Repository navigation
fix(release): synchronize web changelog entries - #2088
Conversation
📝 WalkthroughWalkthroughThe PR adds a web release synchronization script and tests. The release workflow validates draft Release Please PRs, rebuilds and tests release data, safely pushes synchronized commits, and marks valid PRs ready. ChangesWeb release synchronization
Estimated code review effort: 4 (Complex) | ~60 minutes Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 6 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (6 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
46b2606 to
2cf994c
Compare
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release.yml:
- Around line 59-66: Update the “Sync and validate web release entry” workflow
step to run bun run typecheck, bun run typecheck:type-tests, bun run
security:pr-scan -- --base origin/main --head HEAD, and git diff --check
origin/main...HEAD before the release PR is marked ready, while retaining the
existing sync, test, dependency installation, and web build commands.
In `@package.json`:
- Line 57: Document the new bun run sync:web-release maintainer command,
including when it should be run, which generated file it modifies, and the exact
validation commands to execute afterward. Keep the documentation concise and
place it with the existing release or development command guidance.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 2c90e685-c915-4241-96f9-ffb9bba8eac6
📒 Files selected for processing (5)
.github/workflows/release.ymlpackage.jsonrelease-please-config.jsonscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
📜 Review details
🧰 Additional context used
📓 Path-based instructions (9)
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when setup, commands, or user-facing behavior changes.
Files:
package.jsonrelease-please-config.jsonscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
package.jsonrelease-please-config.jsonscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}
⚙️ CodeRabbit configuration file
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.
Files:
package.jsonscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Use TypeScript strict mode and ESM imports throughout the source code.
Run
bun run typecheckandbun run typecheck:type-testsfor TypeScript changes when applicable.
Files:
scripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (AGENTS.md)
Use React and Ink patterns for terminal UI components.
Files:
scripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Files:
scripts/sync-web-release-entry.test.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (AGENTS.md)
Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.
**/*.{ts,tsx,js,jsx}: Follow the existing code style in touched source files, prefer small readable changes, avoid unrelated reformatting, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid broad rewrites or unnecessary generated changes.
Review AI-assisted code for correctness, style consistency, unnecessary changes, and adherence to project architecture before submitting it.
Files:
scripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
**/*.{test,spec}.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
**/*.{test,spec}.{ts,tsx,js,jsx}: Add or update tests when a code change affects behavior.
Use focused tests such asbun test ./path/to/test-file.test.tswhen validating a narrowly scoped change.
Files:
scripts/sync-web-release-entry.test.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
scripts/sync-web-release-entry.test.ts
.github/**
⚙️ CodeRabbit configuration file
.github/**: Review CI and release workflow changes for token permissions, third-party actions, pull_request_target usage, artifact upload/download behavior, shell injection, and whether checks still run on the actual PR head. Block on broadened write permissions or unpinned/excessively trusted external execution unless clearly justified.
Files:
.github/workflows/release.yml
🪛 ast-grep (0.45.0)
scripts/sync-web-release-entry.ts
[warning] 37-40: Regular expression constructed from variable input detected. This can lead to Regular Expression Denial of Service (ReDoS) attacks if the variable contains malicious patterns. Use libraries like 'recheck' to validate regex safety or use static patterns.
Context: new RegExp(
^## \\[${escapeRegExp(target)}\\][^\\n]*\\((\\d{4}-\\d{2}-\\d{2})\\)\\s*$,
'm',
)
Note: [CWE-1333] Inefficient Regular Expression Complexity
(regexp-from-variable)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
There was a problem hiding this comment.
♻️ Duplicate comments (1)
.github/workflows/release.yml (1)
95-102: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winRun and document all required release validation.
The workflow can mark the release PR ready without root type checks, the PR intent scan, or a whitespace check. The recovery instructions omit the same commands. The provided context does not show passing GitHub Check results.
.github/workflows/release.yml#L95-L102: Before marking the PR ready, runbun run typecheck,bun run typecheck:type-tests,bun run security:pr-scan -- --base origin/main --head HEAD, andgit diff --check origin/main...HEAD.CONTRIBUTING.md#L141-L143: Add the same required validation commands to the recovery procedure.As per coding guidelines, PRs must pass applicable tests, type checks, and the PR intent scan. As per path instructions, run the synchronization test, type checks, security scan, whitespace checks, and web validation, and document required recovery validation in
CONTRIBUTING.md.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/release.yml around lines 95 - 102, Update the release validation step in .github/workflows/release.yml lines 95-102 to run bun run typecheck, bun run typecheck:type-tests, bun run security:pr-scan -- --base origin/main --head HEAD, and git diff --check origin/main...HEAD alongside the existing synchronization test and web build before marking the release PR ready. Update CONTRIBUTING.md lines 141-143 to include the same required validation commands in the recovery procedure.Sources: Coding guidelines, Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Duplicate comments:
In @.github/workflows/release.yml:
- Around line 95-102: Update the release validation step in
.github/workflows/release.yml lines 95-102 to run bun run typecheck, bun run
typecheck:type-tests, bun run security:pr-scan -- --base origin/main --head
HEAD, and git diff --check origin/main...HEAD alongside the existing
synchronization test and web build before marking the release PR ready. Update
CONTRIBUTING.md lines 141-143 to include the same required validation commands
in the recovery procedure.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 020a5570-02cd-4f68-a133-c4f30d18de12
📒 Files selected for processing (2)
.github/workflows/release.ymlCONTRIBUTING.md
📜 Review details
⏰ Context from checks skipped due to timeout. (1)
- GitHub Check: smoke-and-tests (24.11.x)
🧰 Additional context used
📓 Path-based instructions (3)
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
PRs must pass the applicable CI checks before merging, including tests, type checks, and the PR intent scan.
