job trigger condition allows non-bot users to run the workflow on
issue_comment events while the job has write permissions and secrets; update the
conditional that uses github.event.sender.type and github.event_name so that for
issue_comment events you also require a trusted commenter by checking
github.event.comment.author_association is one of OWNER, MEMBER, or COLLABORATOR
(or otherwise exclude NONE/CONTRIBUTOR) before proceeding; modify the expression
that currently reads the combined check (the line referencing
github.event.sender.type and github.event.issue.pull_request) to include this
author_association gate for issue_comment paths so only trusted commenters can
trigger the workflow with secrets.
---
Nitpick comments:
In `@packages/bot/src/spotify/spotifyUserSeeds.spec.ts`:
- Around line 64-85: The test asserts the returned likedTrackIds but doesn't
verify that spotifyApi.getUserSavedTracks was invoked correctly and only once;
update the test that calls getUserSpotifySeeds('test-user-id') to also assert
spotifyApi.getUserSavedTracks was called exactly once and with the expected
argument(s) (e.g., the valid access token returned by
spotifyLinkService.getValidAccessToken or the spotifyId from mockLink depending
on how getUserSavedTracks is invoked in getUserSpotifySeeds), using
toHaveBeenCalledTimes(1) and toHaveBeenCalledWith(...) to lock down the call
shape/count.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 8dd2a6ae-c01a-4be1-b3c8-e30a5fe28adb
📒 Files selected for processing (7)
.github/workflows/ci.yml.github/workflows/pr-agent.ymlpackages/backend/src/routes/invite.tspackages/bot/src/spotify/spotifyApi.spec.tspackages/bot/src/spotify/spotifyApi.tspackages/bot/src/spotify/spotifyUserSeeds.spec.tspackages/bot/src/spotify/spotifyUserSeeds.ts
🚧 Files skipped from review as they are similar to previous changes (3)
- packages/bot/src/spotify/spotifyApi.ts
- packages/backend/src/routes/invite.ts
- packages/bot/src/spotify/spotifyUserSeeds.ts
📜 Review details
🧰 Additional context used
📓 Path-based instructions (4)
**/*.{ts,tsx}
📄 CodeRabbit inference engine (.github/copilot-instructions.md)
**/*.{ts,tsx}: Use theisPrisma*Error()helper functions to check for specific Prisma error types (e.g.,isPrismaForeignKeyError,isPrismaUniqueConstraintError) instead of manually checking error codes
Use Prisma's$transaction()method to ensure database operations are atomic and avoid partial updates when multiple related tables are modified
Always useselectorincludein Prisma queries to explicitly specify which fields to return, avoiding unnecessary data transfer
For Redis operations, use connection pooling and implement exponential backoff retry logic for transient failures
Always uselogAndRethrow()orlogAndSwallow()utilities when handling errors to ensure errors are logged with context before propagating or suppressing
Files:
packages/bot/src/spotify/spotifyUserSeeds.spec.tspackages/bot/src/spotify/spotifyApi.spec.ts
packages/{bot,backend,shared}/src/**/*.ts
📄 CodeRabbit inference engine (.github/copilot-instructions.md)
packages/{bot,backend,shared}/src/**/*.ts: For feature toggles, check both global and guild-specific toggles usingFeatureToggleService.isEnabledForGuild()rather than checking them separately
Use branded types (e.g.,GuildId,UserId,ChannelId) for Discord IDs throughout the codebase to prevent type-level ID confusion
Files:
packages/bot/src/spotify/spotifyUserSeeds.spec.tspackages/bot/src/spotify/spotifyApi.spec.ts
packages/bot/src/**/*.ts
📄 CodeRabbit inference engine (.github/copilot-instructions.md)
When building Discord embeds, use
EmbedBuilderService.createTemplate()orEmbedBuilderService.getTemplate()instead of constructing embeds directly
Files:
packages/bot/src/spotify/spotifyUserSeeds.spec.tspackages/bot/src/spotify/spotifyApi.spec.ts
packages/bot/src/{spotify,utils/music}/**/*.ts
📄 CodeRabbit inference engine (.github/copilot-instructions.md)
Extract Spotify track IDs using
extractSpotifyTrackId()before passing to Spotify API calls to prevent malformed requests
Files:
packages/bot/src/spotify/spotifyUserSeeds.spec.tspackages/bot/src/spotify/spotifyApi.spec.ts
🔇 Additional comments (2)
packages/bot/src/spotify/spotifyApi.spec.ts (1)
841-917: Good coverage forgetUserSavedTracksedge cases.Nice addition: this suite validates happy path, malformed payload filtering, failure modes, and the
limit=50cap, which strengthens regression safety for the new Spotify saved-tracks integration.packages/bot/src/spotify/spotifyUserSeeds.spec.ts (1)
15-22: Good coverage for new liked-tracks behavior.Nice additions: default mock reset in
beforeEach, explicitlikedTrackIdsassertions, and both success/failure paths forgetUserSavedTracksare covered well.Also applies to: 61-62, 64-110
The route test was getting a 500 when mockInfoLog was set to throw because logAndSwallow (real impl) was reaching the log service, which surfaced an issue in the test environment. Mocking @lucky/shared/utils/error isolates the route's routing behavior from logging internals. Also adds mockInfoLog.mockReset() in beforeEach so a mockImplementation set in one test doesn't persist to the next (jest clearAllMocks does not reset implementations, only call counts). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
|
Want your agent to iterate on Greptile's feedback? Try greploops. |
|
Stale bot review on superseded commit — dismissing to unblock auto-merge.
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
|
@coderabbitai approve |
✅ Actions performedComments resolved and changes approved. |
* fix(player): harden stream bridge + add 57 missing tests (#815) * fix(player): harden stream bridge error handling - soundcloudMatcher: wrap playdl.stream() in try/catch so auth failures and rate limits surface with context instead of propagating as raw rejections - streamBridge: call proc.kill() in the error handler so the yt-dlp subprocess is cleaned up on spawn errors, not only on timeout - playerFactory: fix priority comment — play-dl SoundCloud init runs before YouTube extractor registration, not after * test(player): add streamBridge and soundcloudMatcher test suites streamBridge.spec.ts (28 tests): - URL validation: allowlist, https-only, ytsearch bypass - Process lifecycle: stdout resolve, error+kill, exit code with stderr, timeout+kill - streamViaYtDlpSearch: empty query guard, ytsearch1 prefix - createResilientStream: full fallback chain, circuit breaker, parenthetical stripping soundcloudMatcher.spec.ts (29 tests): - parseDurationString: MM:SS, HH:MM:SS, edge cases, invalid formats - findMatchingSoundCloudResult: 75% token threshold, duration ±30s boundary, punctuation normalization, case-insensitive, empty query handling - streamViaSoundCloud: empty query, no results, validation miss, happy path, playdl.stream error wrapping with context Also improve replenishQueue error messages in queueHandlers.ts to include actionable recovery steps for the user. * ci: extend workflow triggers to release/** branches Ensures CI, SonarCloud, bundle-size, and path-portability run on PRs targeting and pushes to any release/vX.Y.Z branch. deploy.yml and docker-publish.yml remain main-only. * ci: add PR-Agent AI review and Socket.dev supply chain scan - Add pr-agent.yml workflow: AI-powered code review on every PR using Anthropic claude-sonnet-4-6 backend via Codium-ai/pr-agent action. Auto-describes, auto-reviews, and auto-improves PRs on open/reopen. Requires ANTHROPIC_API_KEY secret. - Add Socket.dev supply chain scan step to existing security job. Detects malicious packages, typosquats, and supply chain attacks. Requires SOCKET_SECURITY_API_KEY secret (continue-on-error until secret is wired). * feat(backend): add /invite UTM tracking route + update README messaging Adds a public /invite redirect route that logs utm_source, utm_medium, utm_campaign, and utm_content before forwarding to the Discord OAuth URL. Updates README subtitle and "Why Lucky?" to lead with shutdown-proof positioning (Groovy/Rythm/Hydra narrative). Swaps all three bare Discord OAuth invite URLs in README for tracked lucky.lucassantana.tech/invite URLs. * fix: correct pr-agent model field + synchronize error-kill assertion - pr-agent.yml: OPENAI.API_VERSION → OPENAI.MODEL (was passing model name as API version, causing PR-Agent to fail/fall back to default model) - streamBridge.spec.ts: emit error synchronously so proc.kill() assertion runs after the handler fires, not before the setImmediate callback * ci: add allow-warnings to socket.dev action, note GitHub App covers PR blocking * feat(spotify): add getUserSavedTracks + likedTrackIds to user seeds - spotifyApi.ts: add getUserSavedTracks() — fetches up to 50 liked tracks via /v1/me/tracks, returns string[] of track IDs - spotifyUserSeeds.ts: add likedTrackIds field to UserSpotifySeeds and populate it by calling getUserSavedTracks on each seed fetch - spotifyUserSeeds.spec.ts: fix beforeEach to re-set getUserSavedTracks mock after jest.clearAllMocks() wipes factory-level mockResolvedValue * fix(backend): harden invite route + add test coverage - Add rate limiting (apiLimiter) to /invite endpoint - Normalize req.query UTM values to string | undefined (guards against array/ParsedQs) - Wrap infoLog in try/catch so logging failure doesn't block redirect - Add invite.test.ts (6 tests: redirect, UTM logging, array coercion, logging failure, no open-redirect) * ci: disable unavailable socketdev action + fix S5144 in getUserSavedTracks - Disable SocketDev/socket-security-action@v1 (repo unavailable; GitHub App covers PR blocking) - Replace template literal with string concatenation in getUserSavedTracks fetch URL to resolve S5144 SSRF hotspot * ci: replace unavailable SocketDev action with run step SocketDev/socket-security-action@v1 repo is not found on GitHub. if: false does not prevent action resolution at job setup time, so replace the entire uses: block with a run: echo placeholder. The GitHub App (apps/socket-security) covers PR-level blocking. * test(spotify): add getUserSavedTracks coverage to fix SonarCloud gate Add 6 tests for getUserSavedTracks (success, missing-id filtering, non-ok response, JSON parse failure, network error, limit capping). The function was introduced in this branch with 0% coverage, causing the quality gate to fail at 43.5% on new code (threshold: 80%). * ci: trigger CI for PR #816 [skip ci-push] * fix(ci): fix YAML syntax error in Socket.dev scan step Colon+space in the echo string was parsed as a YAML mapping separator, breaking workflow file validation and preventing CI/CD Pipeline pull_request runs from being created. * fix(autoplay): use Spotify genres as fallback when Last.fm is not linked to block Spanish gospel When Last.fm is absent, candidateTags is always [] so the cross-locale veto only has text-based signals. Spanish gospel artists (Marcos Witt, Alex Zurdo, Christine D'Clario) carry no Spanish text markers in title/author but Spotify classifies them as 'musica cristiana', 'latin gospel', 'latin worship'. - spotifyRecommender: fall back to getArtistGenres(token, author) when lastFmTags.length === 0; skip if Last.fm returns tags (no double-fetch) - languageHeuristics: add 'latin worship', 'ccm en español', 'spanish ccm' to SPANISH_GENRE_MARKERS; add 'eres', 'nuestro/a', 'siervo/a', 'digno', 'fuego', 'cielos' to SPANISH_DISTINCT_TOKENS - spotifyRecommender.spec: wire getArtistGenresMock; add two tests covering the fallback path and the no-double-fetch guarantee * Revert "fix(autoplay): use Spotify genres as fallback when Last.fm is not linked to block Spanish gospel" This reverts commit 48a1a9336697dca36896d8d36139c347a602aba4. * fix: address CodeRabbit review comments on PR #816 - invite.ts: replace bare catch{} with logAndSwallow() per error-handling guidelines - pr-agent.yml: gate issue_comment trigger to PRs only to avoid running on plain issue comments * fix: address review findings from /pr-review-toolkit:review-pr - spotifyApi: add warnLog when saved-tracks fetch returns non-ok status - spotifyUserSeeds: isolate getUserSavedTracks rejection with .catch([]){} so a network failure doesn't collapse the entire seeds fetch into null - spotifyUserSeeds.spec: test that seeds resolve normally when getUserSavedTracks rejects - pr-agent.yml: pin Codium-ai/pr-agent to SHA instead of floating @main * test(invite): mock logAndSwallow + reset mockInfoLog between tests The route test was getting a 500 when mockInfoLog was set to throw because logAndSwallow (real impl) was reaching the log service, which surfaced an issue in the test environment. Mocking @lucky/shared/utils/error isolates the route's routing behavior from logging internals. Also adds mockInfoLog.mockReset() in beforeEach so a mockImplementation set in one test doesn't persist to the next (jest clearAllMocks does not reset implementations, only call counts). --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Promote [Unreleased] entries into the v2.10.0 section, bump root + workspace versions from 2.9.0 to 2.10.0, and update the lockfile. Release highlights: - Spotify 429 retry hardening (#808) - Last.fm canonical metadata + multi-artist scrobble fix (#821) - Autoplay Spanish-gospel-block + sertanejo prioritization series (#817-#820, #827, #829, #830) - Review-tools revamp: Claude review + Danger + chilled CodeRabbit via org-level reusable workflows (#838) - Coverage threshold pinned for phase-2 test cleanup (#835) - CI extended to release/** branches (#816)



Summary
release/**branches in addition tomainrelease/v2.10.0(and future release branches) run the full quality gate, SonarCloud, bundle size, and path portability checks[main]-only — production deploys only on release mergesWorkflows updated
ci.ymlrelease/**to push + pull_request triggerssonarcloud.ymlrelease/**to push + pull_request triggersbundle-size.ymlrelease/**to pull_request triggerpath-portability.ymlrelease/**to push triggerTest plan
release/v2.10.0— all four workflows should appear as required checksrelease/v2.10.0— push-triggered workflows should fire on that branch🤖 Generated with Claude Code
Summary by CodeRabbit
New Features
Documentation
Chores
Greptile Summary
/invitebackend route that logs UTM parameters and redirects to the Discord OAuth URL, with tests covering error resilience and open-redirect protection. Also introduces a newpr-agent.ymlworkflow for automated AI code review.UserSpotifySeedswith alikedTrackIdsfield populated by a newgetUserSavedTracksSpotify API call, though the field is not yet consumed by any recommendation logic (tracked from a prior review).streamBridgetest by capturing the promise before synchronously emitting the error event, removing asetImmediatetiming dependency.Confidence Score: 4/5
Safe to merge with one P1 fix needed in the pr-agent workflow configuration
A single P1 finding in pr-agent.yml: mixing OPENAI.* and CONFIG.AI_PROVIDER=anthropic config styles means the Anthropic API key may never be passed to the SDK, causing every PR Agent invocation to fail with auth errors. All other changes are well-tested and low risk.
.github/workflows/pr-agent.yml — Anthropic provider configuration needs to be made consistent
Important Files Changed
Sequence Diagram
sequenceDiagram participant Browser participant Backend as Backend /invite participant Log as infoLog participant Discord as Discord OAuth URL Browser->>Backend: "GET /invite?utm_source=github&utm_medium=readme" Backend->>Log: "infoLog({ utm_source, utm_medium, ... })" Note over Log: logAndSwallow on failure Backend-->>Browser: 302 Redirect Browser->>Discord: GET discord.com/oauth2/authorize?...Reviews (11): Last reviewed commit: "test(invite): mock logAndSwallow + reset..." | Re-trigger Greptile