Skip to content

ci: add autonomous AI development loop (issue → PR → review → converge) - #216

Merged
allxsmith merged 4 commits into
mainfrom
ci/ai-loop
Jul 5, 2026
Merged

allxsmith merged 4 commits into
mainfrom
ci/ai-loop

Conversation

@allxsmith

@allxsmith allxsmith commented Jul 5, 2026 •

Copy link
Copy Markdown
Owner

Which package(s) does this affect?

  • bulma-ui (@allxsmith/bestax-bulma)
  • create-bestax
  • docs
  • skills
  • repo tooling / CI

Closes #215 (phase 2 — the issue body defines the full loop; leave open until the guinea-pig run converges)

What does this PR do?

Implements the autonomous AI development loop defined in #215: label an issue claude-fix → Claude implements it and opens a PR labeled ai-loop → CodeRabbit (per-push engine) + a one-shot Claude deep review (opus) review it → Claude fixes or refutes every finding → each reviewer re-verifies its own findings against the pushed code → converge → a human reviews and squash-merges (the loop never merges).

Components

File Role
.github/workflows/claude-implement.yml Entry: claude-fix label (owner-only) → implement → PR
.github/workflows/claude-review.yml One deep adversarial review per AI PR (claude-opus-4-8); certifies itself with a <!-- claude-deep-review --> marker review
.github/workflows/claude-pr-loop.yml Loop core: cheap shell gate → fix / verify / handoff / halt, plus a 2-hourly sweep watchdog
.coderabbit.yaml auto_pause_after_reviewed_commits: 0, explicit commit_status: true
CLAUDE.md Loop labels, kill switches, state-comment contract
docs/.../ai-development.md + CONTRIBUTING sections User/contributor documentation

Safety model

  • Maintainer-only entry: the claude-fix labeler must hold triage+ access, re-verified live via the collaborators/permission API (defeats template auto-labeling; non-collaborator labels are a silent no-op). Loop scoped to ai-loop-labeled PRs on same-repo claude/* branches; AI_LOOP_ENABLED repo variable is the global kill switch.
  • Iteration cap 4 (state comment is author-filtered to github-actions[bot] and fails closed on corruption); per-branch concurrency queues events, never cancels.
  • Every no-progress path ends in a named state (needs-human-review / ai-loop-paused with reason: cap, protected-path, review-failed, cr-stalled) — no silent stalls; the sweep re-dispatches any stragglers.
  • Protected paths: the gate halts any AI PR touching .github/**, jest/commitlint/release configs, pnpm-workspace.yaml, .npmrc, .coderabbit.yaml, turbo.json.
  • Cancelled CI counts as blocking, not green. Handoff additionally requires CodeRabbit's commit status on the current head and evidence the deep review posted.
  • request_changes_workflow stays false so CodeRabbit can never satisfy the required-approval rule; no auto-merge anywhere.

Pre-merge validation done

  • All three workflows parse (prettier + yaml); Docusaurus build green (link check); pnpm format:check clean.
  • Multi-agent adversarial review of the YAML (3 lenses, every finding independently verified): 8 confirmed defects found and fixed — handoff/deep-review race, forgeable iteration marker, cancelled-CI-as-green, CodeRabbit auto-pause deadlock, silent skip dead-ends, clean-PR dedupe gap.

To validate empirically on the first live run (see #215 checklist)

gh pr create --label from automation mode; allowed_bots on the workflow_run path; CodeRabbit commit-status context matches /coderabbit/i; use_commit_signing on workflow_run checkouts; deep-review marker posting.

Checklist

Summary by CodeRabbit

  • New Features
    • Added “Claude Deep Review” for AI-labeled pull requests, plus an automated fix/verify loop that iterates, verifies progress, and cleanly pauses or hands off to human review when needed.
    • Added issue-label-driven automation to generate and open iteration PRs, with guarded behavior and safe fallbacks.
  • Documentation
    • Expanded contributing and getting-started materials to explain the AI loop lifecycle, labels, guardrails, and how to pause/stop automation.

@coderabbitai

coderabbitai Bot commented Jul 5, 2026 •

Copy link
Copy Markdown

Review Change Stack

Walkthrough

This PR adds an autonomous AI development loop with GitHub Actions workflows, review gating, loop-state transitions, and documentation for labels, guardrails, and human handoff.

Changes

Autonomous AI development loop

Layer / File(s) Summary
Review config and deep review
.coderabbit.yaml, .github/workflows/claude-review.yml
Updates CodeRabbit review settings and adds the gated Claude deep review workflow with deduplication and marked-review output.
Issue label to PR implementation
.github/workflows/claude-implement.yml
Adds the issue-labeled Claude implementation workflow with permission checks, guarded execution, PR creation, and optional Copilot review.
Loop gate and state machine
.github/workflows/claude-pr-loop.yml
Adds the PR loop workflow with sweep, gate, fix, verify, handoff, and halt paths driven by labels, reviews, CI, and iteration state.
AI loop documentation
CLAUDE.md, CONTRIBUTING.md, docs/docs/guides/getting-started/ai-development.md, docs/docs/guides/getting-started/contributing.md
Adds documentation for the AI loop lifecycle, label states, guardrails, and contributor guidance.

Estimated code review effort: 5 (Critical) | ~120 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Owner
  participant ClaudeImplement
  participant PR
  participant ClaudeReview
  participant ClaudePRLoop
  participant Human

  Owner->>ClaudeImplement: label issue claude-fix
  ClaudeImplement->>PR: open ai-loop PR
  PR->>ClaudeReview: opened/labeled event
  ClaudeReview->>PR: post marked deep review
  PR->>ClaudePRLoop: review and CI events
  ClaudePRLoop->>PR: fix, verify, handoff, or halt actions
  ClaudePRLoop->>Human: request review or pause
Loading

Related issues: #215
Related PRs: #214
Suggested labels: enhancement, documentation, automation
Suggested reviewers: allxsmith

Poem:

An issue gets a label, Claude begins,
Reviews and fixes loop until it wins,
Then human hands decide the final pass,
With guardrails set to keep the process fast.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The PR implements the requested workflows, labels, docs, and guardrails for issue #215's autonomous loop.
Out of Scope Changes check ✅ Passed The changes stay focused on the autonomous AI loop workflows, config, and documentation with no unrelated additions.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Title check ✅ Passed The title clearly summarizes the main change: adding an autonomous AI development loop.
Description check ✅ Passed The description covers the change summary, affected packages, related issue, safety model, validation, and checklist, with only minor template gaps.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/ai-loop

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 5, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://2167f4ee.bestax.pages.dev

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/claude-implement.yml:
- Around line 40-43: The Checkout code step in the workflow should disable
credential persistence because the job later runs untrusted content through the
Claude agent with shell access. Update the actions/checkout usage in this
workflow to set persist-credentials to false so the GitHub token is not left in
.git/config, and keep the existing fetch-depth setting unchanged.
- Around line 89-94: The protected-path guidance in the implementer prompt is
missing turbo.json, so Claude can still edit a file that the PR loop later
rejects. Update the protected-path list in the workflow prompt to include
turbo.json alongside the other forbidden configs, and keep the wording aligned
with the existing guarded paths.

In @.github/workflows/claude-pr-loop.yml:
- Around line 287-291: The checkout steps in the workflow are leaving GitHub
credentials persisted, which is unnecessary and increases risk. Update the
`actions/checkout` invocations for both the `fix` job and the `verify` job to
set `persist-credentials: false`, keeping the existing `ref` and `fetch-depth`
behavior unchanged. Use the `Checkout PR branch` steps in the workflow as the
targets to apply the same hardening consistently.
- Around line 43-48: The workflow-level permissions are too broad for jobs that
only read data: scope permissions per job in the claude-pr-loop workflow so
`gate` and `sweep` use read-only access instead of inheriting `contents: write`,
`pull-requests: write`, `issues: write`, `id-token: write`, and `actions:
write`. Keep elevated permissions only on the jobs that actually need them (such
as `fix` and any dispatching step), and verify the job definitions for `gate`,
`sweep`, and `fix` are explicitly configured with the minimum required scopes.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 6054ff81-bba9-4618-b63d-dd997c09d47f

📥 Commits

Reviewing files that changed from the base of the PR and between 7fc7823 and 5b50e51.

📒 Files selected for processing (8)
  • .coderabbit.yaml
  • .github/workflows/claude-implement.yml
  • .github/workflows/claude-pr-loop.yml
  • .github/workflows/claude-review.yml
  • CLAUDE.md
  • CONTRIBUTING.md
  • docs/docs/guides/getting-started/ai-development.md
  • docs/docs/guides/getting-started/contributing.md

Comment thread .github/workflows/claude-implement.yml
Comment thread .github/workflows/claude-implement.yml Outdated
Comment thread .github/workflows/claude-pr-loop.yml Outdated
Comment thread .github/workflows/claude-pr-loop.yml
- persist-credentials: false on all agent checkouts (token exfil surface)
- per-job least-privilege permissions in claude-pr-loop.yml
- align both agent prompts' protected-path lists with the gate (turbo.json)
@github-actions

github-actions Bot commented Jul 5, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://5c5abc70.bestax.pages.dev

Replace the hardcoded owner gate with a live permission check on the
labeler (GitHub already restricts labeling to triage+; the step re-verifies
via the collaborators/permission API and no-ops otherwise). Drop the
workflow_dispatch actor allowlist — GitHub only lets write-access users
dispatch. Handoff still requests review from the repo owner.
@github-actions

github-actions Bot commented Jul 5, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://24317a17.bestax.pages.dev

@github-actions

github-actions Bot commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 5.2.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.2.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[AI] Autonomous development loop: issue → PR → AI review → converge → human merge

1 participant