Repository navigation
ci: ai-triage v2 — fan-out commands, always-on with budget, config modes (#289) - #292
Conversation
…des (#289) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Pohc8xLkdx4gwXkW3xd7up
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
WalkthroughAdds issue and pull-request triage command specifications, rewrites the GitHub Actions workflow around event modes, permissions, daily budgeting, and Claude command execution, updates documentation, and introduces a ChangesAI triage automation
Pre-pull-request gate
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant GitHub
participant Workflow
participant BudgetIssue
participant Claude
participant Commands
GitHub->>Workflow: Trigger opened or labeled event
Workflow->>Workflow: Check mode, permissions, and eligibility
Workflow->>BudgetIssue: Read or increment daily counter
Workflow->>Claude: Start triage session
Claude->>Commands: Run the matching triage command
Commands->>GitHub: Search candidates and post one triage comment
Possibly related issues
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Preview DeploymentPreview URL: https://fa9fdf4c.bestax.pages.dev |
There was a problem hiding this comment.
Actionable comments posted: 6
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.claude/commands/pre-pr.md:
- Around line 11-13: The step 2 checklist reference should use the
repository-relative CONTRIBUTING-COMPONENTS.md path instead of an absolute root
path, and the command’s allowed-tools configuration should include a
read-capable tool so the checklist can be inspected.
- Around line 11-18: Update the pre-PR review instructions around the checklist
in CONTRIBUTING-COMPONENTS.md to first determine whether the diff includes
component changes. Run the stories, homepage/guide listing, and skills-sync
checks only for component-related changes; skip them for unrelated PRs while
retaining the broader diff and commit-message review.
In @.claude/commands/triage-find-issues.md:
- Around line 42-47: Resolve the contradiction between labeled reruns and silent
empty results in the triage commands. In .claude/commands/triage-find-issues.md
at lines 42-47, refresh the existing marker with a negative result on an
explicit labeled rerun, while remaining silent for opened PRs without a marker;
update lines 17-22 to cross-reference this handling. Apply the same distinction
and cross-reference updates in .claude/commands/triage-find-duplicate-prs.md at
lines 38-43 and 17-22.
In @.github/workflows/ai-triage.yml:
- Around line 166-207: The workflow’s concurrency scope allows different AI
triage runs to race while reading and updating the shared budget comment. Update
the workflow-level concurrency configuration, using the existing concurrency
group symbol, so all runs sharing the repository-wide daily budget serialize
through the gate and budget-charge steps, while preserving the current
cancellation behavior and per-item processing semantics.
- Around line 166-194: Update the daily budget lookup around STATE in the
workflow to fetch all tracking-issue comment pages before filtering for the
latest github-actions[bot] marker. Preserve the existing marker selection and
fail-closed parsing behavior, ensuring older comments beyond the first 100
cannot cause the count to reset.
In `@docs/docs/guides/getting-started/ai-development.md`:
- Around line 67-68: Clarify the AI_TRIAGE_MODE description in the
getting-started documentation so off explicitly disables both automatic triage
and label handling, rather than suggesting the label remains active. Preserve
the existing auto and label behavior descriptions.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: e4f23594-00ee-4365-85b0-9de3ba296d9e
📒 Files selected for processing (7)
.claude/commands/pre-pr.md.claude/commands/triage-dedupe.md.claude/commands/triage-find-duplicate-prs.md.claude/commands/triage-find-issues.md.github/workflows/ai-triage.ymlCLAUDE.mddocs/docs/guides/getting-started/ai-development.md
There was a problem hiding this comment.
Deep review — 2 finding(s)
| # | Severity | Area | Finding | Location |
|---|---|---|---|---|
| 1 | 🟠 Major | Correctness | Per-item concurrency + shared read-modify-write counter → budget race, cap can be exceeded | .github/workflows/ai-triage.yml:196 |
| 2 | 🟡 Minor | Correctness | Budget probe reads only first 100 comments of #290; fails open if the marker paginates off page 1 | .github/workflows/ai-triage.yml:172 |
Overall: This is a well-documented, security-conscious workflow change — the two-layer gate, pull_request_target base-only checkout, GET-only allowlist, fail-closed unparsable-marker handling, and label-vs-auto split are all sound, and the four command files are consistent with the workflow prompt and tool allowlist. The riskiest part is the new shared daily-budget counter on #290: it's a repo-wide read-modify-write guarded only by a per-item concurrency group, so concurrent auto runs race and the cost cap it exists to enforce can leak under a burst of new issues/PRs. The human should focus there first — decide whether to serialize the gate with a global concurrency group. The pagination gap is a slower-burning variant of the same "counter isn't robust" theme. Everything else (modes matrix, AUTOCLOSE passthrough, idempotency, label removal) checks out.
🏄 Clean set, dude — the triage machine paddles out solid and the security rails are tight. Just watch that shared budget buoy: two waves hitting at once and the counter drifts, so the daily cap might not hold in a swell. Lock that down and it's all-time.
- global single-flight concurrency group: load-bearing for the shared read-modify-write budget counter (deep-review Major + CodeRabbit) - budget probe paginates all tracking-issue comments so the marker can never fall off page 1 and fail open - labeled reruns of the two PR triage commands now refresh the marker with a negative result instead of contradicting their silent-on-zero rule; opened runs stay silent - pre-pr: repo-relative checklist path, Read tool, component checks now conditional on the diff actually touching components - docs: AI_TRIAGE_MODE 'off' explicitly disables label triage too Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Pohc8xLkdx4gwXkW3xd7up
Preview DeploymentPreview URL: https://e73ae9fc.bestax.pages.dev |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.claude/commands/triage-find-duplicate-prs.md:
- Around line 42-45: Clarify the trigger-specific behavior in the duplicate PR
handling instructions: when no credible duplicates are found, TRIGGER=opened
must remain completely silent, while TRIGGER=labeled must post or refresh the
single-line “No duplicate PRs found.” comment with the marker. Update the
conflicting rule near the “nothing was found” guidance so this labeled-trigger
exception is explicit and preserves idempotent refresh behavior.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: c006ec10-84a7-404a-87df-95ce3bb43fce
📒 Files selected for processing (5)
.claude/commands/pre-pr.md.claude/commands/triage-find-duplicate-prs.md.claude/commands/triage-find-issues.md.github/workflows/ai-triage.ymldocs/docs/guides/getting-started/ai-development.md
✅ Files skipped from review due to trivial changes (1)
- .claude/commands/pre-pr.md
🚧 Files skipped from review as they are similar to previous changes (3)
- docs/docs/guides/getting-started/ai-development.md
- .github/workflows/ai-triage.yml
- .claude/commands/triage-find-issues.md
| weak matches. Zero credible duplicates: on `TRIGGER=opened`, stop SILENTLY | ||
| — no comment, no marker; on `TRIGGER=labeled` (an explicit human request), | ||
| post/refresh the comment with the single line "No duplicate PRs found." | ||
| plus the marker (matches the pre-check refresh path). |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Resolve the contradiction with the hard rules.
These lines require TRIGGER=labeled to post or refresh “No duplicate PRs found.”, but Line 66 says to post no comment whenever nothing was found. An agent may follow the hard rule and suppress the required labeled rerun comment, breaking the documented idempotency contract.
Proposed clarification
- anything; post at most one comment, and none at all when nothing was found.
+ anything; post at most one comment. For no matches, post nothing on
+ `TRIGGER=opened`; on `TRIGGER=labeled`, follow the explicit refresh
+ behavior above.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.claude/commands/triage-find-duplicate-prs.md around lines 42 - 45, Clarify
the trigger-specific behavior in the duplicate PR handling instructions: when no
credible duplicates are found, TRIGGER=opened must remain completely silent,
while TRIGGER=labeled must post or refresh the single-line “No duplicate PRs
found.” comment with the marker. Update the conflicting rule near the “nothing
was found” guidance so this labeled-trigger exception is explicit and preserves
idempotent refresh behavior.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Pohc8xLkdx4gwXkW3xd7up
Preview DeploymentPreview URL: https://65be229a.bestax.pages.dev |
|
🎉 This PR is included in version 3.2.1 🎉 The release is available on: Your semantic-release bot 📦🚀 |
|
🎉 This PR is included in version 5.4.1 🎉 The release is available on: Your semantic-release bot 📦🚀 |
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Pull Request
Description
PR A of #289: rewrites the
ai-triageworkflow for Bun-parity fan-out triage, establishes.claude/commands/, and updates the docs. PR B (auto-close cron + script) lands separately.@allxsmith/bestax-bulma)create-bestax)@allxsmith/bestax-docs) — ai-development guide.github/workflows/ai-triage.yml,.claude/commands/)Workflow (
ai-triage.yml):openedalongsidelabeled(issues +pull_request_target; still base-default-branch checkout only,persist-credentials: false).AI_TRIAGE_MODE(auto/label/off; unset ⇒ label-only — GitHub renders unset vars as'', and theif:is designed around that).bestaxbot,claude/*heads, and PRs already carryingFixes #/Closes #, then a daily budget — one<!-- ai-triage-budget date=… count=N -->marker comment on tracking issue AI triage budget tracker (machine-managed — keep open) #290, author-filtered togithub-actions[bot], fail-closed when unparsable, incremented before any Claude spend (mirrorsclaude-pr-loop.yml's iteration counter). Limit fromAI_TRIAGE_DAILY_LIMIT(unset ⇒ 10).--max-turns 50, sonnet, allowlist = GET-only gh set + the two comment commands +Task(fan-out sub-agents) — still nogh api, no Edit/Write. Issues run/triage-dedupe; PRs run/triage-find-issuesthen/triage-find-duplicate-prs.AI_TRIAGE_AUTOCLOSE(on/dry-run) injects the 14-day auto-close notice into dedupe comments.labeledevents.Slash commands (
.claude/commands/, greenfield):triage-dedupe.md— pre-checks, 5 parallel Task agents (error strings / component+file names / API+prop names / title keywords / broad area), filter pass, ONE comment with a machine-parseableDuplicate of #Nline (the auto-close cron's anchor) +<!-- ai-triage:dedupe -->marker.triage-find-issues.md— 5 agents over PR title/body/diff; open issues only; copy-pasteableFixes #Nblock;<!-- ai-triage:find-issues -->.triage-find-duplicate-prs.md— 3 agents scopedis:pr is:open is:unmerged; silent when zero;<!-- ai-triage:find-duplicate-prs -->.pre-pr.md— restores the/pre-prcommand docs: new-component checklist, bounded CLAUDE.md deltas, /pre-pr command #269's description promised but its squash never included: runpnpm all, then self-review the diff against/CONTRIBUTING-COMPONENTS.md.Related Issue(s)
Refs #289 (PR A — PR B completes it)
See #269 (pre-pr.md restoration closes its gap), #274, #277
Type of Change
Checklist
CLAUDE.mdfiles are updatedAdditional Context
Rollout requires repo variables (workflow defaults are safe until set):
AI_TRIAGE_MODE=auto,AI_TRIAGE_DAILY_LIMIT=10,AI_TRIAGE_AUTOCLOSE=dry-run(flip toonafter a week of sane dry-run logs). Issue #290 is the pinned budget anchor — the workflow'sTRACKING_ISSUEenv points at it; the gate PATCHes onegithub-actions[bot]marker comment there per UTC day.Deviation worth noting: with
gh apideliberately absent from the allowlist, label-triggered "refresh in place" usesgh issue|pr comment --edit-last, which can only target the bot's most recent comment — the commands fall back to posting fresh when an older marker isn't last (only reachable on PR re-labels, where two marker comments exist).🤖 Generated with Claude Code
https://claude.ai/code/session_01Pohc8xLkdx4gwXkW3xd7up
Generated by Claude Code
Summary by CodeRabbit
New Features
Documentation