Skip to content

chore: sync workflow templates - #132

Closed
stranske wants to merge 1 commit into
mainfrom
sync/workflows-d0d4ad2bdd25
Closed

stranske wants to merge 1 commit into
mainfrom
sync/workflows-d0d4ad2bdd25

Conversation

@stranske

@stranske stranske commented Jun 23, 2026 •

Copy link
Copy Markdown
Owner

Sync Summary

Files Updated

  • agents-guard.yml: Agents guard - enforces agents workflow protections (Health 45)
  • tokens.css: Design-system theme tokens (theme-air/theme-paper + density axis). Override tokens in an app stylesheet loaded after this; do not fork.
  • components.css: Design-system component layer (.ds): panels/appbar/kpis/tables/fields + presentation-state patterns (.notice, .empty-state, .badge, .skeleton).
  • ds_streamlit.py: Streamlit adapter for the design system (inject_theme/empty_state/notice/error/translate_error/dev_note/availability_badge/humanize_id) so Streamlit apps consume the same presentation patterns.
  • PRESENTATION_PATTERNS.md: The presentation-patterns standard (P1-P6): the rule behind each pattern + per-app-type application + the finding->pattern map from the 2026-06 UX-Review fleet baseline.
  • README.md: Design-system usage guide: how to apply the theme + components/kit per app type.

Files Skipped

  • pr-00-gate.yml: File exists and sync_mode is create_only
  • ci.yml: File exists and sync_mode is create_only
  • renovate.json: File exists and sync_mode is create_only
  • cross-repo-smoke.yml: File exists and sync_mode is create_only
  • llm_slots.json: None

Review Checklist

  • CI passes with updated workflows
  • No repo-specific customizations were overwritten

Source: stranske/Workflows
Source SHA: dfe0854ae9b1ba1c616e4b57fb498f283ea3216f
Template hash: d0d4ad2bdd25
Sync branch: sync/workflows-d0d4ad2bdd25
Consumer repo: stranske/Fine-Art-Archive
Manifest: .github/sync-manifest.yml

Summary by CodeRabbit

Release Notes

  • New Features

    • Added keyboard focus indicators for interactive elements.
    • Added support for reduced-motion accessibility preference with static animations.
  • Bug Fixes

    • Improved security in display components through HTML sanitization.
    • Enhanced error message mapping with case-insensitive pattern matching.
  • Documentation

    • Updated design system documentation with current tooling and distribution details.
  • Style

    • Updated system font stack for improved rendering across platforms.

Automated sync from stranske/Workflows
Template hash: d0d4ad2bdd25

Changes synced from sync-manifest.yml
@stranske stranske added sync Automated sync from Workflows automated Automated sync from Workflows labels Jun 23, 2026
@stranske
stranske temporarily deployed to agent-standard June 23, 2026 08:28 — with GitHub Actions Inactive
@stranske
stranske temporarily deployed to agent-standard June 23, 2026 08:28 — with GitHub Actions Inactive
@coderabbitai

coderabbitai Bot commented Jun 23, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Updates the design system CSS with font-token corrections and accessibility rules (focus-visible, prefers-reduced-motion), hardens Streamlit UI helpers with HTML escaping and case-insensitive error translation, adds a diagnostics_expander() context manager, aligns docs to the shared kit model, and bumps a pinned CI action SHA.

Changes

Design System Updates

Layer / File(s) Summary
CSS token and accessibility additions
design-system/tokens.css, design-system/components.css
--font-body token updated to system-ui-first stack; "Georgia" quoted in --font-heading; :focus-visible outline added for .ds interactive elements; prefers-reduced-motion block disables skeleton shimmer animation.
Streamlit helper HTML escaping, error translation, and new exports
design-system/ds_streamlit.py
Imports contextmanager and escape; empty_state() and notice() escape injected strings before unsafe_allow_html; translate_error() uses case-insensitive matching via text_lower; diagnostics_expander() added as a new exported context manager; availability_badge() returns plain text; humanize_id() uses last colon-separated segment.
Design system README and pattern docs update
design-system/README.md, design-system/PRESENTATION_PATTERNS.md
README title changed to "Shared Design System"; ds_streamlit.py replaces index.html/preview.html in the Files table; Status section rewritten to describe sync-manifest distribution; blank-line formatting normalized in PRESENTATION_PATTERNS.md around P2–P6 section boundaries.

CI Workflow SHA Pin Update

Layer / File(s) Summary
agents-guard.yml fallback action SHA update
.github/workflows/agents-guard.yml
Pinned uses: SHA for the stranske/Workflows/.github/actions/setup-api-client fallback step updated to 44965d8d784573c119fb63828c05c89256c5f3e1 in both the pull_request_target and pull_request event jobs.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related PRs

  • stranske/Fine-Art-Archive#112: Touches the same agents-guard.yml workflow-template sync logic and the same setup-api-client fallback uses: step that this PR updates.
  • stranske/Fine-Art-Archive#130: Also updates the pinned stranske/Workflows/.github/actions/setup-api-client commit SHA in the Workflows fallback steps of agents-guard.yml.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Title check ⚠️ Warning The title 'chore: sync workflow templates' is vague and does not accurately reflect the full scope of changes. The PR updates multiple design-system files (CSS, Python, Markdown) and documentation in addition to workflow templates. Consider a more specific title like 'chore: sync workflow and design-system templates' or detail the main changes affected.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch sync/workflows-d0d4ad2bdd25

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Agents Gate Followups. Do not edit.

@github-actions

github-actions Bot commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Keepalive Loop Reporter. Do not edit.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@design-system/ds_streamlit.py`:
- Around line 115-121: The docstring for the `action` parameter indicates it
accepts markdown, but the implementation HTML-escapes the action parameter
before inserting it into the div element, which prevents markdown syntax from
being parsed. Update the docstring to accurately reflect that the `action`
parameter accepts literal text only (not markdown), or if markdown support is
intended, remove the escape call on the action parameter and add a comment
explaining any security considerations or trade-offs associated with this
change. Ensure the documentation matches the actual behavior that callers will
experience.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b7673469-50a7-457f-9fb7-7ae70ac718af

📥 Commits

Reviewing files that changed from the base of the PR and between 33526af and c95f3cb.

📒 Files selected for processing (6)
  • .github/workflows/agents-guard.yml
  • design-system/PRESENTATION_PATTERNS.md
  • design-system/README.md
  • design-system/components.css
  • design-system/ds_streamlit.py
  • design-system/tokens.css
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • stranske/Workflows (auto-detected)
  • stranske/Template (auto-detected)
📜 Review details
🧰 Additional context used
📓 Path-based instructions (6)
.github/workflows/*.{yml,yaml}

📄 CodeRabbit inference engine (.github/copilot-instructions.md)

startup_failure in GitHub Actions workflows with zero jobs indicates GitHub couldn't parse the workflow; check for invalid YAML syntax, conflicting permissions: blocks on workflow_call reusable workflows, invalid permission scopes, or circular workflow references

Files:

  • .github/workflows/agents-guard.yml
.github/workflows/*.yml

📄 CodeRabbit inference engine (CLAUDE.md)

Reference reusable workflows with @main by default unless intentionally pinning to an exact commit SHA for a documented reason

Files:

  • .github/workflows/agents-guard.yml
{.github/workflows/agents-*.yml,.github/workflows/autofix.yml,.github/codex/**,docs/**}

📄 CodeRabbit inference engine (CLAUDE.md)

Synced workflows, prompts, scripts, and consumer docs are managed through .github/sync-manifest.yml in Workflows and should not be edited locally

Files:

  • .github/workflows/agents-guard.yml
**/.github/workflows/*.yml

📄 CodeRabbit inference engine (AGENTS.md)

Reference reusable workflows with @main unless intentionally pinning to an exact commit SHA for a controlled reason.

Files:

  • .github/workflows/agents-guard.yml
{**/.github/workflows/agents-*.yml,.github/workflows/autofix.yml,.github/codex/**,docs/ops/CONSUMER_REPO_MAINTENANCE.md,docs/keepalive/Agents.md}

📄 CodeRabbit inference engine (AGENTS.md)

Synced workflows, prompts, scripts, and consumer docs (including agents-*.yml, autofix.yml, .github/codex/ prompts, and synced scripts) are managed through .github/sync-manifest.yml in Workflows and should not be edited locally; fix issues in Workflows instead.

Files:

  • .github/workflows/agents-guard.yml
**/*.py

📄 CodeRabbit inference engine (.github/copilot-instructions.md)

For Manager-Database repository: use Prefect 2.x and import schedules from prefect.client.schemas.schedules

Files:

  • design-system/ds_streamlit.py
🪛 LanguageTool
design-system/README.md

[uncategorized] ~50-~50: The official name of this software platform is spelled with a capital “H”.
Context: ...m/and distributed by Maint 68 through.github/sync-manifest.yml`. Update it here firs...

(GITHUB)

🔀 Multi-repo context stranske/Workflows

Perfect! Now I have a complete picture. Let me document my findings:

Linked repositories findings

Based on my exploration of stranske/Workflows and stranske/Template, I've identified critical breaking changes in the synced ds_streamlit.py module that will affect downstream consumer repositories.

Breaking API Changes in ds_streamlit.py

[::stranske/Workflows::]

1. availability_badge(label) return value — BREAKING CHANGE

  • Old behavior (stranske/Template design-system/ds_streamlit.py): Returns HTML markup <span class='ds-badge'>{label}</span>
  • New behavior (synced version): Returns plain string · {str(label).strip()}
  • Impact: Any Streamlit app using availability_badge() in tab titles will now display plain text with a bullet separator instead of styled HTML badge. Visual presentation changes from styled badge to plain marker.

2. humanize_id(raw, mapping) ID parsing logic — BREAKING CHANGE

  • Old behavior (stranske/Template): Takes the FIRST colon-separated segment: split(":")[0]
  • New behavior (synced version): Takes the LAST colon-separated segment: split(":")[-1]
  • Impact: IDs with colons (e.g., "prefix:item:id123") will now be decoded to "id123" instead of "prefix". This changes the human-readable label displayed to users. Any app relying on the old behavior will show incorrect decoded labels.

3. Security hardening in empty_state() — NON-BREAKING

  • icon, title, desc parameters are now HTML-escaped before interpolation into markdown
  • File: ./templates/consumer-repo/design-system/ds_streamlit.py lines ~75-85
  • Impact: Strengthens XSS protection but should not break existing calls unless code was intentionally passing raw HTML

4. Security hardening in notice() — NON-BREAKING

  • title, body, action parameters are now HTML-escaped
  • File: ./templates/consumer-repo/design-system/ds_streamlit.py lines ~100-108
  • Impact: Strengthens XSS protection

5. translate_error() matching logic — BEHAVIOR IMPROVEMENT

  • Changed from case-sensitive substring matching ("financing_mode" in text, "No investable funds") to case-insensitive matching using text_lower variable
  • File: ./templates/consumer-repo/design-system/ds_streamlit.py lines ~125-140
  • Impact: More robust error pattern matching; existing error handling may catch more cases

6. New function added: diagnostics_expander()

  • Added contextmanager for P4 (diagnostics) pattern
  • File: ./templates/consumer-repo/design-system/ds_streamlit.py lines ~162-167
  • Impact: Non-breaking addition; purely optional enhancement

Documentation Alignment

[::stranske/Workflows::]

The PRESENTATION_PATTERNS.md confirms these functions are part of the design-system rollout strategy:

  • P5 (availability_badge): "Streamlit: ds_streamlit.availability_badge(label) in the tab title / disabled control caption"
  • P6 (humanize_id): "decode internal IDs...into human-readable labels before display"

The patterns are documented as standards that will be "synced fleet-wide" to consumer repositories via .github/sync-manifest.yml.

Key Review Considerations

  1. Downstream impact: The change affects all consumer repositories that have been or will be synced from this template. Any Streamlit apps using availability_badge() or humanize_id() will experience behavior changes.

  2. No current internal usages found: Neither stranske/Template nor stranske/Workflows/templates/consumer-repo show active usages of these functions outside their definitions, suggesting they are forward-looking API additions for new consumer implementations.

  3. Design intent: The changes align with the stated goal of "hardening synced design system helpers" (commit message: dfe0854 fix: harden synced design system helpers (#2511)), prioritizing security and correctness of ID parsing.

🔇 Additional comments (7)
design-system/tokens.css (1)

29-29: LGTM!

Also applies to: 74-74

design-system/components.css (1)

41-41: LGTM!

Also applies to: 97-99

design-system/ds_streamlit.py (2)

29-30: LGTM!

Also applies to: 93-98, 137-149, 165-171


174-185: 🎯 Functional Correctness

This review comment should be removed. The availability_badge() and humanize_id() functions are newly synced helpers that Fine-Art-Archive does not call or depend on, so downstream compatibility concerns do not apply to this repository. These functions were added in the initial template sync (commit c95f3cb) and have zero call sites in the codebase.

			> Likely an incorrect or invalid review comment.
design-system/README.md (1)

1-1: LGTM!

Also applies to: 41-41, 50-50

design-system/PRESENTATION_PATTERNS.md (1)

17-24: LGTM!

Also applies to: 33-33, 43-51, 60-60

.github/workflows/agents-guard.yml (1)

114-114: LGTM!

Also applies to: 183-183

Comment on lines +115 to +121
head = f"<strong>{escape(str(title))}</strong><br>" if title else ""
act = f"<div style='margin-top:6px'>{escape(str(action))}</div>" if action else ""
safe_body = escape(str(body))
st.markdown(
f"<div class='ds-notice' style='background:{bg};border-color:{color}33'>"
f"<span class='ic' style='color:{color}'>{ic}</span>"
f"<div>{head}{body}{act}</div></div>",
f"<div>{head}{safe_body}{act}</div></div>",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Locate notice() usages and nearby arguments.
rg -nP --type=py -C3 '\bnotice\s*\('
rg -nP --type=py -C3 '\baction\s*='

Repository: stranske/Fine-Art-Archive

Length of output: 163


🌐 Web query:

In Streamlit, when using st.markdown(..., unsafe_allow_html=True), is Markdown syntax inside an injected HTML <div> rendered as Markdown (e.g., links), or displayed literally?

💡 Result:

In Streamlit, when using st.markdown(..., unsafe_allow_html=True), Markdown syntax inside an HTML

is generally treated as raw HTML and may not be parsed as Markdown [1][2]. Historically, this behavior has been a known limitation because Streamlit's Markdown parser (typically react-markdown) often treats content inside block-level HTML tags like
as raw HTML, causing Markdown features—such as links or bold text—within those tags to be displayed literally rather than rendered [1][2]. However, this behavior is subject to updates and improvements. For example, as of early 2026, specific issues regarding the failure of Markdown links to render inside
blocks have been addressed via improvements to Streamlit's internal processing, which pre-processes such content to ensure Markdown-style links are converted correctly before the final rendering [2]. If you encounter issues where Markdown syntax is not rendering inside HTML tags: - Ensure you are using an up-to-date version of Streamlit [2]. - Note that Streamlit often requires content to be correctly structured (e.g., proper spacing or paragraph breaks) for the parser to identify and render Markdown elements correctly within HTML blocks [1][3]. - For pure HTML or complex layouts, consider using st.html instead of st.markdown, as st.html is designed specifically for rendering HTML and does not attempt to parse Markdown [4][5]. Streamlit also does not support "open-ended" HTML tags that span across multiple st.markdown calls, as each command creates its own isolated container [6][7]. If you are attempting to wrap other Streamlit elements (like charts or widgets) inside a single
, this is not natively supported by st.markdown [6][7].

Citations:


🏁 Script executed:

#!/bin/bash
# First, locate and read the notice() function definition
fd -e py "ds_streamlit" | head -5

Repository: stranske/Fine-Art-Archive

Length of output: 193


🏁 Script executed:

#!/bin/bash
# Read the notice function with context around line 111-121
sed -n '100,130p' design-system/ds_streamlit.py

Repository: stranske/Fine-Art-Archive

Length of output: 1397


🏁 Script executed on selected repositories:

#!/bin/bash
# Search for notice() usages in related repos
rg -nP --type=py '\bnotice\s*\(' -A2 -B2 || true

Repositories: stranske/Workflows, stranske/Template

Length of output: 416


🏁 Script executed:

#!/bin/bash
# Check if there's any recent commit history or changes context
git log --oneline -n 20 design-system/ds_streamlit.py 2>/dev/null || echo "git log unavailable"

Repository: stranske/Fine-Art-Archive

Length of output: 222


🏁 Script executed:

#!/bin/bash
# Check the full notice() function including docstring to confirm markdown claim
sed -n '111,122p' design-system/ds_streamlit.py

Repository: stranske/Fine-Art-Archive

Length of output: 771


Docstring-implementation mismatch: action parameter escapes HTML but is documented as markdown.

Line 111's docstring states action is "optional remediation (markdown)", but line 116 HTML-escapes the action parameter before rendering inside a <div>. In Streamlit, Markdown syntax inside HTML block elements is treated as literal text rather than parsed, so callers cannot pass markdown-formatted remediation text (e.g., links like [click here](url)) as the docstring implies.

Either update the docstring to document that action accepts literal text only, or clarify the intentional security-first tradeoff if the escape is non-negotiable. This change appears intentional for XSS hardening, but the contract with callers needs alignment.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@design-system/ds_streamlit.py` around lines 115 - 121, The docstring for the
`action` parameter indicates it accepts markdown, but the implementation
HTML-escapes the action parameter before inserting it into the div element,
which prevents markdown syntax from being parsed. Update the docstring to
accurately reflect that the `action` parameter accepts literal text only (not
markdown), or if markdown support is intended, remove the escape call on the
action parameter and add a comment explaining any security considerations or
trade-offs associated with this change. Ensure the documentation matches the
actual behavior that callers will experience.

@stranske

Copy link
Copy Markdown
Owner Author

Closing as superseded by newer sync PR #133 from the latest Workflows sync wave.

@stranske stranske closed this Jun 23, 2026
@stranske
stranske deleted the sync/workflows-d0d4ad2bdd25 branch June 23, 2026 12:11

This branch was previously deployed

1 inactive deployment
agent-standard — c95f3cb0 Deployed Jun 23, 2026 by stranske via Update keepalive summary #662
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated sync from Workflows sync Automated sync from Workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant