Skip to content

OSAC-2145: always post new review comment, review only changed files - #103

Merged
openshift-merge-bot[bot] merged 2 commits into
osac-project:mainfrom
ItzikEzra-rh:feat/OSAC-2145-always-new-comment
Jul 7, 2026
Merged

openshift-merge-bot[bot] merged 2 commits into
osac-project:mainfrom
ItzikEzra-rh:feat/OSAC-2145-always-new-comment

Conversation

@ItzikEzra-rh

@ItzikEzra-rh ItzikEzra-rh commented Jul 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Always post a new comment instead of updating existing ones — preserves review history
  • For synchronize events, only review files changed in the latest push — updating prd.md won't re-trigger the design review
  • Each review type (PRD/design) operates independently on dual PRs

Test plan

  • Initial PR with both prd.md + design.md → 2 separate comments
  • Update only prd.md → 1 new PRD comment, no design comment
  • Update both files → 2 new comments

Test evidence

ItzikEzra-rh#14

Generated with Claude Code

Summary by CodeRabbit

  • New Features
    • Review checks now focus on only the files changed in the latest push for updated pull requests, making feedback faster and more relevant.
  • Bug Fixes
    • Review comments are now posted as a fresh comment instead of trying to update an older one.
    • Log and status messages were refined to better reflect what was reviewed and why something was skipped.

ItzikEzra-rh and others added 2 commits July 7, 2026 12:25
When a PR has both prd.md and design.md, the design review was
overwriting the PRD comment. Now each review only looks for its
own marker when checking for existing comments.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Always post a new comment instead of updating existing ones
- For synchronize events, only review files changed in the push
- Each review type uses its own marker independently

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@openshift-ci-robot

openshift-ci-robot commented Jul 7, 2026 •

Copy link
Copy Markdown

@ItzikEzra-rh: This pull request references OSAC-2145 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the bug to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

  • Always post a new comment instead of updating existing ones — preserves review history
  • For synchronize events, only review files changed in the latest push — updating prd.md won't re-trigger the design review
  • Each review type (PRD/design) operates independently on dual PRs

Test plan

  • Initial PR with both prd.md + design.md → 2 separate comments
  • Update only prd.md → 1 new PRD comment, no design comment
  • Update both files → 2 new comments

Test evidence

ItzikEzra-rh#14

Generated with Claude Code

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested review from avishayt and rccrdpccl July 7, 2026 11:14
@coderabbitai

coderabbitai Bot commented Jul 7, 2026 •

Copy link
Copy Markdown

Review Change Stack

Walkthrough

Changes modify GitHub Actions automation scripts: ep_hooks.py now always posts a new PR review comment via gh pr comment --body-file rather than patching an existing comment; ep_review.py adds incremental file detection for synchronize events using the GitHub compare API; and ep-review.yml passes new event-related environment variables to the review script.

Changes

EP Review Automation

Layer / File(s) Summary
Comment posting behavior
.github/scripts/ep_hooks.py
Removes prior lookup/PATCH of an existing bot review comment; always writes the comment to a temp markdown file and posts a new PR comment via gh pr comment --body-file.
Incremental diff detection
.github/scripts/ep_review.py
Adds get_incremental_files(before_sha, head_sha) using the GitHub compare API; main() branches on synchronize events to use incremental files, falling back to full PR file list, with updated log messages.
Workflow env wiring
.github/workflows/ep-review.yml
Adds EVENT_NAME, EVENT_ACTION, and EVENT_BEFORE_SHA environment variables to the "Run EP review" step.

Estimated code review effort: 2 (Simple) | ~10 minutes

Sequence Diagram(s)

sequenceDiagram
    participant Workflow as ep-review.yml
    participant Script as ep_review.py
    participant GH as GitHub API

    Workflow->>Script: Run with EVENT_NAME, EVENT_ACTION, EVENT_BEFORE_SHA
    alt EVENT_ACTION is synchronize
        Script->>GH: compare(before_sha, head_sha)
        GH-->>Script: incremental changed files
    else other event action
        Script->>GH: get PR files
        GH-->>Script: full changed files list
    end
    Script->>Script: filter reviewable .md docs
    Script->>GH: gh pr comment --body-file (post new review comment)
Loading

Estimated code review effort: 2 (Simple) | ~10 minutes

🚥 Pre-merge checks | ✅ 10 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Ai-Attribution ⚠️ Warning PR/commits mention Claude Code, but the branch only uses Co-Authored-By trailers; no Assisted-by or Generated-by Red Hat attribution found. Add Red Hat Assisted-by or Generated-by trailers for any AI-assisted commits, and avoid Co-Authored-By for AI tools.
✅ Passed checks (10 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main changes: new review comments are always posted and reviews are limited to changed files.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed No hardcoded secrets, credential literals, or embedded URLs found in the touched files; workflow only references secrets via env vars.
No-Weak-Crypto ✅ Passed Changed scripts only handle PR SHAs/comments; no MD5/SHA1/DES/RC4/3DES/Blowfish/ECB, custom crypto, or secret/token comparisons found.
No-Injection-Vectors ✅ Passed No flagged injection APIs found; subprocess calls use argv lists, and the new comment path posts via --body-file from a temp file, not shell execution.
Container-Privileges ✅ Passed Only scripts and a workflow changed; no container/K8s manifest was added or modified, and the workflow adds no privileged or host namespace settings.
No-Sensitive-Data-In-Logs ✅ Passed Logs only emit SHA prefixes, skill names, scores, and status; no secrets, PII, or raw comment bodies are printed.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@eranco74

eranco74 commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

/lgtm

@eranco74

eranco74 commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

/approve

@openshift-ci

openshift-ci Bot commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: eranco74, ItzikEzra-rh

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved label Jul 7, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/scripts/ep_hooks.py (1)

60-73: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Scope the pre-gate to the active skill marker. .github/scripts/ep_hooks.py:60-73 still treats any bot comment with the current head SHA as “already reviewed,” while both skills share the same reviewed_label. Since run_review() only stores _skill_name on ticket and check_pr_state() ignores it, the first review will block the other one as soon as the shared label is set. Filter by the running skill’s marker instead of matching both comment types.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/scripts/ep_hooks.py around lines 60 - 73, The pre-gate in
check_pr_state is too broad because it treats any bot comment with the current
head SHA as already reviewed, causing one skill’s review to block the other
under the shared reviewed_label. Update check_pr_state to use the active skill
marker from ticket["_skill_name"] (set by run_review) when selecting existing
comments, so it only matches the comment type for the currently running skill
instead of both "AI EP Review:" and "AI Design Review:".
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/scripts/ep_review.py:
- Around line 43-47: get_incremental_files() currently relies on the compare
API, which can truncate the file list at 300 entries and cause missed
review-triggering changes. Update get_incremental_files() to detect when the
compare result reaches that cap and then fall back to a full-diff source such as
get_changed_files(pr_number) so prd.md/design.md changes are not skipped; use
the existing compare call and the incremental file collection path as the place
to add this fallback.
- Around line 126-130: The synchronize path in get_incremental_files() can still
fail when gh() raises RuntimeError, so the review aborts instead of falling
back. Update the event_action == "synchronize" branch to catch compare failures
around get_incremental_files(before_sha, head_sha) and on error use
get_changed_files(pr_number) as the fallback, keeping the existing print/log
context for the incremental attempt.

---

Outside diff comments:
In @.github/scripts/ep_hooks.py:
- Around line 60-73: The pre-gate in check_pr_state is too broad because it
treats any bot comment with the current head SHA as already reviewed, causing
one skill’s review to block the other under the shared reviewed_label. Update
check_pr_state to use the active skill marker from ticket["_skill_name"] (set by
run_review) when selecting existing comments, so it only matches the comment
type for the currently running skill instead of both "AI EP Review:" and "AI
Design Review:".
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: 6cbd249b-cfb2-4c0d-a9f0-1c03643fc34a

📥 Commits

Reviewing files that changed from the base of the PR and between d7c7859 and 347c982.

📒 Files selected for processing (3)
  • .github/scripts/ep_hooks.py
  • .github/scripts/ep_review.py
  • .github/workflows/ep-review.yml

Comment on lines +43 to +47
def get_incremental_files(before_sha, head_sha):
raw = gh(["api", f"repos/{REPO}/compare/{before_sha}...{head_sha}",
"--jq", "[.files[].filename]"])
return json.loads(raw) if raw.strip() else []

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Locate the review script and nearby helpers.
git ls-files '.github/scripts/*' '.github/**' | sed -n '1,120p'

echo
echo "=== outline: .github/scripts/ep_review.py ==="
ast-grep outline .github/scripts/ep_review.py --view expanded || true

echo
echo "=== relevant lines in .github/scripts/ep_review.py ==="
cat -n .github/scripts/ep_review.py | sed -n '1,220p'

echo
echo "=== search for get_changed_files / detect_skills / compare usage ==="
rg -n "get_changed_files|get_incremental_files|detect_skills|compare/" .github/scripts .github -S

Repository: osac-project/enhancement-proposals

Length of output: 9510


🌐 Web query:

GitHub REST API compare two commits files array capped 300 pagination compare endpoint files not paginated

💡 Result:

The GitHub REST API "Compare two commits" endpoint (/repos/{owner}/{repo}/compare/{basehead}) does not support pagination for the list of changed files [1][2]. While the endpoint itself supports pagination for the list of commits, the files array in the response is capped at a maximum of 300 files and is only returned on the first page of results [1][3][4]. Even when implementing pagination (using the page and per_page parameters to retrieve all commits), the API does not provide a mechanism to fetch additional pages of files beyond the initial 300 [5][2][4]. Consequently, if a comparison involves more than 300 changed files, the REST API cannot be used to retrieve the full list of files [3][2]. To obtain a complete list of changed files for large comparisons, common workarounds include: 1. Using the diff format by setting the Accept header to application/vnd.github.v3.diff [3]. This returns the full diff, from which you can parse the list of files [3]. 2. Fetching commits individually and aggregating the changed files for each commit [6]. Top Results: [1][3][2][4]

Citations:


Handle the 300-file cap in compare diffs
get_incremental_files() uses the compare endpoint, which stops at 300 files and does not paginate that list. A large synchronize push can miss prd.md/design.md changes and skip a review; fall back to get_changed_files(pr_number) or another full-diff source once the compare result hits that cap.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/scripts/ep_review.py around lines 43 - 47, get_incremental_files()
currently relies on the compare API, which can truncate the file list at 300
entries and cause missed review-triggering changes. Update
get_incremental_files() to detect when the compare result reaches that cap and
then fall back to a full-diff source such as get_changed_files(pr_number) so
prd.md/design.md changes are not skipped; use the existing compare call and the
incremental file collection path as the place to add this fallback.

Comment on lines +126 to +130
if event_action == "synchronize" and before_sha and head_sha:
files = get_incremental_files(before_sha, head_sha)
print(f"Synchronize: checking incremental diff ({before_sha[:8]}..{head_sha[:8]})")
else:
files = get_changed_files(pr_number)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '== File map ==\n'
git ls-files .github/scripts/ep_review.py
printf '\n== Outline ==\n'
ast-grep outline .github/scripts/ep_review.py --view expanded || true

printf '\n== Relevant sections ==\n'
nl -ba .github/scripts/ep_review.py | sed -n '1,220p'

printf '\n== Symbols ==\n'
rg -n "def (gh|get_incremental_files|get_changed_files)|event_action|before_sha|head_sha" .github/scripts/ep_review.py

Repository: osac-project/enhancement-proposals

Length of output: 743


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '== lines 1-180 =='
sed -n '1,180p' .github/scripts/ep_review.py | cat -n

echo
echo '== get_incremental_files / main context =='
sed -n '20,150p' .github/scripts/ep_review.py | cat -n

Repository: osac-project/enhancement-proposals

Length of output: 12486


🏁 Script executed:

#!/bin/bash
set -euo pipefail

sed -n '20,150p' .github/scripts/ep_review.py | cat -n

Repository: osac-project/enhancement-proposals

Length of output: 5431


🏁 Script executed:

#!/bin/bash
set -euo pipefail
sed -n '20,150p' .github/scripts/ep_review.py | cat -n

Repository: osac-project/enhancement-proposals

Length of output: 5431


🏁 Script executed:

#!/bin/bash
set -euo pipefail
rg -n "except RuntimeError|subprocess|raise RuntimeError|get_incremental_files|get_changed_files|def gh" .github/scripts/ep_review.py

Repository: osac-project/enhancement-proposals

Length of output: 483


🏁 Script executed:

#!/bin/bash
set -euo pipefail
python3 - <<'PY'
from pathlib import Path
p = Path('.github/scripts/ep_review.py')
text = p.read_text()
for needle in ['def gh(', 'def get_changed_files(', 'def get_incremental_files(', 'def main(']:
    idx = text.find(needle)
    print(f'## {needle} at {idx}')
    if idx != -1:
        start = text.rfind('\n', 0, idx - 200)
        end = text.find('\n', idx + 800)
        snippet = text[max(0, idx-200):min(len(text), idx+1200)]
        print(snippet)
        print()
PY

Repository: osac-project/enhancement-proposals

Length of output: 5890


Fallback to full PR file list on compare failure. get_incremental_files() can still raise here because gh() turns non-zero exits into RuntimeError in CI. A rewritten before_sha or all-zero SHA will abort the review instead of falling back to get_changed_files(pr_number).

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/scripts/ep_review.py around lines 126 - 130, The synchronize path in
get_incremental_files() can still fail when gh() raises RuntimeError, so the
review aborts instead of falling back. Update the event_action == "synchronize"
branch to catch compare failures around get_incremental_files(before_sha,
head_sha) and on error use get_changed_files(pr_number) as the fallback, keeping
the existing print/log context for the incremental attempt.

@openshift-merge-bot
openshift-merge-bot Bot merged commit 44c2fdf into osac-project:main Jul 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants