Skip to content

chore: sync workflow templates - #118

Closed
stranske wants to merge 1 commit into
mainfrom
sync/workflows-b653eb470804
Closed

stranske wants to merge 1 commit into
mainfrom
sync/workflows-b653eb470804

Conversation

@stranske

@stranske stranske commented Jun 22, 2026 •

Copy link
Copy Markdown
Owner

Sync Summary

Files Updated

  • maint-76-claude-code-review.yml: Claude Code review (opt-in) - runs only on labeled PRs or manual dispatch
  • reference_packs.py: Validates and resolves reference pack configuration for shared runner prompt assembly
  • orchestrator_skill.py: Validates and resolves exported Orchestrator skill context for remote Codex lanes
  • runner_lib/ (1 files): Shared runner prompt assembly, output parsing, and dispatch debounce helpers

Files Skipped

  • pr-00-gate.yml: File exists and sync_mode is create_only
  • ci.yml: File exists and sync_mode is create_only
  • renovate.json: File exists and sync_mode is create_only
  • cross-repo-smoke.yml: File exists and sync_mode is create_only
  • llm_slots.json: None

Review Checklist

  • CI passes with updated workflows
  • No repo-specific customizations were overwritten

Source: stranske/Workflows
Source SHA: 1bc0f231da20f5596199ce25d3923f9230ac4b76
Template hash: b653eb470804
Sync branch: sync/workflows-b653eb470804
Consumer repo: stranske/Fine-Art-Archive
Manifest: .github/sync-manifest.yml

Summary by CodeRabbit

  • New Features

    • Added support for using pre-generated orchestrator skill context summaries alongside fresh materialization.
  • Bug Fixes

    • Strengthened repository validation to enforce strict owner/name format, rejecting previously accepted invalid patterns.
  • Chores

    • Updated Claude Code Review action to latest version.

Automated sync from stranske/Workflows
Template hash: b653eb470804

Changes synced from sync-manifest.yml
@stranske stranske added sync Automated sync from Workflows automated Automated sync from Workflows labels Jun 22, 2026
@stranske
stranske temporarily deployed to agent-standard June 22, 2026 03:40 — with GitHub Actions Inactive
@stranske
stranske temporarily deployed to agent-standard June 22, 2026 03:40 — with GitHub Actions Inactive
@coderabbitai

coderabbitai Bot commented Jun 22, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Two _validate_repo functions (in orchestrator_skill.py and reference_packs.py) are updated to split on / and require exactly two non-empty segments. In runner_lib/core.py, orchestrator skill prompt assembly is extended to accept a pre-generated summary path via ORCHESTRATOR_SKILL_SUMMARY_PATH, suppress FileNotFoundError during directory cleanup, and conditionally append the skill context only when the resolved file exists. The anthropics/claude-code-action workflow pin is also bumped.

Changes

Script: repo validation and orchestrator skill context path support

Layer / File(s) Summary
_validate_repo strict owner/name enforcement
scripts/orchestrator_skill.py, scripts/reference_packs.py
Both _validate_repo functions now split repo on / and require exactly two non-empty parts, rejecting inputs like a/b/c or a//b that the previous boundary-based check accepted.
Orchestrator skill context path and prompt assembly
scripts/runner_lib/core.py
Adds import contextlib; suppresses FileNotFoundError when removing an existing checkout directory before re-materializing; resolves orchestrator_summary_path from either the materialize_orchestrator_skill return value or the new ORCHESTRATOR_SKILL_SUMMARY_PATH env var (relative to workspace if not absolute); appends "Orchestrator Skill Context" to the prompt only when the resolved path points to an existing file.

CI: Claude Code Review workflow

Layer / File(s) Summary
Repinned claude-code-action commit hash
.github/workflows/maint-76-claude-code-review.yml
The uses: reference for anthropics/claude-code-action is updated to a new pinned commit hash; all other inputs and conditions are unchanged.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • stranske/Fine-Art-Archive#97: Also repins anthropics/claude-code-action to a new commit digest in the same workflow file.
  • stranske/Fine-Art-Archive#113: Touches both scripts/orchestrator_skill.py and scripts/runner_lib/core.py for orchestrator-skill plumbing, directly overlapping with the materialization and assemble_prompt changes here.
🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 40.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Title check ❓ Inconclusive The PR title 'chore: sync workflow templates' is vague and generic. It uses non-descriptive terms that don't convey meaningful information about the actual changes made to the repository validation logic and orchestrator skill context handling. Consider a more specific title that reflects the main technical changes, such as 'chore: sync workflow templates and update repository validation logic' or 'chore: update orchestrator skill and repo validation from workflow sync'.
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch sync/workflows-b653eb470804

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actions Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Keepalive Loop Reporter. Do not edit.

@stranske
stranske temporarily deployed to agent-standard June 22, 2026 03:41 — with GitHub Actions Inactive
@github-actions

github-actions Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Agents Gate Followups. Do not edit.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/maint-76-claude-code-review.yml:
- Line 192: The inline version comment in the anthropics/claude-code-action
action reference is inaccurate. Update the comment from `# v1` to `# v1.0.153`
to correctly reflect the actual version tag that corresponds to the specified
commit hash. This ensures the comment accurately documents which version of the
action is being used.

In `@scripts/runner_lib/core.py`:
- Around line 426-431: The `orchestrator_summary_path` currently allows
arbitrary absolute paths to be used when sourced from the environment variable
at line 955, which poses a security risk since the file contents are included in
prompt output at line 465. Modify the path handling logic in the section
starting with the `orchestrator_summary_path` assignment to ensure that the
final resolved path is always constrained within the workspace directory
boundary, regardless of whether it was specified as an absolute or relative
path. Validate that the resolved path is a child of the workspace using path
resolution and comparison methods to prevent arbitrary file inclusion from
untrusted environment inputs.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f70dddfd-e1ef-430c-bdd5-8c01c03d8b8b

📥 Commits

Reviewing files that changed from the base of the PR and between 3dad21e and e1eff08.

📒 Files selected for processing (4)
  • .github/workflows/maint-76-claude-code-review.yml
  • scripts/orchestrator_skill.py
  • scripts/reference_packs.py
  • scripts/runner_lib/core.py
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • stranske/Workflows (auto-detected)
  • stranske/Template (auto-detected)
📜 Review details
🧰 Additional context used
📓 Path-based instructions (4)
**/*.py

📄 CodeRabbit inference engine (.github/copilot-instructions.md)

For Manager-Database repository: use Prefect 2.x and import schedules from prefect.client.schemas.schedules

Files:

  • scripts/reference_packs.py
  • scripts/orchestrator_skill.py
  • scripts/runner_lib/core.py
.github/workflows/*.{yml,yaml}

📄 CodeRabbit inference engine (.github/copilot-instructions.md)

startup_failure in GitHub Actions workflows with zero jobs indicates GitHub couldn't parse the workflow; check for invalid YAML syntax, conflicting permissions: blocks on workflow_call reusable workflows, invalid permission scopes, or circular workflow references

Files:

  • .github/workflows/maint-76-claude-code-review.yml
.github/workflows/*.yml

📄 CodeRabbit inference engine (CLAUDE.md)

Reference reusable workflows with @main by default unless intentionally pinning to an exact commit SHA for a documented reason

Files:

  • .github/workflows/maint-76-claude-code-review.yml
**/.github/workflows/*.yml

📄 CodeRabbit inference engine (AGENTS.md)

Reference reusable workflows with @main unless intentionally pinning to an exact commit SHA for a controlled reason.

Files:

  • .github/workflows/maint-76-claude-code-review.yml
🔀 Multi-repo context stranske/Workflows, stranske/Template

Linked repositories findings

stranske/Workflows [::stranske/Workflows::]

Repository validation change impact

The PR introduces stricter validation of the repo field in both scripts/reference_packs.py and scripts/orchestrator_skill.py. The new _validate_repo function enforces that the repository string must contain exactly two non-empty segments when split by / (format: owner/name).

Breaking validation pattern:

  • scripts/reference_packs.py:_validate_repo() [::stranske/Workflows::] — Changed to reject repo strings that don't match exactly owner/name format (e.g., rejects trend/research/extra, a//b, /a, a/)
  • scripts/orchestrator_skill.py:_validate_repo() [::stranske/Workflows::] — Same stricter validation applied

Test evidence:

  • tests/scripts/test_reference_packs.py:test_parse_reference_packs_rejects_nested_repo_names() [::stranske/Workflows::] — Explicitly validates that "repo": "trend/research/extra" is rejected with error "repo must use owner/name format"
  • tests/scripts/test_orchestrator_skill.py:test_parse_rejects_nested_repo_names() [::stranske/Workflows::] — Same validation rejection for "repo": "owner/repo/extra"

Configuration files affected

Both .github/reference_packs.json and .github/orchestrator_skill.json are optional configuration files where the repo field is validated:

  • docs/ci/ORCHESTRATOR_SKILL_CONTEXT.md [::stranske/Workflows::] — Documents the configuration format and requires repos in format like "stranske/Workflows" and "trend/research"
  • scripts/reference_packs.py:parse_reference_packs() [::stranske/Workflows::] — Validates repo field in pack definitions
  • scripts/orchestrator_skill.py:parse_orchestrator_skill_config() [::stranske/Workflows::] — Validates inline repo field in orchestrator skill config

Runner context changes

scripts/runner_lib/core.py:assemble_prompt() [::stranske/Workflows::] — Now supports conditional materialization of orchestrator skill context:

  • If materialize_orchestrator_skill is enabled, it calls materialize_orchestrator_skill() and captures the returned summary path
  • Otherwise, reads orchestrator_skill_summary_path from context and resolves it relative to workspace when not absolute
  • Only includes "## Orchestrator Skill Context" section if the resolved summary file exists

stranske/Template [::stranske/Template::]

No actual configuration files found — Neither .github/orchestrator_skill.json nor .github/reference_packs.json exist in the Template repository outside of test fixtures, indicating Template itself does not currently consume these features. The synced scripts are present but not actively used.

Breaking change summary

Any consumer repository using .github/reference_packs.json or .github/orchestrator_skill.json with repo fields containing:

  • Multiple slashes (e.g., owner/org/repo)
  • Empty segments (e.g., owner//repo or /owner/repo)
  • Trailing/leading slashes

...will now fail validation during workflow execution with error: "repo must use owner/name format".

🔇 Additional comments (3)
scripts/reference_packs.py (1)

86-87: LGTM!

scripts/runner_lib/core.py (1)

8-8: LGTM!

Also applies to: 370-376, 419-424, 461-462

scripts/orchestrator_skill.py (1)

83-84: Validation code is correct; no config files exist in this repository to validate.

The stricter owner/name validation at lines 83-84 properly enforces the contract (splits on "/" and requires exactly 2 non-empty parts). However, Fine-Art-Archive has no .github/orchestrator_skill.json or .github/reference_packs.json files, so the validation will never be triggered at runtime. The code gracefully handles missing configs by returning None, preventing any failures.

id: claude
continue-on-error: true
uses: anthropics/claude-code-action@51705da45eecce209d4700538bf8377d5b5fc695 # v1
uses: anthropics/claude-code-action@2fee15510437d71399d9139ed60433470484a8fb # v1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Verify the anthropics/claude-code-action commit hash and version

# Check if the commit exists and get its details
echo "=== Checking commit details ==="
gh api repos/anthropics/claude-code-action/commits/2fee15510437d71399d9139ed60433470484a8fb \
  --jq '{sha: .sha, author: .commit.author.name, date: .commit.author.date, message: .commit.message}' 2>&1 || echo "Commit not found or API error"

echo ""
echo "=== Checking tags containing this commit ==="
gh api repos/anthropics/claude-code-action/tags --jq '.[] | select(.commit.sha == "2fee15510437d71399d9139ed60433470484a8fb") | {name: .name, sha: .commit.sha}' 2>&1 || echo "No tags found or API error"

echo ""
echo "=== Checking for security advisories ==="
gh api graphql -f query='
{
  repository(owner: "anthropics", name: "claude-code-action") {
    vulnerabilityAlerts(first: 5) {
      nodes {
        securityVulnerability {
          advisory {
            summary
            severity
            publishedAt
          }
        }
      }
    }
  }
}' 2>&1 || echo "Unable to query advisories or none found"

Repository: stranske/Fine-Art-Archive

Length of output: 497


Update version comment to reflect actual tag: use # v1.0.153 instead of # v1.

The commit hash 2fee15510437d71399d9139ed60433470484a8fb is valid and corresponds to tag v1.0.153 in the anthropics/claude-code-action repository. No security advisories exist for this version. However, the inline comment should be corrected to match the actual version tag for accuracy.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/maint-76-claude-code-review.yml at line 192, The inline
version comment in the anthropics/claude-code-action action reference is
inaccurate. Update the comment from `# v1` to `# v1.0.153` to correctly reflect
the actual version tag that corresponds to the specified commit hash. This
ensures the comment accurately documents which version of the action is being
used.

Comment on lines +426 to +431
orchestrator_summary_raw = context.get("orchestrator_skill_summary_path")
orchestrator_summary_path = (
Path(str(orchestrator_summary_raw)) if orchestrator_summary_raw else None
)
if orchestrator_summary_path and not orchestrator_summary_path.is_absolute():
orchestrator_summary_path = workspace / orchestrator_summary_path

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Constrain orchestrator_skill_summary_path to the workspace boundary.

Line 955 sources the path from env, and Line 426-431 allows absolute paths; Line 465 then reads that file into prompt output. This permits arbitrary file inclusion if the env value is influenced.

Proposed fix
@@
     else:
         orchestrator_summary_raw = context.get("orchestrator_skill_summary_path")
         orchestrator_summary_path = (
             Path(str(orchestrator_summary_raw)) if orchestrator_summary_raw else None
         )
-        if orchestrator_summary_path and not orchestrator_summary_path.is_absolute():
-            orchestrator_summary_path = workspace / orchestrator_summary_path
+        if orchestrator_summary_path:
+            if not orchestrator_summary_path.is_absolute():
+                orchestrator_summary_path = workspace / orchestrator_summary_path
+            orchestrator_summary_path = orchestrator_summary_path.resolve()
+            workspace_root = workspace.resolve()
+            try:
+                orchestrator_summary_path.relative_to(workspace_root)
+            except ValueError as exc:
+                raise ValueError(
+                    "orchestrator_skill_summary_path must resolve within workspace"
+                ) from exc

Also applies to: 461-465, 955-955

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/runner_lib/core.py` around lines 426 - 431, The
`orchestrator_summary_path` currently allows arbitrary absolute paths to be used
when sourced from the environment variable at line 955, which poses a security
risk since the file contents are included in prompt output at line 465. Modify
the path handling logic in the section starting with the
`orchestrator_summary_path` assignment to ensure that the final resolved path is
always constrained within the workspace directory boundary, regardless of
whether it was specified as an absolute or relative path. Validate that the
resolved path is a child of the workspace using path resolution and comparison
methods to prevent arbitrary file inclusion from untrusted environment inputs.

@stranske

Copy link
Copy Markdown
Owner Author

Closing as stale: newer replacement #119 exists from sync/workflows-76689bc445fd.

@stranske stranske closed this Jun 22, 2026
@stranske
stranske deleted the sync/workflows-b653eb470804 branch June 22, 2026 04:16

This branch was previously deployed

1 inactive deployment
agent-standard — e1eff08c Deployed Jun 22, 2026 by stranske via Update keepalive summary #593
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated sync from Workflows sync Automated sync from Workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant