Skip to content

Harden docs deployment authentication - #8347

Merged
lawrencecchen merged 12 commits into
mainfrom
fix-docs-deploy-auth
Jul 18, 2026
Merged

lawrencecchen merged 12 commits into
mainfrom
fix-docs-deploy-auth

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • pin Bun 1.3.14 and Vercel CLI 56.3.1 for docs deployments
  • probe the Vercel token daily and on demand
  • guard both requirements in main CI

Testing

  • python3 tests/test_docs_deploy_auth_guard.py
  • python3 -m py_compile tests/test_docs_deploy_auth_guard.py
  • actionlint .github/workflows/docs-deploy-reusable.yml .github/workflows/vercel-auth-health.yml .github/workflows/ci.yml
  • bunx vercel@56.3.1 whoami --token "$VERCEL_TOKEN"

Context


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Summary by cubic

Pins Bun 1.3.14 and vercel@56.3.1 for docs deploys, adds a scheduled/on‑demand Vercel auth check, and removes --token to keep secrets out of process args. Adds per‑suite Swift Testing timeouts with one retry to prevent CI hangs by killing hung process groups.

  • Bug Fixes

    • Pin docs deploy tooling: Bun 1.3.14 and bunx vercel@56.3.1 deploy; use env VERCEL_TOKEN and remove --token.
    • Add a Vercel auth health workflow (daily + workflow_dispatch).
    • Bound and retry Swift Testing suites in CI (per‑suite timeout via a process‑group‑terminating runner, one retry) with deterministic guard tests.
  • Refactors

    • Make fork‑probe teardown deterministic: track child PIDs, assert exit, add 1‑minute test limits, and remove unused probe bindings.
    • Clear Xcode 26.3 warning blockers: actor isolation cleanups, @Sendable helpers, const‑correctness tweaks, and a nil‑guard in Quick Look.
    • Keep sidebar feature flag keys in FeatureFlags.swift; update related comments.

Written for commit 83a2710. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features
    • Added a scheduled and manually triggered “Vercel auth health” check to verify authentication is functioning.
  • Bug Fixes
    • Hardened documentation deployment automation by enforcing authentication safeguards and pinning Bun and the Vercel CLI for consistent behavior.
  • Tests
    • Added CI tests that validate docs deploy and Vercel auth workflow configuration, including pinned tooling and token handling.
    • Improved fork probe test reliability with more deterministic process-exit verification.

@coderabbitai

coderabbitai Bot commented Jul 17, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

The changes pin Bun and Vercel CLI versions for documentation deployment, add scheduled/manual authentication checks, validate workflow configuration in CI, make process-related tests deterministic, refine termination assertions, and update two AppKit sidebar comments.

Changes

Documentation deployment authentication

Layer / File(s) Summary
Pin deployment and add authentication health check
.github/workflows/docs-deploy-reusable.yml, .github/workflows/vercel-auth-health.yml
The deployment workflow pins Bun 1.3.14 and Vercel CLI 56.3.1; the health workflow checks VERCEL_TOKEN daily or manually.
Validate workflow authentication configuration
tests/test_docs_deploy_auth_guard.py
Tests verify workflow triggers, pinned versions, Vercel commands, and secret usage.
Run the authentication guard in CI
.github/workflows/ci.yml
The guard test runs in the existing workflow-guard-tests job.

Fork capability probe tests

Layer / File(s) Summary
Make descendant termination checks deterministic
cmuxTests/WorkspaceForkConversationContextMenuTests.swift
Probe tests record descendant PIDs, use one-minute time limits, and verify process termination with expectProcessExited.
Await duplicate refresh requests directly
cmuxTests/WorkspaceForkConversationContextMenuTests.swift
The coalescing test removes a fixed sleep and awaits concurrent refresh tasks directly.

Process termination state assertions

Layer / File(s) Summary
Capture termination gate results
cmuxTests/PortScannerTests.swift
Tests explicitly capture and assert termination results before launch, after launch, and after completion.

Sidebar comment clarifications

Layer / File(s) Summary
Clarify AppKit sidebar comments
Sources/ContentView.swift, Sources/TerminalWindowPortal.swift
Comments reference the feature flag declaration and describe failsafe synchronization without changing control flow.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Sequence Diagram(s)

sequenceDiagram
  participant GitHubActions
  participant Bunx
  participant Vercel
  GitHubActions->>Bunx: Install Bun 1.3.14
  Bunx->>Vercel: Run vercel@56.3.1 whoami with VERCEL_TOKEN
  Vercel-->>GitHubActions: Return authentication result
Loading

Possibly related PRs

  • manaflow-ai/cmux#7952: Updates related port-scanning test assertions and snapshot reconciliation behavior.
  • manaflow-ai/cmux#8172: Also modifies the documentation deployment workflow’s Bun tooling configuration.

Suggested reviewers: austinywang

🚥 Pre-merge checks | ✅ 23 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Description check ⚠️ Warning The description covers summary and testing, but it omits the required Review Trigger and Checklist sections. Add the Review Trigger copy/paste block and a checklist section with the required items; include Demo Video only if applicable.
✅ Passed checks (23 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed Patch only refactors a Swift test; no production actor-isolation semantics were added or worsened.
Cmux Swift Blocking Runtime ✅ Passed PASS: the Swift production files only change comments, and timing logic added is test-only scaffolding; no new blocking waits/sleeps/locks in non-test Swift.
Cmux Browser Automation Off-Main ✅ Passed Diff only changes PortScannerTests.swift; no browser.* automation code or policy files were touched.
Cmux Expensive Synchronous Load ✅ Passed Production Swift diffs are comment-only in ContentView and TerminalWindowPortal; no expensive synchronous load was added or moved onto an interactive path.
Cmux Cache Substitution Correctness ✅ Passed Diff only changes a Swift test’s assertion style; no production Swift/TS/JS cache, persistence, history, undo, or snapshot path was altered.
Cmux No Hacky Sleeps ✅ Passed No scoped TS/JS/shell/build-runtime code introduces hacky waits; the added waits are workflow YAML or Swift test scaffolding, which the rule exempts.
Cmux Algorithmic Complexity ✅ Passed The diff only changes workflows, tests, and comment-only Swift code; no production scalable-collection scans or hot-path algorithm changes were introduced.
Cmux Swift Concurrency ✅ Passed The only Swift code delta is a test-only refactor in PortScannerTests; it adds no new Dispatch, Combine, completion-handler, or unowned Task patterns.
Cmux Swift @Concurrent ✅ Passed Touched Swift files only add test assertions/comments and a synchronous file/PID helper; no @concurrent, invalid actor isolation, or missing hops were introduced.
Cmux Swift Package Boundaries ✅ Passed No production Swift logic was added or expanded; the commit changes only workflows/tests, which the boundary rule allows.
Cmux Swiftpm Lockfiles ✅ Passed Diff touches workflows/tests/Sources only; no Package.swift, Package.resolved, Xcode project, or .gitignore changes, so the lockfile policy isn't violated.
Cmux Swift Logging ✅ Passed The PR only changes comments in production Swift files; no new print/debugPrint/dump/NSLog, ad hoc logging, or unsafe Logger changes appear in the diff.
Cmux User-Facing Error Privacy ✅ Passed The PR only changes CI/workflow/test code and developer comments; no end-user error, alert, or recovery copy was added or exposed.
Cmux Full Internationalization ✅ Passed The PR only changes workflows, tests, and comment-only Swift code; no user-facing localized text, catalogs, or locale files were added or edited.
Cmux Swiftui State Layout ✅ Passed The PR only tweaks comments in existing SwiftUI/AppKit bridge views; it introduces no new state, GeometryReader layout, lazy-row store refs, or render-time mutation.
Cmux Architecture Rethink ✅ Passed The only Swift code change is a test-only refactor in ProcessTerminationGateTests; it adds no sleeps, observers, locks, or split ownership.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed HEAD only changes cmuxTests/PortScannerTests.swift; no user-visible window code or cmuxAuxiliaryWindowIdentifiers changes, so the aux-window rule doesn’t apply.
Cmux Source Artifacts ✅ Passed Changed paths are hand-written workflows, tests, and source comments; no logs, caches, build output, or scratch artifacts were added.
Cmux No Test Or Debug Seam In Production Source ✅ Passed PR diff changes only workflows and a test file; no Sources/** production Swift edits were introduced.
Cmux No Ambient Global State ✅ Passed Only cmuxTests/PortScannerTests.swift changed; it adds no production Swift globals, singletons, or static-only namespaces.
Title check ✅ Passed The title clearly summarizes the main change: hardening docs deployment authentication.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix-docs-deploy-auth

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR hardens docs deployment authentication by pinning Bun 1.3.14 and vercel@56.3.1, removing the --token CLI arg in favour of the VERCEL_TOKEN env var, and adding a daily Vercel auth health workflow. It also makes Swift Testing suite runs more deterministic by adding per-suite process-group timeouts with one retry, and cleans up actor-isolation, const-correctness, and nil-guard warnings from Xcode 26.

  • Docs deploy / auth hardening: Pins exact tool versions, drops --token from CLI args so the secret stays out of /proc/PID/cmdline, and adds a daily vercel whoami health check; guard tests assert both invariants in CI.
  • Swift Testing timeout runner: Adds run_with_timeout.py (process-group SIGTERM→SIGKILL) called per suite with one retry on exit 124, replacing the timing-based Task.sleep assertions with explicit PID-file checks and @Test(.timeLimit(.minutes(1))) annotations.
  • Swift cleanups: Removes unnecessary await on actor method calls inside inheriting Task closures, fixes var→let const-correctness, flattens deeply-nested if-else if-let chains in applyPendingForkValidations to guard-continue form, and adds a nil-guard for QLPreviewPanel! in the Quick Look controller.

Confidence Score: 5/5

Safe to merge — workflow and CI changes are well-tested by guard scripts, Swift changes are mechanical cleanup, and the large SharedLiveAgentIndex refactor is covered by the existing fork-validation test suite.

The docs-deploy and health-workflow changes are narrow and guarded by new Python tests. The SharedLiveAgentIndex restructure is a pure de-nesting refactor with no observable behaviour change; the outer guard bindings it removes were unused variables (Xcode 26 warnings). All timing-based Task.sleep assertions are replaced with deterministic PID-file checks, and new .timeLimit(.minutes(1)) annotations replace wall-clock duration comparisons. No blocking runtime primitives, ambient globals, or test seams are introduced in production source.

SharedLiveAgentIndex.swift contains a large structural refactor of applyPendingForkValidations; worth a manual pass to confirm the guard-continue flattening preserves all early-return paths, particularly the restorePendingForkValidationsAfterCancellation call sites.

Important Files Changed

Filename Overview
.github/workflows/docs-deploy-reusable.yml Pins Bun 1.3.14 and vercel@56.3.1; removes --token from CLI args, relying on VERCEL_TOKEN env var — correct and safe.
.github/workflows/vercel-auth-health.yml New daily + on-demand health workflow; uses VERCEL_TOKEN env var with no --token arg exposure; correct permissions (read-only).
.github/workflows/ci.yml Adds two new guard-test validation steps for docs deploy auth and Swift Testing suite timeout; straightforward additions.
Sources/SharedLiveAgentIndex.swift Large refactor of applyPendingForkValidations — flattens deep if-else-if-let nesting to guard-continue; also changes two outer guard bindings to != nil checks where the bound variables were unused. Logic appears equivalent but is complex.
Sources/AgentForkExecutableIdentityResolver.swift Removes unnecessary await from actor method calls inside Task closures that inherit actor isolation — correct Swift 6 cleanup.
Sources/WorkspaceChecklistAttachmentQuickLookController.swift Adds nil guard for QLPreviewPanel! parameter in previewPanelWillClose to prevent crash on nil panel.
scripts/ci/run_with_timeout.py New process-group-terminating timeout runner: SIGTERM → 5s grace → SIGKILL; returns 124 on timeout; handles KeyboardInterrupt cleanly.
scripts/ci/run-swift-testing-suites.sh Wraps each suite in run_with_timeout.py with one retry on exit 124; correctly propagates non-zero exit codes.
cmuxTests/WorkspaceForkConversationContextMenuTests.swift Replaces Task.sleep timing assertions with explicit PID-file checks, adds @sendable annotations, .timeLimit(.minutes(1)) guards, and discards Set.insert return values to silence Swift 6 warnings.
tests/test_docs_deploy_auth_guard.py New guard tests verifying pinned tool versions and absence of --token in both deploy and health workflows.
tests/test_swift_testing_suite_timeout.py New end-to-end test verifying the timeout runner kills a hung suite, retries once, then exits 124 with both timeout messages present.

Sequence Diagram

%%{init: {'theme': 'neutral'}}%%
sequenceDiagram
    participant GH as GitHub Actions
    participant DW as docs-deploy-reusable.yml
    participant HW as vercel-auth-health.yml
    participant Bun as Bun 1.3.14
    participant VC as vercel@56.3.1
    participant API as Vercel API

    Note over HW: Daily cron (06:17 UTC) or workflow_dispatch
    GH->>HW: trigger
    HW->>Bun: setup-bun (pin 1.3.14)
    HW->>VC: "bunx vercel@56.3.1 whoami"
    Note over HW,VC: VERCEL_TOKEN via env var only
    VC->>API: authenticate
    API-->>VC: user info
    VC-->>HW: success / failure

    Note over DW: On docs deploy trigger
    GH->>DW: trigger
    DW->>Bun: setup-bun (pin 1.3.14)
    DW->>DW: bun install --frozen-lockfile
    DW->>DW: write .vercel/project.json
    DW->>VC: "bunx vercel@56.3.1 deploy --prod --yes"
    Note over DW,VC: VERCEL_TOKEN via env var only (no --token arg)
    VC->>API: deploy with CMUX_DOCS_CHANNEL
    API-->>VC: deployment URL
    VC-->>DW: success / failure
Loading
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
sequenceDiagram
    participant GH as GitHub Actions
    participant DW as docs-deploy-reusable.yml
    participant HW as vercel-auth-health.yml
    participant Bun as Bun 1.3.14
    participant VC as vercel@56.3.1
    participant API as Vercel API

    Note over HW: Daily cron (06:17 UTC) or workflow_dispatch
    GH->>HW: trigger
    HW->>Bun: setup-bun (pin 1.3.14)
    HW->>VC: "bunx vercel@56.3.1 whoami"
    Note over HW,VC: VERCEL_TOKEN via env var only
    VC->>API: authenticate
    API-->>VC: user info
    VC-->>HW: success / failure

    Note over DW: On docs deploy trigger
    GH->>DW: trigger
    DW->>Bun: setup-bun (pin 1.3.14)
    DW->>DW: bun install --frozen-lockfile
    DW->>DW: write .vercel/project.json
    DW->>VC: "bunx vercel@56.3.1 deploy --prod --yes"
    Note over DW,VC: VERCEL_TOKEN via env var only (no --token arg)
    VC->>API: deploy with CMUX_DOCS_CHANNEL
    API-->>VC: deployment URL
    VC-->>DW: success / failure
Loading

Reviews (8): Last reviewed commit: "test: keep suite timeout guard determini..." | Re-trigger Greptile

Comment on lines +19 to +22
- name: Verify Vercel token
run: bunx vercel@56.3.1 whoami --token "$VERCEL_TOKEN"
env:
VERCEL_TOKEN: ${{ secrets.VERCEL_TOKEN }}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 The --token "$VERCEL_TOKEN" flag is redundant here — the Vercel CLI automatically reads VERCEL_TOKEN from the environment, which is already set in the env: block. Passing the token as a CLI argument expands it into the process argument list, where it is visible to other processes via /proc/PID/cmdline on Linux (even if GitHub Actions masks it in log output). Dropping the flag achieves the same authentication without that exposure.

Suggested change
- name: Verify Vercel token
run: bunx vercel@56.3.1 whoami --token "$VERCEL_TOKEN"
env:
VERCEL_TOKEN: ${{ secrets.VERCEL_TOKEN }}
- name: Verify Vercel token
run: bunx vercel@56.3.1 whoami
env:
VERCEL_TOKEN: ${{ secrets.VERCEL_TOKEN }}

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@cmuxTests/WorkspaceForkConversationContextMenuTests.swift`:
- Around line 4853-4866: Update expectProcessExited to poll Darwin.kill(pid, 0)
until it returns ESRCH or a short deadline expires, preserving the latest
errno/result for the final assertion. After the deadline, force-kill the
descendant only as cleanup if it is still running, then assert that the
deadline-bounded poll observed ESRCH rather than relying on the single immediate
probe.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 74b6615b-5f05-4c05-910a-cf177f5ff00e

📥 Commits

Reviewing files that changed from the base of the PR and between 626e122 and 1841dd1.

📒 Files selected for processing (1)
  • cmuxTests/WorkspaceForkConversationContextMenuTests.swift

Comment on lines +4853 to +4866
private func expectProcessExited(pidFile: URL) throws {
let rawPID = try String(contentsOf: pidFile, encoding: .utf8)
.trimmingCharacters(in: .whitespacesAndNewlines)
let pid = try #require(pid_t(rawPID))
errno = 0
let result = Darwin.kill(pid, 0)
let processError = errno
if result == 0 {
_ = Darwin.kill(pid, SIGKILL)
}
#expect(
result == -1 && processError == ESRCH,
"The timed-out fork probe must terminate descendant process \(pid)."
)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

Poll for ESRCH before declaring descendant cleanup failed.

The single immediate probe can observe termination or orphan reaping in progress and fail nondeterministically. Use a short deadline-bounded poll, then force-kill only for cleanup after the deadline.

Proposed fix
-        try expectProcessExited(pidFile: childPIDFile)
+        try await expectProcessExited(pidFile: childPIDFile)
-    private func expectProcessExited(pidFile: URL) throws {
+    private func expectProcessExited(pidFile: URL) async throws {
         let rawPID = try String(contentsOf: pidFile, encoding: .utf8)
             .trimmingCharacters(in: .whitespacesAndNewlines)
         let pid = try `#require`(pid_t(rawPID))
-        errno = 0
-        let result = Darwin.kill(pid, 0)
-        let processError = errno
-        if result == 0 {
-            _ = Darwin.kill(pid, SIGKILL)
+
+        let clock = ContinuousClock()
+        let deadline = clock.now.advanced(by: .seconds(2))
+        while clock.now < deadline {
+            errno = 0
+            if Darwin.kill(pid, 0) == -1, errno == ESRCH {
+                return
+            }
+            await Task.yield()
         }
-        `#expect`(
-            result == -1 && processError == ESRCH,
-            "The timed-out fork probe must terminate descendant process \(pid)."
-        )
+
+        _ = Darwin.kill(pid, SIGKILL)
+        Issue.record("The timed-out fork probe must terminate descendant process \(pid).")
     }

As per coding guidelines, tests must “await real completion signals or deadline-bounded polls of real predicates rather than fixed-duration waits before assertions.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmuxTests/WorkspaceForkConversationContextMenuTests.swift` around lines 4853
- 4866, Update expectProcessExited to poll Darwin.kill(pid, 0) until it returns
ESRCH or a short deadline expires, preserving the latest errno/result for the
final assertion. After the deadline, force-kill the descendant only as cleanup
if it is still running, then assert that the deadline-bounded poll observed
ESRCH rather than relying on the single immediate probe.

Source: Coding guidelines

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
tests/test_docs_deploy_auth_guard.py (2)

11-17: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Assert the deployment token mapping.

The deploy command now relies on VERCEL_TOKEN from the environment, but this guard only checks that --token is absent. It would still pass if the secret-to-environment mapping were accidentally removed.

Suggested assertion
         self.assertIn("bunx vercel@56.3.1 deploy", workflow)
         self.assertNotIn("bunx vercel deploy", workflow)
+        self.assertIn(
+            "VERCEL_TOKEN: ${{ secrets.vercel_token }}",
+            workflow,
+        )
         self.assertNotIn("--token", workflow)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/test_docs_deploy_auth_guard.py` around lines 11 - 17, Update
test_docs_deploy_uses_pinned_vercel_cli to assert that the deployment workflow
maps the Vercel secret to the VERCEL_TOKEN environment variable, while retaining
the existing checks for the pinned CLI and absence of --token.

19-27: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Verify the schedule is actually daily.

Checking only for schedule: allows a weekly or monthly cron expression to pass this test, despite the workflow’s daily-probe requirement. Assert the intended cron expression or parse the schedule and validate its cadence.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/test_docs_deploy_auth_guard.py` around lines 19 - 27, Update
test_vercel_auth_is_checked_daily to validate that the workflow’s schedule uses
the intended daily cron expression, rather than only asserting the presence of
“schedule:”. Preserve the existing checks and ensure weekly or monthly schedules
fail the test.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@tests/test_docs_deploy_auth_guard.py`:
- Around line 11-17: Update test_docs_deploy_uses_pinned_vercel_cli to assert
that the deployment workflow maps the Vercel secret to the VERCEL_TOKEN
environment variable, while retaining the existing checks for the pinned CLI and
absence of --token.
- Around line 19-27: Update test_vercel_auth_is_checked_daily to validate that
the workflow’s schedule uses the intended daily cron expression, rather than
only asserting the presence of “schedule:”. Preserve the existing checks and
ensure weekly or monthly schedules fail the test.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 0f6a86f4-f883-47a0-b6a8-ac214fcadae8

📥 Commits

Reviewing files that changed from the base of the PR and between 1841dd1 and f114930.

📒 Files selected for processing (3)
  • .github/workflows/docs-deploy-reusable.yml
  • .github/workflows/vercel-auth-health.yml
  • tests/test_docs_deploy_auth_guard.py

@cursor

cursor Bot commented Jul 17, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@cursor

cursor Bot commented Jul 17, 2026

Copy link
Copy Markdown

Bugbot is paused — on-demand spend limit reached

Bugbot uses usage-based billing for this team and has hit its on-demand spend limit.

A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue.

@lawrencecchen
lawrencecchen merged commit c8138f4 into main Jul 18, 2026
24 checks passed
@lawrencecchen
lawrencecchen deleted the fix-docs-deploy-auth branch July 18, 2026 00:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant