-
Notifications
You must be signed in to change notification settings - Fork 0
ci: auto-trigger CodeRabbit review on every PR push #457
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,43 @@ | ||
| # Auto-trigger CodeRabbit review on every push to a PR. | ||
| # Context: repo has <10 GitHub stars, so CodeRabbit's auto-review is skipped | ||
| # ("manual review required for this OSS repository"). This workflow automates | ||
| # the manual trigger by commenting `@coderabbitai review` on the PR as the | ||
| # token owner (not github-actions[bot]) — CodeRabbit ignores bot comments. | ||
| name: CodeRabbit auto-trigger | ||
|
|
||
| on: | ||
| pull_request: | ||
| types: [opened, synchronize, reopened] | ||
| branches: [main] | ||
|
Comment on lines
+8
to
+11
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/coderabbit-trigger.yml
printf '%s\n' '--- related configuration ---'
if [ -f .coderabbit.yaml ]; then cat -n .coderabbit.yaml; fi
printf '%s\n' '--- workflow references ---'
rg -n 'coderabbit-trigger|AGENT_ALPHA|pull_request_target|pull_request:|permissions:|concurrency:|skip|guard|comment' .github .coderabbit.yaml 2>/dev/null || true
printf '%s\n' '--- tracked workflow files ---'
git ls-files .github/workflowsRepository: carlitotate12160-tech/agent-alpha Length of output: 9844 🌐 Web query:
💡 Result: The Citations:
🏁 Script executed: #!/bin/bash
set -eu
python3 - <<'PY'
from pathlib import Path
import re
path = Path(".github/workflows/coderabbit-trigger.yml")
text = path.read_text()
checks = {
"pull_request trigger": bool(re.search(r"(?m)^ pull_request:\s*$", text)),
"pull_request_target trigger": bool(re.search(r"(?m)^ pull_request_target:\s*$", text)),
"secret passed to GH_TOKEN": "GH_TOKEN: ${{ secrets.AGENT_ALPHA }}" in text,
"checkout step absent": not bool(re.search(r"(?m)^\s*-\s*uses:\s+actions/checkout@", text)),
"draft guard": "if: github.event.pull_request.draft == false" in text,
"comment command": 'gh pr comment "$PR_NUMBER"' in text,
"PAT permissions configured here": bool(re.search(r"(?m)^\s*permissions:\s*$", text)),
}
for name, result in checks.items():
print(f"{name}: {result}")
print("\nRelevant lines:")
for number, line in enumerate(text.splitlines(), 1):
if 8 <= number <= 43:
print(f"{number}: {line}")
PYRepository: carlitotate12160-tech/agent-alpha Length of output: 1721 Run the PAT from a trusted workflow revision.
Fork PRs cannot access 🤖 Prompt for AI AgentsSource: Path instructions |
||
|
|
||
| permissions: | ||
| pull-requests: write | ||
| contents: read | ||
|
|
||
| concurrency: | ||
| group: coderabbit-trigger-${{ github.event.pull_request.number }} | ||
| cancel-in-progress: true | ||
|
Comment on lines
+17
to
+19
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- workflow files ---'
git ls-files '.github/workflows/**' '.coderabbit.yaml' '.coderabbit.yml'
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/coderabbit-trigger.yml
printf '%s\n' '--- CodeRabbit configuration candidates ---'
for f in .coderabbit.yaml .coderabbit.yml; do
if [ -f "$f" ]; then
printf '%s\n' "--- $f ---"
cat -n "$f"
fi
done
printf '%s\n' '--- references to the workflow and comment command ---'
rg -n --hidden --glob '!node_modules' --glob '!dist' \
'coderabbit-trigger|gh pr comment|AGENT_ALPHA|coderabbitai review|cancel-in-progress|concurrency:' .Repository: carlitotate12160-tech/agent-alpha Length of output: 18022 🌐 Web query:
💡 Result: In GitHub Actions, using the concurrency key with cancel-in-progress: true will automatically terminate currently running jobs within the same concurrency group [1][2]. When a cancellation is triggered, GitHub Actions follows a specific sequence to stop processes, which has important implications for external side effects [3]: 1. Evaluation of Conditionals: GitHub Actions first re-evaluates if conditions for running jobs. Jobs with conditions like if: always will continue to run even when a cancellation is requested [3][4]. 2. Cancellation Signal: For jobs marked for cancellation, the runner sends a SIGINT/Ctrl-C signal to the process [3]. If the process does not exit within 7500 ms, it sends SIGTERM/Ctrl-Break and waits an additional 2500 ms [3]. 3. Final Termination: If the process is still running after this 10-second period, the runner kills the process tree [3]. There is also a 5-minute hard timeout after which the server will forcibly terminate any jobs still running [3]. Because external side effects (e.g., database writes, API calls, or file system modifications) may occur before these signals are received or during the grace period, they are not automatically rolled back by GitHub Actions [3]. To safely handle side effects when concurrency cancellation is enabled, you should: - Ensure scripts are designed to handle termination signals (SIGINT/SIGTERM) gracefully to perform necessary cleanup [3]. - Use the cancelled status check function in steps that must run during or after a cancellation, such as those responsible for cleanup or reverting partial changes [3][4]. - Avoid relying on the absence of cancellation as a guarantee of atomic execution; if your workflow performs operations on external services that must be atomic, implement idempotency or transactional logic in those external services [5]. Note that jobs or steps protected by conditions like if: always will persist despite the cancellation request, which can be useful for cleanup logic but requires careful configuration [3][4]. Citations:
🌐 Web query:
💡 Result: In the GitHub CLI (gh), editing or deleting a pull request comment is performed using the Citations: 🏁 Script executed: #!/bin/bash
set -eu
python3 - <<'PY'
from dataclasses import dataclass
`@dataclass`
class Comment:
body: str
head_sha: str
def run_sequence(cancel_after_write: bool):
comments = []
old = Comment("`@coderabbitai` review", "old-sha")
new = Comment("`@coderabbitai` review", "new-sha")
# Older run performs the external write before cancellation reaches it.
comments.append(old)
old_cancelled = cancel_after_write
# The newer run starts after the older run is cancelled and performs its write.
if old_cancelled:
comments.append(new)
return comments
comments = run_sequence(cancel_after_write=True)
assert len(comments) == 2
assert [comment.body for comment in comments] == [
"`@coderabbitai` review",
"`@coderabbitai` review",
]
print("duplicate comments remain possible:", len(comments))
PYRepository: carlitotate12160-tech/agent-alpha Length of output: 209 Make the CodeRabbit trigger idempotent. Include a marker containing 🤖 Prompt for AI Agents |
||
|
|
||
| jobs: | ||
| trigger: | ||
| # Skip draft PRs (matches .coderabbit.yaml `drafts: false`) | ||
| if: github.event.pull_request.draft == false | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Verify PAT secret is set | ||
| env: | ||
| CR_PAT: ${{ secrets.AGENT_ALPHA }} | ||
| if: ${{ env.CR_PAT == '' }} | ||
| run: | | ||
| echo "::error::Secret AGENT_ALPHA (PAT) is not set. Add it in repo settings → secrets → actions." | ||
| exit 1 | ||
|
|
||
| - name: Trigger CodeRabbit review as token owner | ||
| env: | ||
| GH_TOKEN: ${{ secrets.AGENT_ALPHA }} | ||
| PR_NUMBER: ${{ github.event.pull_request.number }} | ||
| REPO: ${{ github.repository }} | ||
| run: | | ||
| echo "Triggering CodeRabbit review on PR #$PR_NUMBER ($REPO) as token owner" | ||
| gh pr comment "$PR_NUMBER" --repo "$REPO" --body "@coderabbitai review" | ||
| echo "Comment posted as authenticated user. CodeRabbit should pick it up within ~1-2 min." | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
3. Ready drafts remain unreviewed
🐞 Bug≡ CorrectnessAgent Prompt
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools