From 15c4479ffc12d7206252cef7f525b049755db887 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Thu, 6 Aug 2026 18:58:12 +0000 Subject: [PATCH 1/5] =?UTF-8?q?ci(github-action):=20update=20action=20miso?= =?UTF-8?q?space/pr-reviewer-action=20(v2.1.10=20=E2=9E=94=20v2.2.0)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/agent-pr-review.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/agent-pr-review.yaml b/.github/workflows/agent-pr-review.yaml index 92d3dd8379..e4d4a39485 100644 --- a/.github/workflows/agent-pr-review.yaml +++ b/.github/workflows/agent-pr-review.yaml @@ -33,7 +33,7 @@ jobs: ref: ${{ github.event.pull_request.head.sha }} - name: Run reviewer - uses: misospace/pr-reviewer-action@6f4fb724b222f6d9a83096d6b41cd636ef3a044e # v2.1.10 + uses: misospace/pr-reviewer-action@99e7764a4906f94d99c249231d2016c3cda8997e # v2.2.0 with: github_token: ${{ github.token }} ai_base_url: http://litellm.ai.svc.cluster.local/v1 From 2df1ad1deeea0c6076f01f87ed2e54eabb7c6be9 Mon Sep 17 00:00:00 2001 From: Tanguille <91473554+Tanguille@users.noreply.github.com> Date: Thu, 6 Aug 2026 21:19:01 +0200 Subject: [PATCH 2/5] ci(pr-review): switch reviews to concise verbosity v2.2.0 adds review_verbosity, which patches the bundled prompt with a ~300-word target and moves minor/info out of prose into the findings array. The hand-written "keep review length proportional" rule in the system_prompt addendum now duplicates it, so drop it. --- .github/workflows/agent-pr-review.yaml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/.github/workflows/agent-pr-review.yaml b/.github/workflows/agent-pr-review.yaml index e4d4a39485..1fbba508d1 100644 --- a/.github/workflows/agent-pr-review.yaml +++ b/.github/workflows/agent-pr-review.yaml @@ -61,6 +61,9 @@ jobs: inline_findings: "true" inline_findings_max: "12" publish_mode: review_comment + # concise targets ~300 words and leaves minor/info to the findings array; it patches the + # bundled default prompt, which only system_prompt_mode: append keeps. + review_verbosity: concise system_prompt_mode: append # v2.1.1 bundles the release-notes STYLE rules (no raw PR/issue/SHA links, summarize in # prose, at most one URL) for renovate-ish PR kinds, so this addendum only steers FETCH @@ -94,8 +97,8 @@ jobs: release in the old-to-new range (releases or compare API) and flag when a chart bump moves the embedded appVersion across a major version. Translate upgrade steps written for docker-compose or .env files into their Kubernetes/Helm equivalent - before flagging them as missing. Keep review length proportional to the change. - Inline findings must require action; never post praise as a finding. + before flagging them as missing. Inline findings must require action; never post + praise as a finding. # Engine hard cap is 126,848 tokens (KV pool); 131072 was over it -> HTTP 500 on # max-packed reviews (validated). 120000 stays under the cap and trims cold-prefill time. model_context_tokens: "120000" From b5ce3856eea0a2f234f917d2eaa46c211a7bd615 Mon Sep 17 00:00:00 2001 From: Tanguille <91473554+Tanguille@users.noreply.github.com> Date: Thu, 6 Aug 2026 21:29:59 +0200 Subject: [PATCH 3/5] ci(pr-review): move the standing review rules to a prompt file Upstream #426 landed in v2.1.11: system_prompt_file and system_prompt are concatenated (file first, inline second) instead of the file being silently dropped. The standing rules move to .github/pr-review-prompt.md, leaving the scalar to hold only the per-PR release-notes branch. --- .github/pr-review-prompt.md | 9 +++++++++ .github/workflows/agent-pr-review.yaml | 16 ++++------------ 2 files changed, 13 insertions(+), 12 deletions(-) create mode 100644 .github/pr-review-prompt.md diff --git a/.github/pr-review-prompt.md b/.github/pr-review-prompt.md new file mode 100644 index 0000000000..0ac6fd00cf --- /dev/null +++ b/.github/pr-review-prompt.md @@ -0,0 +1,9 @@ +# Review quality rules + +Distilled from a fleet audit of past reviews on this repository. + +- Before flagging a config, env var, or resource as missing, read the file that would contain it. If it stays unverifiable, file it under Unknowns at info severity, never as a blocker or major. +- Cite only sources fetched this run. On a failed or empty fetch write "not verified" (never "confirmed") and list the gap under Unknowns. +- For version bumps spanning multiple releases, enumerate every release in the old-to-new range (releases or compare API), and flag when a chart bump moves the embedded appVersion across a major version. +- Translate upgrade steps written for docker-compose or .env files into their Kubernetes/Helm equivalent before flagging them as missing. +- Inline findings must require action. Never post praise as a finding. diff --git a/.github/workflows/agent-pr-review.yaml b/.github/workflows/agent-pr-review.yaml index 1fbba508d1..873a1ac7af 100644 --- a/.github/workflows/agent-pr-review.yaml +++ b/.github/workflows/agent-pr-review.yaml @@ -72,8 +72,10 @@ jobs: # needed, use the authenticated gh_api tool — web_fetch of github.com HTML truncates to # page boilerplate at the response cap and never yielded usable notes (validated in run # logs). Projects that publish no GitHub releases (e.g. Ceph) return 404/empty from - # gh_api, so fall back to the project official release-notes documentation page. The - # trailing quality-rules paragraph distills a fleet audit of past reviews. + # gh_api, so fall back to the project official release-notes documentation page. + # v2.1.11 concatenates file then inline (upstream #426), so the standing rules live in a + # diffable file and only the per-PR branch stays in this scalar. + system_prompt_file: .github/pr-review-prompt.md system_prompt: >- ${{ contains(github.event.pull_request.body, '### Release Notes') && 'The PR body already contains upstream release notes from Renovate. Do not fetch @@ -89,16 +91,6 @@ jobs: the target version section and its Notable Changes summary, then stop. Summarize in a **Release notes** section in review_markdown: user-visible changes, breaking changes, and security fixes.' }} - Review quality rules: Before flagging a config, env var, or resource as missing, - read the file that would contain it; if unverifiable, file it under Unknowns at - info severity, never as a blocker or major. Cite only sources fetched this run; - on a failed or empty fetch write "not verified" (never "confirmed") and list the - gap under Unknowns. For version bumps spanning multiple releases, enumerate every - release in the old-to-new range (releases or compare API) and flag when a chart - bump moves the embedded appVersion across a major version. Translate upgrade steps - written for docker-compose or .env files into their Kubernetes/Helm equivalent - before flagging them as missing. Inline findings must require action; never post - praise as a finding. # Engine hard cap is 126,848 tokens (KV pool); 131072 was over it -> HTTP 500 on # max-packed reviews (validated). 120000 stays under the cap and trims cold-prefill time. model_context_tokens: "120000" From 5c0685551730f16e013daf82a0f2bb2ae819bf03 Mon Sep 17 00:00:00 2001 From: Tanguille <91473554+Tanguille@users.noreply.github.com> Date: Thu, 6 Aug 2026 21:38:21 +0200 Subject: [PATCH 4/5] ci(pr-review): trim the comments and the duplicated summarize sentence --- .github/pr-review-prompt.md | 2 -- .github/workflows/agent-pr-review.yaml | 15 ++++++--------- 2 files changed, 6 insertions(+), 11 deletions(-) diff --git a/.github/pr-review-prompt.md b/.github/pr-review-prompt.md index 0ac6fd00cf..2e68e2dfdd 100644 --- a/.github/pr-review-prompt.md +++ b/.github/pr-review-prompt.md @@ -1,7 +1,5 @@ # Review quality rules -Distilled from a fleet audit of past reviews on this repository. - - Before flagging a config, env var, or resource as missing, read the file that would contain it. If it stays unverifiable, file it under Unknowns at info severity, never as a blocker or major. - Cite only sources fetched this run. On a failed or empty fetch write "not verified" (never "confirmed") and list the gap under Unknowns. - For version bumps spanning multiple releases, enumerate every release in the old-to-new range (releases or compare API), and flag when a chart bump moves the embedded appVersion across a major version. diff --git a/.github/workflows/agent-pr-review.yaml b/.github/workflows/agent-pr-review.yaml index 873a1ac7af..497a2ba9ed 100644 --- a/.github/workflows/agent-pr-review.yaml +++ b/.github/workflows/agent-pr-review.yaml @@ -61,8 +61,7 @@ jobs: inline_findings: "true" inline_findings_max: "12" publish_mode: review_comment - # concise targets ~300 words and leaves minor/info to the findings array; it patches the - # bundled default prompt, which only system_prompt_mode: append keeps. + # concise patches the bundled default prompt, so it needs system_prompt_mode: append below. review_verbosity: concise system_prompt_mode: append # v2.1.1 bundles the release-notes STYLE rules (no raw PR/issue/SHA links, summarize in @@ -73,14 +72,12 @@ jobs: # page boilerplate at the response cap and never yielded usable notes (validated in run # logs). Projects that publish no GitHub releases (e.g. Ceph) return 404/empty from # gh_api, so fall back to the project official release-notes documentation page. - # v2.1.11 concatenates file then inline (upstream #426), so the standing rules live in a - # diffable file and only the per-PR branch stays in this scalar. + # v2.1.11 concatenates system_prompt_file then system_prompt (upstream #426). system_prompt_file: .github/pr-review-prompt.md system_prompt: >- ${{ contains(github.event.pull_request.body, '### Release Notes') && 'The PR body already contains upstream release notes from Renovate. Do not fetch - release notes externally. Summarize the embedded notes in a **Release notes** section - in review_markdown: user-visible changes, breaking changes, and security fixes.' + release notes externally; summarize the embedded notes.' || 'For dependency upgrade and Renovate PRs the body lacks upstream release notes. Fetch them with the gh_api tool (api.github.com /repos/OWNER/REPO/releases JSON) first. If that returns 404 or an empty list (the project does not publish GitHub releases, @@ -88,9 +85,9 @@ jobs: page (e.g. docs.ceph.com/en/latest/releases/tentacle/#v20-2-3-tentacle) rather than github.com HTML pages, which truncate to boilerplate. Large changelogs (Ceph lists hundreds of backported PRs) exhaust the context budget if fetched whole: extract only - the target version section and its Notable Changes summary, then stop. Summarize in a - **Release notes** section in review_markdown: user-visible changes, breaking changes, - and security fixes.' }} + the target version section and its Notable Changes summary, then stop.' }} + Summarize them in a **Release notes** section in review_markdown: user-visible + changes, breaking changes, and security fixes. # Engine hard cap is 126,848 tokens (KV pool); 131072 was over it -> HTTP 500 on # max-packed reviews (validated). 120000 stays under the cap and trims cold-prefill time. model_context_tokens: "120000" From dc2a057cd1366ca24e62317224cb94d07890f8ca Mon Sep 17 00:00:00 2001 From: Tanguille <91473554+Tanguille@users.noreply.github.com> Date: Thu, 6 Aug 2026 21:44:55 +0200 Subject: [PATCH 5/5] ci(pr-review): let the evidence rule reuse the previous review's digest tool_evidence_memory is on by default and seeds a corpus section telling the model to reuse prior evidence instead of re-gathering. The addendum is appended after the bundled default, so "cite only sources fetched this run" overrode it and forced a re-fetch every incremental review. Narrow the rule to the failure it was written for: claiming "confirmed" for a source that was never read. --- .github/pr-review-prompt.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/pr-review-prompt.md b/.github/pr-review-prompt.md index 2e68e2dfdd..1640c14322 100644 --- a/.github/pr-review-prompt.md +++ b/.github/pr-review-prompt.md @@ -1,7 +1,7 @@ # Review quality rules - Before flagging a config, env var, or resource as missing, read the file that would contain it. If it stays unverifiable, file it under Unknowns at info severity, never as a blocker or major. -- Cite only sources fetched this run. On a failed or empty fetch write "not verified" (never "confirmed") and list the gap under Unknowns. +- Never write "confirmed" for a source you did not read. Cite what you fetched this run, or what the previous review's evidence section recorded. On a failed or empty fetch write "not verified" and list the gap under Unknowns. - For version bumps spanning multiple releases, enumerate every release in the old-to-new range (releases or compare API), and flag when a chart bump moves the embedded appVersion across a major version. - Translate upgrade steps written for docker-compose or .env files into their Kubernetes/Helm equivalent before flagging them as missing. - Inline findings must require action. Never post praise as a finding.