Files:
CONTRIBUTING.md
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
CONTRIBUTING.md
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}
⚙️ CodeRabbit configuration file
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}: Review docs for accuracy against current code behavior. Flag security or provider claims that overpromise, stale install commands, missing setup caveats, and instructions that could push users toward unsafe credential handling. Keep purely wording-level suggestions non-blocking.
Files:
CONTRIBUTING.md
.github/**
⚙️ CodeRabbit configuration file
.github/**: Review CI and release workflow changes for token permissions, third-party actions, pull_request_target usage, artifact upload/download behavior, shell injection, and whether checks still run on the actual PR head. Block on broadened write permissions or unpinned/excessively trusted external execution unless clearly justified.
Files:
.github/workflows/release.yml
🧠 Learnings (1)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:03:03.386Z
Learning: Preserve existing repository patterns unless intentionally refactoring them.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:03:03.386Z
Learning: Update documentation when setup, commands, or user-facing behavior changes.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:03:03.386Z
Learning: Avoid breaking third-party providers when fixing first-party provider behavior.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:03:03.386Z
Learning: Dependency changes must have a concrete project benefit, such as fixing a bug, addressing a security issue, or supporting an approved feature.
There was a problem hiding this comment.
Actionable comments posted: 1
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (2)
.github/workflows/release.yml (2)
111-123: 🩺 Stability & Availability | 🟠 Major | 🏗️ Heavy liftRun required checks for the final release PR commit.
- Parse
steps.release.outputs.prwith.headBranchName. The current.headRefNamelookup returnsnull.- Validate the synchronized
web/src/data/releases.tsafter committing it, or validate the final pushed SHA. Current validation runs before the synchronization commit.- Use an approved GitHub App token or explicitly dispatch and await checks for the final SHA before
gh pr ready.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/release.yml around lines 111 - 123, Update the release PR workflow to read the PR branch from steps.release.outputs.pr.headBranchName instead of headRefName, then run the required validation against the synchronized releases.ts content or final synchronization commit SHA after committing and pushing it. Before invoking gh pr ready, use an approved GitHub App token or explicitly dispatch and await the required checks for that final SHA.Source: Path instructions
39-65: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winUse the correct Release Please branch field.
The pinned
googleapis/release-please-action@45996ed...emits aPullRequestobject withheadBranchName. The fallback usesheadRefName. Line 65 writesbranch=nullon the normal output path, so checkout targets an invalid ref. Normalize both fields and fail when neither exists.Proposed fix
- echo "branch=$(jq -r .headRefName <<<"$release_pr")" >> "$GITHUB_OUTPUT" + branch="$(jq -r '.headBranchName // .headRefName // empty' <<<"$release_pr")" + if [ -z "$branch" ]; then + echo "release PR JSON has no branch name" >&2 + exit 1 + fi + echo "branch=$branch" >> "$GITHUB_OUTPUT"🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/release.yml around lines 39 - 65, Update the release PR extraction around the fallback jq query and final branch output to normalize the action’s headBranchName with the fallback PR’s headRefName. Select whichever field is present, and fail explicitly if neither exists; ensure the branch output uses this normalized value instead of reading only .headRefName from release_pr.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release.yml:
- Around line 101-104: Update the release workflow to parse .headBranchName from
steps.release.outputs.pr, then synchronize and validate the pushed PR head
before marking it ready. Ensure security:pr-scan and git diff --check inspect
the committed synchronized head, and add an appropriate trigger or explicit
check execution because GITHUB_TOKEN pushes do not start the PR checks.
---
Outside diff comments:
In @.github/workflows/release.yml:
- Around line 111-123: Update the release PR workflow to read the PR branch from
steps.release.outputs.pr.headBranchName instead of headRefName, then run the
required validation against the synchronized releases.ts content or final
synchronization commit SHA after committing and pushing it. Before invoking gh
pr ready, use an approved GitHub App token or explicitly dispatch and await the
required checks for that final SHA.
- Around line 39-65: Update the release PR extraction around the fallback jq
query and final branch output to normalize the action’s headBranchName with the
fallback PR’s headRefName. Select whichever field is present, and fail
explicitly if neither exists; ensure the branch output uses this normalized
value instead of reading only .headRefName from release_pr.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 4da18f8e-fde3-49a9-826c-11c5c1d5527b
📒 Files selected for processing (2)
.github/workflows/release.ymlCONTRIBUTING.md
📜 Review details
🧰 Additional context used
📓 Path-based instructions (3)
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Follow the existing code style in touched files and do not reformat unrelated files.
Files:
CONTRIBUTING.md
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
CONTRIBUTING.md
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}
⚙️ CodeRabbit configuration file
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}: Review docs for accuracy against current code behavior. Flag security or provider claims that overpromise, stale install commands, missing setup caveats, and instructions that could push users toward unsafe credential handling. Keep purely wording-level suggestions non-blocking.
Files:
CONTRIBUTING.md
.github/**
⚙️ CodeRabbit configuration file
.github/**: Review CI and release workflow changes for token permissions, third-party actions, pull_request_target usage, artifact upload/download behavior, shell injection, and whether checks still run on the actual PR head. Block on broadened write permissions or unpinned/excessively trusted external execution unless clearly justified.
Files:
.github/workflows/release.yml
🧠 Learnings (1)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:11:26.870Z
Learning: Keep pull requests focused on one problem or clearly scoped improvement; avoid unrelated cleanup, fixes, features, or refactors.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:11:26.870Z
Learning: Preserve existing repository patterns unless intentionally refactoring them, and prefer small, readable changes over broad rewrites.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:11:26.870Z
Learning: Add or update tests when a change affects behavior.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:11:26.870Z
Learning: Update documentation when setup, commands, or user-facing behavior changes.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:11:26.870Z
Learning: Provider changes must explicitly identify affected providers and document limitations or follow-up work in the pull request description.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:11:26.870Z
Learning: PRs must pass the applicable CI checks before merging, including tests, typechecks, security PR scanning, and web checks when relevant.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:11:26.870Z
Learning: Resolve merge conflicts before requesting review or approval.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:11:26.870Z
Learning: Do not change the project's language, core runtime, dependency stack, or major technical direction without prior maintainer agreement.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T18:11:26.870Z
Learning: Open an issue before proposing larger changes or new features so scope and alignment can be discussed with maintainers.
🔇 Additional comments (3)
.github/workflows/release.yml (2)
67-76: LGTM!
80-100: LGTM!Also applies to: 105-106
CONTRIBUTING.md (1)
143-143: 🎯 Functional CorrectnessVerify the documented web build command.
The workflow runs
bun run --cwd web buildat Line 106, but this document instructs contributors to runbun run web:build. Confirm that rootpackage.jsondefinesweb:build. If it does not, use the workflow command in this document.As per path instructions, documentation commands must match current code behavior.
Source: Path instructions
There was a problem hiding this comment.
Actionable comments posted: 5
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release.yml:
- Around line 36-38: Document the elevated permissions in both release workflow
jobs: at .github/workflows/release.yml lines 36-38, comment that pull-requests:
write is used to undo the release PR’s ready state; at lines 338-340, comment
that contents: write pushes the synchronized commit and pull-requests: write
marks the PR ready.
- Around line 229-232: Correct the numeric prerelease checks in the inline
script by changing the regex literals used for aNumeric and bNumeric to match
digit-only identifiers rather than literal backslashes. Preserve the existing
BigInt comparison and numeric-versus-nonnumeric precedence logic.
- Around line 411-414: Update the git push command in the release workflow to
authenticate via Git’s HTTP extraheader mechanism instead of embedding
GITHUB_TOKEN in the remote URL or command arguments. Preserve the existing
force-with-lease ref validation and RELEASE_PR_BRANCH push target while ensuring
the token is passed only through the authentication header.
In `@CONTRIBUTING.md`:
- Line 143: Add `bun run web:typecheck` to the release-entry recovery command
list alongside the existing `bun run web:build` check, preserving the
requirement to run it against the committed generated file and confirm tracked
files remain unchanged.
In `@scripts/sync-web-release-entry.test.ts`:
- Around line 187-189: Extend the sanitizeChangelogBullet test coverage for
malformed numeric entities by adding cases such as &`#x110000`; and &`#55296`;.
Assert that sanitizeChangelogBullet preserves these invalid scalar values
without throwing or aborting processing, while retaining the existing
valid-entity decoding assertion.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 0faae7ab-179b-4776-8e5e-e46885245611
📒 Files selected for processing (6)
.github/workflows/release.ymlCONTRIBUTING.mdscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.tsweb/src/data/releases.tsweb/src/pages/changelog.astro
📜 Review details
🧰 Additional context used
📓 Path-based instructions (14)
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Use TypeScript strict mode and ESM imports throughout the source code.
**/*.{ts,tsx}: When changing behavior in TypeScript code, add or update corresponding tests.
Run type checking, including type-test validation, for TypeScript changes before submission.
Use focused tests for the touched area and run the full project checks when appropriate.
For provider changes, test the exact provider and model path affected when possible and avoid breaking third-party providers.
Provider integrations must follow the documented patterns indocs/integrations/overview.mdand the relevant guides underdocs/integrations/how-to/.
When changing provider behavior, explicitly identify affected providers, limitations, and follow-up work in the pull request description.
Files:
web/src/data/releases.tsscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (AGENTS.md)
Use React and Ink patterns for terminal UI components.
Files:
web/src/data/releases.tsscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
web/**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
When changing the web application, run the web typecheck and build checks.
Files:
web/src/data/releases.ts
web/src/data/releases.ts
📄 CodeRabbit inference engine (AGENTS.md)
Do not edit
web/src/data/releases.tsin ordinary feature or bugfix PRs; it is owned by the release/web process.
web/src/data/releases.ts: Do not editweb/src/data/releases.tsin ordinary feature or bug-fix work; modify it only in an explicit release/web changelog PR.
For explicit release/web PRs, regenerateweb/src/data/releases.tswith the release synchronization workflow rather than preserving direct bot-file edits.
Files:
web/src/data/releases.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (AGENTS.md)
Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.
**/*.{ts,tsx,js,jsx}: Preserve existing repository code style in touched files and avoid broad rewrites or unrelated reformatting.
Keep comments useful and concise.
Files:
web/src/data/releases.tsscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
web/**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
When changing web behavior, run the web typecheck and web build validation commands.
Files:
web/src/data/releases.ts
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Do not change the project's language, core runtime, dependency stack, or major architecture without prior maintainer agreement.
Files:
web/src/data/releases.tsscripts/sync-web-release-entry.test.tsweb/src/pages/changelog.astroscripts/sync-web-release-entry.tsCONTRIBUTING.md
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
web/src/data/releases.tsscripts/sync-web-release-entry.test.tsweb/src/pages/changelog.astroscripts/sync-web-release-entry.tsCONTRIBUTING.md
web/**
⚙️ CodeRabbit configuration file
web/**: Review browser extension changes for content-script isolation, message validation, cross-origin assumptions, permission surfaces, and failures that could leak prompts or credentials.
Files:
web/src/data/releases.tsweb/src/pages/changelog.astro
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Files:
scripts/sync-web-release-entry.test.ts
scripts/sync-web-release-entry.test.ts
📄 CodeRabbit inference engine (CONTRIBUTING.md)
After synchronizing the web release entry, run the dedicated synchronization test.
Files:
scripts/sync-web-release-entry.test.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}
⚙️ CodeRabbit configuration file
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.
Files:
scripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
scripts/sync-web-release-entry.test.ts
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}
⚙️ CodeRabbit configuration file
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}: Review docs for accuracy against current code behavior. Flag security or provider claims that overpromise, stale install commands, missing setup caveats, and instructions that could push users toward unsafe credential handling. Keep purely wording-level suggestions non-blocking.
Files:
CONTRIBUTING.md
.github/**
⚙️ CodeRabbit configuration file
.github/**: Review CI and release workflow changes for token permissions, third-party actions, pull_request_target usage, artifact upload/download behavior, shell injection, and whether checks still run on the actual PR head. Block on broadened write permissions or unpinned/excessively trusted external execution unless clearly justified.
Files:
.github/workflows/release.yml
🧠 Learnings (1)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T20:26:07.827Z
Learning: Keep each pull request focused on one issue or clearly scoped improvement; do not mix unrelated cleanup, fixes, features, or refactors.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T20:26:07.827Z
Learning: Review generated or AI-assisted code for correctness, unnecessary changes, style consistency, and architectural adherence before submission.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T20:26:07.827Z
Learning: Update documentation when setup, commands, or user-facing behavior changes.
🪛 ast-grep (0.45.0)
scripts/sync-web-release-entry.ts
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
🪛 zizmor (1.29.0)
.github/workflows/release.yml
[warning] 38-38: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment
(undocumented-permissions)
[warning] 339-339: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment
(undocumented-permissions)
🔇 Additional comments (13)
scripts/sync-web-release-entry.ts (2)
7-8: LGTM!Also applies to: 32-52, 86-87, 97-102, 104-106, 118-145, 208-212
161-205: 📐 Maintainability & Code QualityRun the required validation commands in a Bun-enabled environment. Bun is unavailable, so all five commands exited with
bun: command not found.scripts/sync-web-release-entry.test.ts (1)
6-6: LGTM!Also applies to: 53-53, 74-74, 116-150, 192-196
.github/workflows/release.yml (8)
24-30: LGTM!
44-117: LGTM!
151-199: LGTM!
266-293: LGTM!
295-331: LGTM!
342-387: LGTM!
400-410: LGTM!Also applies to: 416-467
243-245: 🎯 Functional CorrectnessKeep the trusted-base rebuild.
For the same merge base, changelog, and manifest,
sync:web-releasegenerates the same entry. The date comes from the changelog, not the current time.web/src/data/releases.ts (1)
1-3: LGTM!web/src/pages/changelog.astro (1)
7-7: LGTM!Also applies to: 35-35
Superseded by head cb50298: findings addressed or intentionally out of scope after the sync workflow was cut back to a single draft-until-push job. Latest CodeRabbit review on that head is APPROVED.
Move pending Release Please web sync into its own job so a sync failure cannot skip install-verify, npm, or docker after a release tag is already created.
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release.yml:
- Around line 88-90: The release workflow must not grant write permissions to
the PR-code validation job. Refactor the workflow so validation runs with
read-only permissions, while a separate clean write-capable job consumes only a
validated releases.ts artifact, verifies its digest and PR head, and performs
the push without executing PR-controlled commands.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: fe434c0d-deec-4645-80cd-60a4010e1943
📒 Files selected for processing (2)
.github/workflows/release.ymlCONTRIBUTING.md
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
- GitHub Check: typecheck
- GitHub Check: smoke-and-tests (22)
- GitHub Check: smoke-and-tests (24.11.x)
🧰 Additional context used
📓 Path-based instructions (4)
CONTRIBUTING.md
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Read
CONTRIBUTING.mdandAGENTS.mdbefore opening a pull request.
Files:
CONTRIBUTING.md
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Do not introduce inconsistent provider behavior or skip the documented provider integration patterns.
Files:
CONTRIBUTING.md
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
CONTRIBUTING.md
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}
⚙️ CodeRabbit configuration file
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}: Review docs for accuracy against current code behavior. Flag security or provider claims that overpromise, stale install commands, missing setup caveats, and instructions that could push users toward unsafe credential handling. Keep purely wording-level suggestions non-blocking.
Files:
CONTRIBUTING.md
.github/**
⚙️ CodeRabbit configuration file
.github/**: Review CI and release workflow changes for token permissions, third-party actions, pull_request_target usage, artifact upload/download behavior, shell injection, and whether checks still run on the actual PR head. Block on broadened write permissions or unpinned/excessively trusted external execution unless clearly justified.
Files:
.github/workflows/release.yml
🧠 Learnings (1)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Search existing issues, discussions, and open or recently closed pull requests before proposing work; coordinate in an existing thread instead of creating duplicate work.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Open an issue before investing in a larger change or new feature, and keep contributions aligned with the maintainer-approved scope.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Keep each pull request focused on one issue or one clearly scoped improvement; do not bundle unrelated fixes, refactors, or cleanup.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Include the change rationale, impact, validation commands, linked issue when applicable, screenshots for UI-related changes, and the tested provider path in the pull-request description.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Address all CodeRabbit findings before requesting or expecting maintainer review.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Respond to maintainer or CodeRabbit review feedback within one week, or explain delays; pull requests with no activity for two weeks after a review request may be closed.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Do not change the project's language, core runtime, dependency stack, or significantly restructure dependencies without prior maintainer agreement and a clear project benefit.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Review AI-generated code thoroughly for correctness, consistency, unnecessary changes, and architectural adherence before submitting it.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Preserve existing repository patterns unless intentionally refactoring them, and prefer small, readable changes over broad rewrites.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Add or update tests whenever a change affects behavior, and update documentation when setup, commands, or user-facing behavior changes.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Keep comments useful and concise, and do not reformat unrelated files.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Provider changes must identify affected providers, avoid breaking third-party providers, test the exact provider/model path when possible, document limitations or follow-up work, and never assign or use provider tags.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Run the narrowest meaningful validation for the touched area; relevant checks include `bun run check`, `bun run test:full`, provider tests, typechecks, `bun run security:pr-scan`, and web checks when applicable.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-10T23:19:16.387Z
Learning: Pull requests that fail required CI checks must not be merged.
🔇 Additional comments (3)
.github/workflows/release.yml (2)
18-24: LGTM!Also applies to: 103-103
80-87: LGTM!CONTRIBUTING.md (1)
143-152: LGTM!
Remove hand-curation escape hatches, split read-only validation from write-only push, discover bot PRs by branch identity, and run the full local gate suite before marking the release PR ready.
Commit the synced releases.ts in the read-only validate job before typecheck, security scan, and whitespace checks so those gates inspect the content that will be marked ready, not the pre-sync HEAD.
Run sync from trusted main with only changelog/manifest overlaid from the bot PR, re-draft after release-please, serialize sync without canceling in-flight pushes, and require an explicit sync base.
Fetching changelog/manifest from the bot PR dirtied tracked files on the trusted main checkout and made the final git-diff gate fail on every pending release. Restore those overlays after sync and fetch origin/main for the security/whitespace checks.
There was a problem hiding this comment.
Actionable comments posted: 2
♻️ Duplicate comments (2)
.github/workflows/release.yml (2)
392-396: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winBlocking: the numeric prerelease test matches a backslash, not digits.
The
node -ebody is inside single quotes, so the shell passes\\dthrough unchanged. Innew RegExp("...\\d*...")that is correct. In the regex literal/^\\d+$/it is not:\\matches a literal backslash, soaNumericandbNumericare alwaysfalse.Effect: numeric prerelease identifiers fall through to string comparison.
1.0.0-rc.2→1.0.0-rc.10compares"10" < "2", the gate reports that the version does not advance, and the release PR is blocked. The numeric-over-alphanumeric precedence rule is also dead code.This was raised on an earlier head and the gate has returned in this form.
🐛 Proposed fix
- const aNumeric = /^\\d+$/.test(a) - const bNumeric = /^\\d+$/.test(b) + const aNumeric = /^[0-9]+$/.test(a) + const bNumeric = /^[0-9]+$/.test(b)🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/release.yml around lines 392 - 396, Fix the numeric prerelease detection in the version comparator by changing the regex literals used for aNumeric and bNumeric so they match digit sequences rather than a literal backslash followed by d. Preserve the BigInt numeric ordering and numeric-over-alphanumeric precedence behavior in the surrounding comparison logic.
93-94: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winDocument the write scope on
prepare-web-release.zizmor reports
undocumented-permissionsfor this block. The other permission blocks in this file carry comments, so this one breaks the pattern.📝 Proposed fix
permissions: - pull-requests: write + pull-requests: write # Re-draft the bot release PR after release-please updates it.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/release.yml around lines 93 - 94, Add a concise explanatory comment to the permissions block for prepare-web-release, documenting why pull-requests: write is required. Match the comment style used by the other permission blocks in the workflow.Source: Linters/SAST tools
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release.yml:
- Around line 441-446: Update the metadata-writing step around
release-pr.outputs.number, release-pr.outputs.branch, and
release-pr.outputs.head_sha to pass these values through the step’s env context
instead of interpolating them directly into shell. In the push job, replace
source of .release-sync-artifact/metadata.env with safe key-value parsing via
read_meta and assign number, branch, head_sha, and releases_sha256 from it
without executing file contents.
- Around line 556-587: Update the synchronization flow around
already_synchronized so the validated artifact is staged or otherwise reconciled
with the checked-out head before the cleanliness gate runs, allowing the
concurrent-push retry path to succeed without uncommitted changes. Collapse the
redundant elif and else branches that emit the same message while preserving the
existing commit behavior for unsynchronized artifact changes.
---
Duplicate comments:
In @.github/workflows/release.yml:
- Around line 392-396: Fix the numeric prerelease detection in the version
comparator by changing the regex literals used for aNumeric and bNumeric so they
match digit sequences rather than a literal backslash followed by d. Preserve
the BigInt numeric ordering and numeric-over-alphanumeric precedence behavior in
the surrounding comparison logic.
- Around line 93-94: Add a concise explanatory comment to the permissions block
for prepare-web-release, documenting why pull-requests: write is required. Match
the comment style used by the other permission blocks in the workflow.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 7d605235-ecca-41b4-b50b-0b49c4edc199
📒 Files selected for processing (5)
.github/workflows/release.ymlCONTRIBUTING.mdscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.tsweb/src/data/releases.ts
📜 Review details
🧰 Additional context used
📓 Path-based instructions (14)
**/*
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
CONTRIBUTING.mdscripts/sync-web-release-entry.test.tsweb/src/data/releases.tsscripts/sync-web-release-entry.ts
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}
⚙️ CodeRabbit configuration file
{README.md,CONTRIBUTING.md,docs/**,.github/pull_request_template.md}: Review docs for accuracy against current code behavior. Flag security or provider claims that overpromise, stale install commands, missing setup caveats, and instructions that could push users toward unsafe credential handling. Keep purely wording-level suggestions non-blocking.
Files:
CONTRIBUTING.md
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Use TypeScript strict mode and ESM imports throughout the source code.
**/*.{ts,tsx}: Add or update tests whenever a TypeScript/TSX change affects behavior.
Provider changes must follow the documented integration patterns, avoid breaking third-party providers, test the exact provider/model path changed when possible, and document affected providers and limitations.
Files:
scripts/sync-web-release-entry.test.tsweb/src/data/releases.tsscripts/sync-web-release-entry.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (AGENTS.md)
Use React and Ink patterns for terminal UI components.
Files:
scripts/sync-web-release-entry.test.tsweb/src/data/releases.tsscripts/sync-web-release-entry.ts
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Files:
scripts/sync-web-release-entry.test.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (AGENTS.md)
Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.
**/*.{ts,tsx,js,jsx}: Review AI-generated code for correctness, subtle bugs, unnecessary changes, consistency with existing patterns, and architectural adherence before submitting it.
Follow the existing code style in touched files, prefer small readable changes over broad rewrites, avoid reformatting unrelated files, and keep comments useful and concise.
Preserve existing repository patterns unless intentionally refactoring them, and avoid mixing unrelated cleanup into a feature or bugfix.
Files:
scripts/sync-web-release-entry.test.tsweb/src/data/releases.tsscripts/sync-web-release-entry.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}
⚙️ CodeRabbit configuration file
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.
Files:
scripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
scripts/sync-web-release-entry.test.ts
web/**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
When changing the web application, run the web typecheck and build checks.
Files:
web/src/data/releases.ts
web/src/data/releases.ts
📄 CodeRabbit inference engine (AGENTS.md)
Do not edit
web/src/data/releases.tsin ordinary feature or bugfix PRs; it is owned by the release/web process.Do not edit
web/src/data/releases.tsduring ordinary feature or bugfix work; only modify it in an explicit release/web changelog workflow, where release automation owns generated entries.
Files:
web/src/data/releases.ts
web/**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
When changing the web application, run
bun run web:typecheckandbun run web:build.
Files:
web/src/data/releases.ts
web/**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Do not patch
web/src/data/releases.tsmerely to silence web CI when npm is ahead of the site version; web synchronization is owned by release automation.
Files:
web/src/data/releases.ts
web/**
⚙️ CodeRabbit configuration file
web/**: Review browser extension changes for content-script isolation, message validation, cross-origin assumptions, permission surfaces, and failures that could leak prompts or credentials.
Files:
web/src/data/releases.ts
.github/**
⚙️ CodeRabbit configuration file
.github/**: Review CI and release workflow changes for token permissions, third-party actions, pull_request_target usage, artifact upload/download behavior, shell injection, and whether checks still run on the actual PR head. Block on broadened write permissions or unpinned/excessively trusted external execution unless clearly justified.
Files:
.github/workflows/release.yml
🧠 Learnings (1)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T02:03:17.811Z
Learning: Keep each pull request focused on one issue or one clearly scoped improvement, and avoid bundling unrelated fixes, features, refactors, or dependency changes.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T02:03:17.811Z
Learning: Run the narrowest meaningful validation for the touched area before submitting; PRs must pass required CI checks.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T02:03:17.811Z
Learning: Dependency changes require a clear project benefit such as fixing a bug, addressing a security issue, or supporting an approved feature.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T02:03:17.811Z
Learning: Open an issue before investing in a non-trivial or new feature, and align larger changes with maintainers before implementation.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T02:03:17.811Z
Learning: PR descriptions must explain what changed and why, user or developer impact, exact checks run, linked issues when applicable, screenshots for UI/terminal/VS Code changes, and the provider path tested for provider changes.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T02:03:17.811Z
Learning: Address all CodeRabbit findings before maintainer review; do not ignore automated review comments.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T02:03:17.811Z
Learning: Respond to maintainer or CodeRabbit review requests within one week, or leave a status comment explaining delays; PRs inactive for two weeks after review requests may be closed.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T02:03:17.811Z
Learning: Search existing issues, discussions, and open or closed pull requests before proposing work, especially to avoid duplicate contributions.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T02:03:17.811Z
Learning: For security reports, follow `SECURITY.md` rather than reporting them through ordinary contribution channels.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T02:03:17.811Z
Learning: Be respectful and constructive with other contributors.
🪛 ast-grep (0.45.0)
scripts/sync-web-release-entry.ts
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
🪛 zizmor (1.29.0)
.github/workflows/release.yml
[warning] 94-94: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment
(undocumented-permissions)
[info] 442-442: code injection via template expansion (template-injection): may expand into attacker-controllable code
(template-injection)
[info] 443-443: code injection via template expansion (template-injection): may expand into attacker-controllable code
(template-injection)
[info] 444-444: code injection via template expansion (template-injection): may expand into attacker-controllable code
(template-injection)
🔇 Additional comments (7)
scripts/sync-web-release-entry.ts (3)
7-14: LGTM!
152-174: LGTM!
195-239: LGTM!scripts/sync-web-release-entry.test.ts (1)
185-222: LGTM!Also applies to: 259-284
CONTRIBUTING.md (1)
141-161: LGTM!web/src/data/releases.ts (1)
2-3: LGTM!.github/workflows/release.yml (1)
473-475: 🩺 Stability & AvailabilityKeep the shared job concurrency group.
The workflow-level
auto-release-${{ github.ref }}group allows only one release run to execute. A later run remains pending and cannot queuevalidate-web-releasewhile an earlier run'spush-web-releaseis pending.> Likely an incorrect or invalid review comment.
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.github/workflows/release.yml (1)
29-88: 🩺 Stability & Availability | 🟠 Major | ⚡ Quick winNon-blocking, but a transient API error here stops the release itself.
This step runs inside the
release-pleasejob and exits non-zero on anygh apifailure. A single transient GitHub API error then blocks tag creation, npm publish, and Docker publish. Lines 96-97 state that PR API failures must not suppress publishing, so the pre-step reintroduces the coupling the rest of the workflow avoids.Add a bounded retry around discovery. Keep the hard failure for real ambiguity, such as
match_count != 1.🛡️ Proposed retry
- matches="$(gh api --paginate --method GET "repos/${GH_REPO}/pulls" \ - -f state=open \ - -f base="$RELEASE_BASE_BRANCH" \ - -f per_page=100 \ - | jq -s -c \ + list_open_prs() { + gh api --paginate --method GET "repos/${GH_REPO}/pulls" \ + -f state=open \ + -f base="$RELEASE_BASE_BRANCH" \ + -f per_page=100 + } + raw="" + for attempt in 1 2 3; do + if raw="$(list_open_prs)"; then break; fi + echo "pull request discovery attempt $attempt failed; retrying" >&2 + raw="" + sleep $((attempt * 5)) + done + if [ -z "$raw" ]; then + echo "failed to list open pull requests for $RELEASE_BASE_BRANCH" >&2 + exit 1 + fi + matches="$(jq -s -c <<<"$raw" \The same pattern applies to the discovery calls at lines 136-167 and 245-277, but those run in jobs that cannot block publishing.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/release.yml around lines 29 - 88, Make the Release Please PR discovery in the “Keep an existing Release Please PR draft before updating it” step tolerate transient gh api failures by adding a bounded retry around the discovery call, while preserving the current successful result parsing. After retries are exhausted, allow the API failure to remain non-zero, but retain the hard failure for genuine ambiguity when match_count is not 0 or 1. Do not alter the draft-state handling or publishing workflow coupling beyond this retry.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In @.github/workflows/release.yml:
- Around line 29-88: Make the Release Please PR discovery in the “Keep an
existing Release Please PR draft before updating it” step tolerate transient gh
api failures by adding a bounded retry around the discovery call, while
preserving the current successful result parsing. After retries are exhausted,
allow the API failure to remain non-zero, but retain the hard failure for
genuine ambiguity when match_count is not 0 or 1. Do not alter the draft-state
handling or publishing workflow coupling beyond this retry.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 90dd63ad-824b-4e6f-a702-0bfe06a50236
📒 Files selected for processing (3)
.github/workflows/release.ymlscripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
📜 Review details
🧰 Additional context used
📓 Path-based instructions (9)
**/*.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Use TypeScript strict mode and ESM imports throughout the source code.
**/*.{ts,tsx}: Add or update tests whenever a TypeScript or TSX change affects behavior.
Follow the existing code style in touched TypeScript and TSX files; prefer small, readable changes and avoid unrelated rewrites or reformatting.
Keep comments useful and concise in TypeScript and TSX code.
Provider changes must preserve consistent behavior across provider paths, avoid breaking third-party providers, and test the exact provider/model path changed when possible.
Run type checks for TypeScript changes, includingbun run typecheckandbun run typecheck:type-testswhen applicable.
Review generated or AI-assisted TypeScript code for correctness, style consistency, unnecessary changes, and architectural adherence rather than relying only on compilation.
Files:
scripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
**/*.{tsx,ts}
📄 CodeRabbit inference engine (AGENTS.md)
Use React and Ink patterns for terminal UI components.
Files:
scripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
**/*.{test,spec}.{ts,tsx}
📄 CodeRabbit inference engine (AGENTS.md)
Add or update tests when behavior changes, and run the narrowest useful focused test checks.
Run focused tests for the affected area, and run provider-specific tests when changing provider behavior.
Files:
scripts/sync-web-release-entry.test.ts
**/*.{ts,tsx,js,jsx}
📄 CodeRabbit inference engine (AGENTS.md)
Do not add new Python code, Python provider paths, or Python dependencies without explicit maintainer approval.
Files:
scripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
**/*: Run the narrowest meaningful validation command for the touched area before submitting changes; PRs must not fail required CI checks.
Preserve existing repository patterns unless intentionally refactoring them, and document setup, command, or user-facing behavior changes.
Files:
scripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
scripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
**/scripts/sync-web-release-entry.test.ts
📄 CodeRabbit inference engine (CONTRIBUTING.md)
For explicit release/web changelog recovery, run the web release synchronization test after regenerating
web/src/data/releases.ts.
Files:
scripts/sync-web-release-entry.test.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}
⚙️ CodeRabbit configuration file
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.
Files:
scripts/sync-web-release-entry.test.tsscripts/sync-web-release-entry.ts
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}
⚙️ CodeRabbit configuration file
{src/**/*.test.ts,src/**/*.test.tsx,tests/**,scripts/**/*.test.ts,vscode-extension/**/*.test.js}: Review tests for meaningful coverage of the changed behavior, isolation of global/env/config state, async cleanup, fake timers, provider profile leaks, and Windows-compatible assumptions. Block when risky runtime changes lack focused regression coverage or tests assert implementation details while missing the user-visible behavior.
Files:
scripts/sync-web-release-entry.test.ts
.github/**
⚙️ CodeRabbit configuration file
.github/**: Review CI and release workflow changes for token permissions, third-party actions, pull_request_target usage, artifact upload/download behavior, shell injection, and whether checks still run on the actual PR head. Block on broadened write permissions or unpinned/excessively trusted external execution unless clearly justified.
Files:
.github/workflows/release.yml
🧠 Learnings (1)
📓 Common learnings
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T03:20:08.989Z
Learning: Keep pull requests focused on one problem or clearly scoped improvement; avoid unrelated cleanup and dependency, runtime, language, or core-stack changes without prior maintainer agreement.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T03:20:08.989Z
Learning: Provider-change pull requests must identify affected providers, tested provider/model paths, limitations, and follow-up work; do not assign provider tags.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T03:20:08.989Z
Learning: Before opening a feature pull request, open an issue to discuss and align the feature with the maintainer-directed roadmap.
Learnt from: CR
Repo: Gitlawb/openclaude
Timestamp: 2026-08-11T03:20:08.989Z
Learning: PR descriptions must explain what changed and why, user or developer impact, exact checks run, linked issues when applicable, and screenshots for UI, terminal presentation, or VS Code extension changes.
🪛 ast-grep (0.45.1)
scripts/sync-web-release-entry.ts
[warning] 16-20: Do not use variable for regular expressions
Context: new RegExp(
^(0|[1-9]\\d*)\\.(0|[1-9]\\d*)\\.(0|[1-9]\\d*)
(?:-(${SEMVER_IDENTIFIER}(?:\\.${SEMVER_IDENTIFIER})*))?(?:\\+[0-9A-Za-z-]+(?:\\.[0-9A-Za-z-]+)*)?$,
)
Note: [CWE-1333] Inefficient Regular Expression Complexity. Security best practice.
(regexp-non-literal-typescript)
[warning] Importing child_process exposes a command-execution surface; ensure any command/argument built from input is validated, and prefer execFile/spawn with an argument array over exec.
Context: import { execFileSync } from 'node:child_process'
Note: [CWE-78] Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
(detect-child-process-typescript)
🔇 Additional comments (5)
scripts/sync-web-release-entry.ts (1)
16-73: LGTM!scripts/sync-web-release-entry.test.ts (1)
40-63: LGTM!.github/workflows/release.yml (3)
188-323: LGTM!Also applies to: 514-670
494-499: 🩺 Stability & AvailabilityKeep the shared job concurrency group.
The workflow-level
auto-release-${{ github.ref }}group prevents a newer run from startingvalidate-web-releasewhile an earlier run is still in progress. Therefore, the newer run cannot cancel a pendingpush-web-releasejob in the shared job-level group.> Likely an incorrect or invalid review comment.
421-434: 🎯 Functional CorrectnessConfirm
bun -ebehavior on Bun 1.3.13.The
-eflag exists, but the available documentation does not establish TypeScript parsing and static relative-import resolution for this mode. Test both snippets on Bun 1.3.13, or move them to a.tsfile invoked withbun run.
|
@kevincodex1 LGTM |
Summary
web/src/data/releases.tson the pending Release Please PR from the trusted merge base and the first five changelog bulletsRoot cause
GITHUB_TOKENpushes do not start ordinary PR checks. Waiting on those checks after sync either deadlocked or risked marking an unvalidated head ready. This PR validates the sync locally in the release job, pushes the one generated file, and only then marks the PR ready.Behavior
releases.tsfrom trusted main scripts using the pending bot PR changelog and manifest--force-with-leaseagainst the captured headValidation
bun test ./scripts/sync-web-release-entry.test.ts— 14 passedFinal head:
cb50298c40ef75b10e10ce86c33bcc0c1aa784b1Summary by CodeRabbit
New Features
Bug Fixes
Tests
Documentation