Repository navigation
ci: remove automated PR catch-up - #15959
Conversation
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 45 seconds. View limit detailsLimit details: You’ve used all 10 included reviews currently available. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (21)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (21)
💤 Files with no reviewable changes (7)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe PR removes automatic and manual pull-request catch-up workflows and their selector. Local merge-main tooling now uses the trusted merge resolver, and contributor guidance identifies ChangesMerge-main transition
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The change retires the automated PR catch-up workflow and points contributors to the local merge-main script. The resolver rename is applied consistently, and no merge-blocking risk was identified. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The removal reduces automated access to pull requests. One upgrade path needs attention: an older installed hook can copy the renamed resolver without checking that it matches trusted main, if that file has been modified locally. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 24 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (24 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 14.29% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 11 files. (3 skipped: 3 unsupported.) ✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
|
Review at 7f8b717: No correctness findings. The resolver extraction preserves scripts/merge-main.sh and installed merge-driver behavior, and the deleted selector, workflow, scripts, fixtures, tests and executable references are gone. Fixed: none needed. Left: the pinned CLA workflow retains its historical cmux/catch-up-merge exemption and two comments, plus the validator history comment; removing those triggers the repository-mandated CLA policy migration and trusted maintainer review. |
CI failure attributionCI passes on Written by |
Dogfood tours of
|
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
|
Merge receipt for |
Remove the automated PR catch-up workflow that created bot-authored merge commits and left pull request CI in
action_required(#1024). In September it ran 302 times, with 300 skipped and 2 successful runs.The supported path remains
scripts/merge-main.sh, documented indocs/ci/merge-main.md. It selects a green main base and uses a trusted local resolver for generated-file conflicts.Removed:
.github/workflows/pr-catch-up.ymlscripts/ci/auto_catch_up_select.pyscripts/ci/catch_up_pr.py/catch-upcommand guidance, and related workflow referencesThe shared local resolver moved to
scripts/ci/merge_main_resolver.py;scripts/merge-main.shand the installed project-file merge driver continue to use it. Hook installation and trust tests were updated to copy the renamed resolver.The CLA workflow’s historical trusted-status exemption remains byte-for-byte unchanged because it is an immutable CLA policy transition that requires a trusted maintainer review. No active catch-up workflow remains to produce that status.
Validation:
python3 scripts/verify-local.pypassed 15 of 16 selected checks; Swift syntax had no selected files. The focused suites passed: 23 merge-main tests, 22 project-file merge-driver tests, 15 hook-installation tests, 5 trust tests, and the test execution registry check.git diff --checkpassed. The broader change-area suite has two inherited stale-head fixture failures on fresh main, reproduced on the base commit as well. No app builds were run.Changelog
Removed: automated PR catch-up and its selector, verification, fixtures, tests, and documentation.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Removes the automated PR catch-up workflow that merged green main into open pull requests with bot-authored merge commits, leaving pull request CI in
action_required(#1024). The workflow ran 302 times in September with only 2 successful runs; branches are now kept current throughscripts/merge-main.shonly.scripts/ci/merge_main_resolver.py, whichscripts/merge-main.shand the project-file merge driver now call; hook installation and trust tests copy the renamed resolver.Written for commit 5d6cfc4. Summary will update on new commits.
Summary by CodeRabbit
main, use the documented local merge command.