Repository navigation
feat: implement issue #894 — [Fleet Monitor] petry-projects/.github — .github/workflows/ci.yml - #895
Conversation
… .github/workflows/ci.yml
🤖 CodeAnt AI — Review Status
|
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Review limit reached
Next review available in: 47 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughThe CI workflow now downloads actionlint with bounded curl retries. New Bats tests validate this behavior, and a GitHub Actions workflow runs those tests for relevant CI changes. ChangesCI install resilience
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — waiting on PR blockers (intent: review-changes)PR: #895 |
|
Note @don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically. |
PR Summary by QodoHarden CI actionlint download with bounded curl retries + regression tests
AI Description
Diagram
High-Level Assessment
Files changed (4)
|
There was a problem hiding this comment.
Code Review
This pull request introduces a new Bats test suite (install-resilience.bats and its setup helper) to ensure that all curl commands in the CI workflow (ci.yml) use robust retry flags (--retry, --retry-connrefused, and --retry-all-errors) to prevent flaky CI runs. The review feedback highlights two key improvement opportunities in the test logic: first, refining the curl command detection to exclude YAML metadata fields (like name or uses containing the word 'curl') to prevent false positives, and second, using a regular expression to match the --retry flag more robustly (e.g., supporting --retry=5 instead of just space-separated arguments).
Code Review by Qodo
Context used✅ Compliance rules (platform):
87 rules 1.
|
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
There was a problem hiding this comment.
Actionable comments posted: 5
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/ci-tests.yml:
- Around line 34-35: Add the checkout action input persist-credentials: false
beneath the existing actions/checkout configuration in the workflow, preserving
the current repository checkout behavior while disabling GitHub credential
persistence.
In @.github/workflows/ci.yml:
- Around line 62-64: Add explicit curl timeout options to the actionlint archive
download command, including connection and overall/retry duration limits
compatible with the 63-second p95 target. Preserve the existing retry behavior
and download URL while ensuring stalled transfers cannot hold the workflow
indefinitely.
- Around line 62-64: Update the actionlint download command to restrict both
protocols and redirects to HTTPS by adding curl’s --proto '=https' and
--proto-redir '=https' options alongside the existing retry flags. Preserve the
current URL, output path, and download behavior.
In `@test/workflows/ci/install-resilience.bats`:
- Around line 44-50: Update the retry-option assertion in the curl command loop
to extract the numeric value following --retry and validate that it is a
positive budget, preferably within 1..3, rather than only checking the option’s
presence. Keep the existing --retry-connrefused and --retry-all-errors
assertions unchanged.
- Around line 29-32: Update the continuation check in the line-processing loop
to match exactly one trailing backslash, using the appropriate unescaped
backslash glob pattern instead of the current two-character quoted pattern.
Preserve the existing removal of the continuation marker and command-joining
behavior.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: b0f305f0-78b7-40f4-9ddd-d16e6c56dd25
📒 Files selected for processing (4)
.github/workflows/ci-tests.yml.github/workflows/ci.ymltest/workflows/ci/helpers/setup.bashtest/workflows/ci/install-resilience.bats
Dev-Lead — fix-bot-comment (applied)Changes committed and pushed. |
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
|
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: MEDIUM
Reviewed commit: 3486ab83284bc92be76487432d5f6e6983681f45
Review mode: triage-approved (single reviewer)
Summary
Hardens the flaky actionlint download in ci.yml (issue #894, 14.3% failure rate) with bounded curl retries (--retry 3, --retry-connrefused, --retry-all-errors) plus HTTPS-only protocol enforcement, while preserving the existing pinned version + SHA-256 checksum verification. Adds a bats regression suite that asserts every curl download in ci.yml carries bounded retries, and a path-filtered ci-tests.yml workflow to run it.
Linked issue analysis
Closes #894 ([Fleet Monitor] ci.yml WARNING — 14.3% failure rate). The root cause (bare curl aborting on transient GitHub Releases errors) is directly fixed with a finite retry budget, and the regression test prevents silent reintroduction. Substantively addressed.
Findings
- ci.yml: retry flags are bounded (fails fast if the mirror is truly down); checksum verification unchanged, so integrity guarantees are preserved. No security regression.
- ci-tests.yml: least-privilege permissions (top-level {}, job-level contents: read), persist-credentials: false, 10-minute timeout, concurrency cancellation. actions/checkout pin 9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 verified via the GitHub API as the v7.0.0 tag commit.
- install-resilience.bats: continuation-line joining correctly treats multi-line curl commands as single invocations; asserts a finite retry budget and transient-error coverage.
- Secret scan: run_secret_scanning MCP tool not available in this session; gitleaks CI check passed and no secrets appear in the diff.
- Prior CodeRabbit CHANGES_REQUESTED was resolved (dismissed, later approved); no unresolved review threads remain.
CI status
All checks green at 3486ab8: Lint, bats (x2), ShellCheck, CodeQL, Analyze (actions), Secret scan (gitleaks), Agent Security Scan, AgentShield, SonarCloud, npm audit, CodeRabbit, Graphite AI Reviews. Two CANCELLED dev-lead relay entries are superseded duplicates of successful runs.
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: MEDIUM
Reviewed commit: 3486ab83284bc92be76487432d5f6e6983681f45
Review mode: triage-approved (single reviewer)
Summary
Adds bounded curl retries to the actionlint download in ci.yml (fixing the ~14% flaky failure rate from issue #894), plus a bats regression suite and a ci-tests.yml workflow to run it. The change improves security posture (--proto '=https' enforcement added; sha256 checksum verification retained) and the triage low-risk assessment is confirmed correct.
Linked issue analysis
Issue #894 (Fleet Monitor: ci.yml 14.3% failure rate, WARNING) is substantively addressed: the bare curl download that aborted on transient GitHub Releases errors now has --retry 3 with bounded timeouts, --retry-connrefused, and --retry-all-errors. A regression test asserts every curl in ci.yml keeps bounded retries, preventing silent reintroduction.
Findings
- No blocking findings.
- Security checks pass: actions/checkout pin 9c091bb2… verified via GitHub API as the genuine v7.0.0 tag commit; ci-tests.yml uses top-level
permissions: {}, job-scopedcontents: read,persist-credentials: false, timeout, and concurrency cancellation. - The ci.yml curl hardening adds
--proto '=https' --proto-redir '=https'and keeps sha256 verification, so--retry-all-errorscannot smuggle a corrupted artifact past the checksum. - Test quality: the bats parser joins backslash-continued lines and the
--retry[[:space:]=][1-9]assertion correctly rejects--retry 0and does not false-match--retry-connrefused. - All 9 review threads (gemini, qodo, GHAS/Sonar, CodeRabbit, Graphite) are resolved; CodeRabbit's earlier changes-requested was dismissed and superseded by its approval. Review decision is APPROVED (coderabbitai + donpetry-bot). don-petry review entries are dev-lead automation status posts with no open questions.
- MCP secret scanning tool not available in this run; noted per protocol — gitleaks CI check passed and the diff contains no credential material.
CI status
All substantive checks green: Lint, bats (×2), Analyze (actions)/CodeQL, ShellCheck, Secret scan (gitleaks), Agent Security Scan, npm audit, SonarCloud, agent-shield, CodeRabbit, Graphite. Skipped audits (pip/cargo/govulncheck/pnpm) are ecosystem-detection skips. Two CANCELLED dev-lead dispatch/ci-relay entries are superseded agent-orchestration runs with later SUCCESS duplicates of the same checks — not build failures.
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.



User description
Closes #894
Implemented by dev-lead agent. Please review.
CodeAnt-AI Description
Reduce flaky CI workflow failures when downloading Actionlint
What Changed
Impact
✅ Fewer flaky CI failures✅ More reliable workflow linting✅ Lower chance of false build failures during dependency downloads💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.
Summary by CodeRabbit