Skip to content

OSAC-2001: add /review-ep comment trigger for EP review workflow - #94

Merged
openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
ItzikEzra-rh:feat/OSAC-2001-manual-ep-review-trigger
Jul 5, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
ItzikEzra-rh:feat/OSAC-2001-manual-ep-review-trigger

Conversation

@ItzikEzra-rh

@ItzikEzra-rh ItzikEzra-rh commented Jul 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add issue_comment trigger on /review-ep — comment on any PR to run the EP review agent on demand
  • Extract PR resolution into a resolve-pr job that normalizes PR number/SHA/base-ref across both trigger types
  • Eyes reaction on /review-ep comments for UX feedback
  • Author association check on comment trigger (MEMBER/COLLABORATOR/OWNER only)
  • Resolve PR base ref dynamically for checkout (supports future release branches)
  • Move concurrency group into the review job to avoid comment-triggered cancellation races
  • All event inputs passed via env: vars to prevent shell injection
  • Zero changes to ep_review.py — it already takes PR_NUMBER from env

How to use

From a PR comment: Comment /review-ep on any PR

Automatic (unchanged): PRs touching prd.md or design.md still trigger automatically

Part of OSAC-2001

Assisted-by: Claude Code noreply@anthropic.com

@openshift-ci-robot

openshift-ci-robot commented Jul 5, 2026 •

Copy link
Copy Markdown

@ItzikEzra-rh: This pull request references OSAC-2001 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the story to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

  • Add workflow_dispatch trigger with pr_number input — review any existing PR from the Actions tab or via gh workflow run
  • Add issue_comment trigger on /review-ep — reviewers comment on a PR and the agent runs automatically
  • Extract PR resolution into a resolve-pr job that normalizes PR number/SHA across all three trigger types
  • Eyes reaction on /review-ep comments for UX feedback
  • Author association check on comment trigger (MEMBER/COLLABORATOR/OWNER only)
  • Zero changes to ep_review.py — it already takes PR_NUMBER from env

How to use

From Actions tab: Go to Actions → EP Review → Run workflow → enter PR number

From a PR comment: Comment /review-ep on any PR

Automatic (unchanged): PRs touching prd.md or design.md still trigger automatically

Part of OSAC-2001

Assisted-by: Claude Code noreply@anthropic.com

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested review from carbonin and mhrivnak July 5, 2026 08:02
@coderabbitai

coderabbitai Bot commented Jul 5, 2026 •

Copy link
Copy Markdown

Review Change Stack

Walkthrough

The ep-review.yml workflow adds workflow_dispatch and issue_comment triggers alongside pull_request_target, introduces a resolve-pr job that computes pr_number and head_sha per event type, updates concurrency grouping, changes checkout ref to main, and sources review job env vars from resolve-pr outputs.

Changes

EP Review Workflow Trigger Expansion

Layer / File(s) Summary
Triggers, concurrency, and resolve-pr job
.github/workflows/ep-review.yml
Adds workflow_dispatch (with pr_number input) and issue_comment created triggers alongside pull_request_target; updates concurrency.group to derive PR number per event type; adds resolve-pr job computing pr_number and head_sha via gh pr view or direct event fields, branching on github.event_name.
Review job checkout and env wiring
.github/workflows/ep-review.yml
Checkout now uses ref: main instead of PR base ref; review job depends on resolve-pr and sources PR_NUMBER/PR_HEAD_SHA env vars from its outputs instead of github.event.pull_request.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
    participant Trigger as GitHub Event
    participant Workflow as ep-review.yml
    participant ResolvePR as resolve-pr job
    participant GH as gh CLI / GitHub API
    participant Review as review job

    Trigger->>Workflow: pull_request_target / workflow_dispatch / issue_comment
    Workflow->>ResolvePR: run resolve-pr job
    alt event is pull_request_target
        ResolvePR->>ResolvePR: read pr_number and head_sha from event fields
    else event is workflow_dispatch or issue_comment
        ResolvePR->>GH: gh pr view --json headRefOid
        GH-->>ResolvePR: pr_number, head_sha
    end
    ResolvePR-->>Review: outputs pr_number, head_sha
    Review->>Review: checkout ref main
    Review->>Review: run ep_review.py with PR_NUMBER, PR_HEAD_SHA
Loading

Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (1 error)

Check name Status Explanation Resolution
No-Injection-Vectors ❌ Error workflow_dispatch interpolates github.event.inputs.pr_number directly into a bash run step before gh pr view, creating a user-input shell injection path. Move pr_number into env, quote it, and validate it before using it in the shell command.
✅ Passed checks (10 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed No new hardcoded secrets, passwords, tokens, private keys, or long base64 blobs were added; only secret references like secrets.GITHUB_TOKEN appear.
No-Weak-Crypto ✅ Passed PASS: The changed workflow contains no weak crypto, custom crypto, or non-constant-time secret comparisons.
Container-Privileges ✅ Passed Only a GitHub Actions workflow changed; it contains no container/K8s spec and no privileged settings like hostPID, privileged, or allowPrivilegeEscalation.
No-Sensitive-Data-In-Logs ✅ Passed No new logging of secrets, PII, tokens, or internal data was added; the workflow only logs PR/SHA status and non-sensitive review progress.
Ai-Attribution ✅ Passed HEAD includes an Assisted-by: Claude Code trailer; no Co-Authored-By AI attribution appears in the commit or workflow diff.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the main change: adding a /review-ep comment trigger to the EP review workflow.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ep-review.yml:
- Around line 35-47: The Acknowledge comment step in the resolve-pr job is
missing the permission required to create an issue-comment reaction. Update the
job-level permissions in ep-review.yml to keep least privilege while adding only
the narrow write access needed for the gh api call in Acknowledge comment, and
leave the existing pull-requests permission unchanged.
- Around line 20-22: Move the concurrency control from the top-level workflow
into the review job so only actual EP review runs share the cancellation group.
Update the review job in the workflow to use the same group key currently built
from github.event.pull_request.number, github.event.inputs.pr_number, or
github.event.issue.number, and remove the workflow-level concurrency so a plain
issue_comment event cannot cancel an in-progress review before resolve-pr is
skipped.
- Line 82: The checkout step is hard-coded to main, so release-branch PRs will
use the wrong base. Update the workflow to use the PR base branch resolved by
resolve-pr, and thread that base ref into the checkout step instead of the
static ref. Make sure the existing resolve-pr output is used consistently
wherever the base branch is needed, especially around the checkout
configuration.
- Around line 49-69: The Resolve PR context step is interpolating
github.event.inputs.pr_number directly inside the run script, which can allow
shell breakout in the workflow_dispatch branch. Move the PR input into an env
variable for the Resolve PR context step, quote the value when assigning PR, and
validate that it is a numeric pull request number before calling gh pr view;
keep the existing pr_number and head_sha outputs in the same resolve step.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: db7ead85-1f7b-4ec1-89ca-afafc47f39fe

📥 Commits

Reviewing files that changed from the base of the PR and between 077a4f1 and 7794eba.

📒 Files selected for processing (1)
  • .github/workflows/ep-review.yml

Comment thread .github/workflows/ep-review.yml Outdated
Comment thread .github/workflows/ep-review.yml
Comment thread .github/workflows/ep-review.yml
Comment thread .github/workflows/ep-review.yml Outdated
@ItzikEzra-rh
ItzikEzra-rh force-pushed the feat/OSAC-2001-manual-ep-review-trigger branch from 7794eba to 329f8c4 Compare July 5, 2026 08:32
Add workflow_dispatch (PR number input) and issue_comment (/review-ep)
triggers so the EP review agent can run on existing PRs, not just new
ones. Extracts PR resolution into a dedicated job that all triggers
feed into.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Itzik Ezra <iezra@redhat.com>
@ItzikEzra-rh
ItzikEzra-rh force-pushed the feat/OSAC-2001-manual-ep-review-trigger branch from 329f8c4 to 9211474 Compare July 5, 2026 09:54
@ItzikEzra-rh ItzikEzra-rh changed the title OSAC-2001: add manual and comment triggers for EP review workflow OSAC-2001: add /review-ep comment trigger for EP review workflow Jul 5, 2026

@eranco74 eranco74 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm
/approve

@openshift-ci

openshift-ci Bot commented Jul 5, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: eranco74, ItzikEzra-rh

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved label Jul 5, 2026
@openshift-merge-bot
openshift-merge-bot Bot merged commit 08d6dea into osac-project:main Jul 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants