Repository navigation
ci: add autonomous AI development loop (issue → PR → review → converge) - #216
Conversation
WalkthroughThis PR adds an autonomous AI development loop with GitHub Actions workflows, review gating, loop-state transitions, and documentation for labels, guardrails, and human handoff. ChangesAutonomous AI development loop
Estimated code review effort: 5 (Critical) | ~120 minutes Sequence Diagram(s)sequenceDiagram
participant Owner
participant ClaudeImplement
participant PR
participant ClaudeReview
participant ClaudePRLoop
participant Human
Owner->>ClaudeImplement: label issue claude-fix
ClaudeImplement->>PR: open ai-loop PR
PR->>ClaudeReview: opened/labeled event
ClaudeReview->>PR: post marked deep review
PR->>ClaudePRLoop: review and CI events
ClaudePRLoop->>PR: fix, verify, handoff, or halt actions
ClaudePRLoop->>Human: request review or pause
Related issues: Poem:
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Preview DeploymentPreview URL: https://2167f4ee.bestax.pages.dev |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/claude-implement.yml:
- Around line 40-43: The Checkout code step in the workflow should disable
credential persistence because the job later runs untrusted content through the
Claude agent with shell access. Update the actions/checkout usage in this
workflow to set persist-credentials to false so the GitHub token is not left in
.git/config, and keep the existing fetch-depth setting unchanged.
- Around line 89-94: The protected-path guidance in the implementer prompt is
missing turbo.json, so Claude can still edit a file that the PR loop later
rejects. Update the protected-path list in the workflow prompt to include
turbo.json alongside the other forbidden configs, and keep the wording aligned
with the existing guarded paths.
In @.github/workflows/claude-pr-loop.yml:
- Around line 287-291: The checkout steps in the workflow are leaving GitHub
credentials persisted, which is unnecessary and increases risk. Update the
`actions/checkout` invocations for both the `fix` job and the `verify` job to
set `persist-credentials: false`, keeping the existing `ref` and `fetch-depth`
behavior unchanged. Use the `Checkout PR branch` steps in the workflow as the
targets to apply the same hardening consistently.
- Around line 43-48: The workflow-level permissions are too broad for jobs that
only read data: scope permissions per job in the claude-pr-loop workflow so
`gate` and `sweep` use read-only access instead of inheriting `contents: write`,
`pull-requests: write`, `issues: write`, `id-token: write`, and `actions:
write`. Keep elevated permissions only on the jobs that actually need them (such
as `fix` and any dispatching step), and verify the job definitions for `gate`,
`sweep`, and `fix` are explicitly configured with the minimum required scopes.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: 6054ff81-bba9-4618-b63d-dd997c09d47f
📒 Files selected for processing (8)
.coderabbit.yaml.github/workflows/claude-implement.yml.github/workflows/claude-pr-loop.yml.github/workflows/claude-review.ymlCLAUDE.mdCONTRIBUTING.mddocs/docs/guides/getting-started/ai-development.mddocs/docs/guides/getting-started/contributing.md
- persist-credentials: false on all agent checkouts (token exfil surface) - per-job least-privilege permissions in claude-pr-loop.yml - align both agent prompts' protected-path lists with the gate (turbo.json)
Preview DeploymentPreview URL: https://5c5abc70.bestax.pages.dev |
Replace the hardcoded owner gate with a live permission check on the labeler (GitHub already restricts labeling to triage+; the step re-verifies via the collaborators/permission API and no-ops otherwise). Drop the workflow_dispatch actor allowlist — GitHub only lets write-access users dispatch. Handoff still requests review from the repo owner.
Preview DeploymentPreview URL: https://24317a17.bestax.pages.dev |
|
🎉 This PR is included in version 5.2.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
|
🎉 This PR is included in version 3.2.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Which package(s) does this affect?
Closes #215 (phase 2 — the issue body defines the full loop; leave open until the guinea-pig run converges)
What does this PR do?
Implements the autonomous AI development loop defined in #215: label an issue
claude-fix→ Claude implements it and opens a PR labeledai-loop→ CodeRabbit (per-push engine) + a one-shot Claude deep review (opus) review it → Claude fixes or refutes every finding → each reviewer re-verifies its own findings against the pushed code → converge → a human reviews and squash-merges (the loop never merges).Components
.github/workflows/claude-implement.ymlclaude-fixlabel (owner-only) → implement → PR.github/workflows/claude-review.ymlclaude-opus-4-8); certifies itself with a<!-- claude-deep-review -->marker review.github/workflows/claude-pr-loop.ymlgate→fix/verify/handoff/halt, plus a 2-hourlysweepwatchdog.coderabbit.yamlauto_pause_after_reviewed_commits: 0, explicitcommit_status: trueCLAUDE.mddocs/.../ai-development.md+ CONTRIBUTING sectionsSafety model
claude-fixlabeler must hold triage+ access, re-verified live via the collaborators/permission API (defeats template auto-labeling; non-collaborator labels are a silent no-op). Loop scoped toai-loop-labeled PRs on same-repoclaude/*branches;AI_LOOP_ENABLEDrepo variable is the global kill switch.needs-human-review/ai-loop-pausedwith reason: cap, protected-path, review-failed, cr-stalled) — no silent stalls; the sweep re-dispatches any stragglers..github/**, jest/commitlint/release configs,pnpm-workspace.yaml,.npmrc,.coderabbit.yaml,turbo.json.request_changes_workflowstaysfalseso CodeRabbit can never satisfy the required-approval rule; no auto-merge anywhere.Pre-merge validation done
pnpm format:checkclean.To validate empirically on the first live run (see #215 checklist)
gh pr create --labelfrom automation mode;allowed_botson the workflow_run path; CodeRabbit commit-status context matches/coderabbit/i;use_commit_signingon workflow_run checkouts; deep-review marker posting.Checklist
pnpm allnot applicable to workflow YAML; format:check + docs build run locallySummary by CodeRabbit