Repository navigation
#71 — ci: sticky-PR-comment workflow + consumer recipe + BDD doc-feature - #72
Conversation
Adds .github/workflows/report-preview.yml: on every PR, regenerates each committed example HTML against its fixture pair, uploads as a workflow artifact, and posts a single sticky PR comment (header `cute-dbt-report-preview`) with clickable artifact download links. Structurally separate from `example-report-check` (the byte-identity gate stays a required check; this new job is the human-validation affordance — `if: always()`, never blocks merge, not added to branch protection). A copyable consumer template ships at .github/workflows/examples/cute-dbt-report-preview.yml (subdirectory convention prevents auto-trigger inside this repo). A book recipe page at book/src/recipes/ci-sticky-comment.md walks through the workflow shape, the dbt-parse-in-CI variation, the fork-PR workarounds (pull_request_target / workflow_run split), and the deferred follow-ups (Pages preview, reusable cute-dbt-action). The BDD layer pins the consumer contract as a doc-feature (features/consumer_report_contract.feature + thin step-def glue at tests/steps/consumer_report_contract.rs). The 3 scenarios articulate the structural report properties that make the sticky-comment workflow useful — backed by existing test infrastructure (common::assert_no_external_refs, embedded-payload parsing, std::fs::metadata). Feature-count gate bumps 8 → 9 atomically in .github/workflows/ci.yml and lefthook.yml (per the lefthook-ci-gate-mirror-drift discipline). Fork-PR caveat documented: GitHub strips pull-requests: write from GITHUB_TOKEN on pull_request events from forks. Same-repo branches get the full affordance; fork PRs get the artifact upload only. The recipe page documents two well-trodden workarounds for consumers who need fork-PR coverage. Closes #71 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
|
Warning Review limit reached
More reviews will be available in 38 minutes and 49 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughThis PR implements the sticky-comment report preview feature from issue ChangesCI Sticky-Comment Report Preview Feature
Sequence DiagramsequenceDiagram
participant PR as Pull Request
participant Regenerate as regenerate job
participant Artifacts as Artifact Storage
participant StickyJob as sticky-comment job
participant GhCli as GitHub CLI
participant PRComment as PR Comment
PR->>Regenerate: Trigger on pull_request
Regenerate->>Artifacts: Render and upload HTML reports
Artifacts-->>Regenerate: Artifacts stored (success/failure)
Regenerate->>StickyJob: Job complete (runs if always())
StickyJob->>GhCli: Query run artifacts
GhCli->>StickyJob: Return artifact list
StickyJob->>StickyJob: Format markdown table with links
StickyJob->>PRComment: Post/update sticky comment
PRComment-->>PR: Comment visible to reviewers
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Code Review
This pull request introduces a new CI recipe and documentation for posting a sticky PR comment with a downloadable report preview. It also adds a corresponding Cucumber feature file (consumer_report_contract.feature) and Rust step definitions to formally assert that the rendered report remains self-contained, embeds the necessary payload, and stays under a 10MB size budget. Additionally, the feature count check in lefthook.yml was updated. Feedback is provided to use a generic version placeholder (e.g., v0.x) instead of a specific version (v0.1.0) in the documentation to prevent information rot.
📄 Rendered report previewAll examples regenerated cleanly.
Click Download to fetch the rendered HTML. Each artifact Alternative: GitHub CLI# gh CLI >= 2.63 extracts into ./report-preview-playground/.
gh run download 26489582317 -R breezy-bays-labs/cute-dbt -n report-preview-playground
open report-preview-playground/playground-report.htmlPosted by |
Replace `v0.1.0`-specific phrasing in the recipe page and consumer
template with event-anchored language ("once cute-dbt is available on
crates.io") so the docs don't rot past the first publish. Gemini medium-
priority finding on PR #72.
The substantive recipe content is unchanged — same install paths
(cargo install --git for pre-publish; cargo binstall cute4dbt
post-publish), same fork-PR caveat, same artifact + sticky comment
shape.
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/examples/cute-dbt-report-preview.yml:
- Around line 33-35: The workflow's job "report-preview" needs the actions
permission so the GH API call (gh api
"/repos/${REPO}/actions/runs/${RUN_ID}/artifacts") using GITHUB_TOKEN can list
artifacts; update the job's permissions block (the existing permissions:
contents: read and pull-requests: write) to include actions: read so the "Build
comment body" step can successfully retrieve run-artifacts; apply the same
change for the other occurrences referenced (lines ~94-106) where artifact
lookup is performed.
In @.github/workflows/report-preview.yml:
- Around line 126-149: The workflow's "Build comment body" step uses the Actions
REST API to list artifacts (the gh api call that populates artifacts_json) which
requires the GITHUB_TOKEN to have actions: read permission; update the job
permissions block (for the sticky-comment job) to include "actions: read"
alongside existing permissions so the gh api call won't return an empty array.
Also update the reviewer CLI instructions that use "gh run download -n
report-preview-playground" to reference the extracted path when opening the
report (use report-preview-playground/playground-report.html instead of
playground-report.html) so the downloaded artifact is opened from the correct
directory.
In `@tests/steps/consumer_report_contract.rs`:
- Around line 30-43: Replace the static DOM check in then_zero_external_refs
with a real headless-browser network-block test: instead of calling
common::assert_no_external_refs(html) inside then_zero_external_refs, launch a
headless browser instance with network access disabled, open the generated
report HTML via its file:// URL (using world.report_html.as_ref()), subscribe
to/record any network requests made by the page, and fail the test if any
outbound requests occur (assert no requests). Ensure the browser is run
headless, properly closed on test completion, and integrate this logic into
then_zero_external_refs so the runtime network behavior (not just static
attributes) is validated.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: ef80748c-65b8-456e-8307-97fd81953783
📒 Files selected for processing (9)
.github/workflows/ci.yml.github/workflows/examples/cute-dbt-report-preview.yml.github/workflows/report-preview.ymlbook/src/SUMMARY.mdbook/src/recipes/ci-sticky-comment.mdfeatures/consumer_report_contract.featurelefthook.ymltests/steps/consumer_report_contract.rstests/steps/mod.rs
Two CodeRabbit findings on PR #72: - `actions: read` added to the sticky-comment job in report-preview.yml and to the consumer-recipe job. The `gh api .../actions/runs/<id>/ artifacts` lookup requires this permission under least-privilege GITHUB_TOKEN defaults — without it, the call can silently fail and the comment falls back to the placeholder link. - gh CLI >= 2.63 extracts a single -n named artifact into a subdirectory named after the artifact. Updated the sticky comment's `Alternative: GitHub CLI` fallback hint to reference report-preview-playground/playground-report.html instead of just playground-report.html, matching the actual extraction layout. Declined CR's third finding (replace static lint with headless browser test in tests/steps/consumer_report_contract.rs) — AGENTS.md establishes a two-tier zero-egress model: PRIMARY is tests/headless_zero_egress.rs (real Chromium with network blocked); SECONDARY is the static common::assert_no_external_refs lint. My step mirrors tests/steps/zero_egress.rs:62-70 exactly, which uses the same static stand-in for the same reason. Duplicating the headless proof inside cucumber-rs would be redundant.
Summary
.github/workflows/report-preview.yml: on every PR, regenerates each committed example HTML against its fixture pair, uploads as a workflow artifact, and posts a single sticky PR comment (header: cute-dbt-report-preview) with clickable artifact download links. Structurally separate fromexample-report-check— that pair stays the byte-identity gate (required check); this is the human-validation affordance (if: always(), never blocks merge, NOT added to branch protection)..github/workflows/examples/cute-dbt-report-preview.yml(subdirectory convention prevents auto-trigger inside this repo).book/src/recipes/ci-sticky-comment.mdwalking through the workflow shape, thedbt parse-in-CI variation, fork-PR workarounds (pull_request_target/workflow_runsplit), and deferred follow-ups.features/consumer_report_contract.feature+ thin step-def glue attests/steps/consumer_report_contract.rs). 3 scenarios articulate the structural report properties that make the sticky-comment workflow useful — backed by existingassert_no_external_refs+ embedded-payload parsing +std::fs::metadata. Feature-count gate bumps 8 → 9 atomically inci.ymlandlefthook.yml.Fork-PR caveat (documented, intentional)
GitHub strips
pull-requests: writefromGITHUB_TOKENonpull_requestevents from forks. Same-repo branches get the full affordance; fork PRs get the artifact upload only (sticky comment silently no-ops). Two well-trodden workarounds (pull_request_targetfor the comment-only job, or aworkflow_run-triggered comment workflow) are documented for consumers in the recipe page. This matches the established crap-rs pattern.Validation done locally
cargo fmt --all --check— cleancargo clippy --all-targets --locked -- -D warnings— cleancargo nextest run --locked— 364 passed, 2 skippedcargo test --test bdd— 42 scenarios, 233 steps, all green (was 39 / ~210)mdbook build book— cleanRUSTDOCFLAGS=-D warnings cargo doc --no-deps --document-private-items --locked— cleancargo deny check— okactionlint .github/workflows/report-preview.yml .github/workflows/examples/cute-dbt-report-preview.yml— cleanAction SHA-pin choices
actions/checkout@34e1148… # v4.3.1— matches existing ci.yml pindtolnay/rust-toolchain@29eef33… # stable— matches existing ci.yml pinSwatinem/rust-cache@c193711… # v2.9.1— matches existing ci.yml pinactions/upload-artifact@ea165f8… # v4.6.2— matches existing ci.yml pin (latest is v7.0.1; deferring the repo-wide bump to a separate consistency PR)marocchino/sticky-pull-request-comment@0ea0beb… # v3.0.4— NEW dependency; resolved to latest stable; verifiedheader:+path:inputs supported in v3Test plan (this PR validates itself live)
cute-dbt-report-previewwith bothplayground-report.htmlandjaffle-shop-report.htmlrows + clickable artifact links.if: always()failing condition simulated (intentional bad fixture): confirm sticky comment still posts with status warning.branch-protection.jsonis unchanged (this job is NOT a required check).Deferred follow-ups
pr-<n>/subdirs.breezy-bays-labs/cute-dbt-action@v1composite action.actions/upload-artifactbump v4.6.2 → v7.0.1 across all workflow files for consistency.Closes #71
🤖 Generated with Claude Code
Summary by CodeRabbit
Chores
Documentation
Tests