Skip to content

ci: observe review fabric on pull request events - #13526

Closed
teamleaderleo wants to merge 3 commits into
ci/review-fabric-github-adapterfrom
ci/review-fabric-observe
Closed

teamleaderleo wants to merge 3 commits into
ci/review-fabric-github-adapterfrom
ci/review-fabric-observe

Conversation

@teamleaderleo

@teamleaderleo teamleaderleo commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Add the first ongoing listener for the review fabric, stacked on #13524 / #13522.

The workflow re-captures provider-neutral review state whenever PR/review/comment events change and evaluates the fabric policy in shadow mode.

Event loop

Triggers on:

  • pull_request_target head/metadata changes;
  • review submissions/dismissals;
  • inline review-comment changes;
  • PR issue-comment changes.

Each run:

  1. checks out only trusted base/default-branch repository code;
  2. captures a GitHub review receipt;
  3. evaluates the provider-neutral fabric policy;
  4. writes the JSON evaluation to the step summary;
  5. uploads the receipt + evaluation as a durable artifact.

Security boundary

The observer:

  • never checks out the PR head;
  • uses contents: read, issues: read, and pull-requests: read only;
  • persists no checkout credentials;
  • skips non-PR issue comments;
  • uses the repository's pinned artifact action.

Shadow mode

The policy exit code is recorded but the workflow exits successfully.

That is deliberate: this slice gathers real PR history and lets the quorum/finding semantics prove themselves before becoming a required merge check.

Testing

Adds a structural contract test that pins:

  • trusted pull_request_target execution;
  • read-only permissions;
  • base/default-branch checkout;
  • no PR-head execution;
  • receipt capture + evaluation;
  • non-authoritative shadow behavior;
  • pinned artifact preservation.

Stacked on #13524, which is stacked on #13522.

Refs #13088.


Summary by cubic

Adds a shadow-mode review fabric observer workflow that re-captures provider-neutral review state on PR, review, review-comment, and issue-comment events without making the fabric policy authoritative.

  • Triggers on pull_request_target with read-only permissions, checking out only base/default-branch code and never the PR head.
  • Captures a review receipt, evaluates the policy, writes the evaluation to the step summary, and uploads receipt plus evaluation as artifacts.
  • The policy exit code is recorded but the workflow always exits successfully, keeping the fabric policy non-authoritative.
  • Adds a contract test pinning the trusted execution, read-only permissions, base checkout, shadow behavior, and pinned artifact action.

Written for commit 034f44c. Summary will update on new commits.

Review in cubic

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: manaflow-ai/cmux/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 2d4425e0-79d8-43be-bbb3-745f874580d8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@teamleaderleo
teamleaderleo force-pushed the ci/review-fabric-github-adapter branch from c099d06 to fcdffd0 Compare September 22, 2026 00:18
@teamleaderleo
teamleaderleo force-pushed the ci/review-fabric-observe branch from 33aff93 to 034f44c Compare September 22, 2026 00:19
@teamleaderleo
teamleaderleo force-pushed the ci/review-fabric-github-adapter branch 2 times, most recently from 52466e9 to b1963b9 Compare September 22, 2026 02:27

Copy link
Copy Markdown
Collaborator Author

@greptileai review

Copy link
Copy Markdown
Collaborator Author

@greptile-apps review

@teamleaderleo

Copy link
Copy Markdown
Collaborator Author

Closing along with #13524 (same dependency on the removed review gate).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant