Repository navigation
feat: pre-alpha disclaimers + Cloudflare Pages deploy - #30
Conversation
- README.md: pre-alpha warning banner (APIs may change, not production-ready) - website Base.astro: amber pre-alpha banner on all 4 pages - website global.css: banner styling (dark amber theme) - .github/workflows/deploy-website.yml: Cloudflare Pages deployment via wrangler-action@v4, triggers on push to main (website/** path filter) and manual workflow_dispatch Requires repo secrets: CLOUDFLARE_API_TOKEN, CLOUDFLARE_ACCOUNT_ID Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📜 Recent review details⏰ Context from checks skipped due to timeout. (1)
🔇 Additional comments (4)
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe PR adds a GitHub Actions workflow that builds and deploys the website to Cloudflare Pages. It also adds pre-alpha notices to the README and website, with styling for the website banner. ChangesWebsite release readiness
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant GitHubActions
participant Bun
participant CloudflarePages
GitHubActions->>Bun: Install locked dependencies and build website
Bun->>GitHubActions: Produce website/dist
GitHubActions->>CloudflarePages: Deploy website/dist with configured credentials
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
MergerNeeds Review The substantive review findings are addressed and all threads are resolved, but this security-sensitive deployment workflow has no recorded CI run. Human review is needed before merging an unverified workflow that handles Cloudflare deployment credentials. Commit |
There was a problem hiding this comment.
Summary
This PR adds pre-alpha disclaimers to the README and website, and implements Cloudflare Pages deployment automation. The changes are mostly straightforward, but there's one critical issue that needs to be addressed before merge.
Critical Issue
The GitHub Actions workflow will continue to the deploy step even if the build fails, which could deploy broken or non-existent content.
Changes Reviewed
- ✅ Pre-alpha disclaimer in README.md
- ✅ Pre-alpha banner on website (Base.astro)
- ✅ Banner styling (global.css)
⚠️ Cloudflare Pages deployment workflow (1 issue found)
Please address the workflow error handling issue before merging.
You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.
Up to standards ✅🟢 Issues
|
PR Summary by QodoAdd pre-alpha banners and Cloudflare Pages deploy workflow
AI Description
Diagram
High-Level Assessment
Files changed (4)
|
There was a problem hiding this comment.
Pull Request Overview
This PR introduces pre-alpha disclaimers to the README and website layout, alongside a new GitHub Actions workflow for Cloudflare Pages deployment. Codacy analysis shows the PR is up to standards with no new quality issues.
The review highlights a medium-severity issue in the deployment workflow related to dependency installation in a monorepo context. It is recommended to run installation from the root to ensure lockfile consistency. Additionally, a minor accessibility enhancement is suggested for the disclaimer banner to ensure it is correctly interpreted by assistive technologies.
Test suggestions
- Verify the pre-alpha banner is rendered at the top of the body in the Base layout.
- Verify the presence of the pre-alpha disclaimer in the README.md content.
- Verify the GitHub Action workflow correctly targets the 'sverka' project name and 'website/dist' directory for deployment.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify the pre-alpha banner is rendered at the top of the body in the Base layout.
2. Verify the presence of the pre-alpha disclaimer in the README.md content.
3. Verify the GitHub Action workflow correctly targets the 'sverka' project name and 'website/dist' directory for deployment.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
Code Review by Qodo
1.
|
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/deploy-website.yml:
- Around line 11-14: Confirm whether GitHub Deployment records are required for
the workflow. If they are not, remove the gitHubToken configuration from the
Cloudflare Wrangler action and remove deployments: write from the workflow
permissions; if they are required, retain both and document the purpose beside
the deployments permission.
- Around line 20-22: Pin the workflow actions used in the deployment job to
immutable full commit SHAs: update actions/checkout, oven-sh/setup-bun, and
cloudflare/wrangler-action to the exact SHAs specified in the review comment,
replacing their mutable tags while preserving the existing workflow
configuration.
- Line 20: Update the actions/checkout@v4 step to set persist-credentials to
false, ensuring the checkout token is not retained in local Git configuration
during subsequent workflow steps.
- Around line 3-9: Add workflow-level concurrency configuration alongside the
existing on and deployment settings in the website deployment workflow, using a
stable group for this workflow and setting cancel-in-progress to true. Ensure
newer runs cancel older in-progress deployments to prevent stale production
updates.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 6ed47953-859f-48ed-b036-a67d67630a45
📒 Files selected for processing (4)
.github/workflows/deploy-website.ymlREADME.mdwebsite/src/layouts/Base.astrowebsite/src/styles/global.css
📜 Review details
⏰ Context from checks skipped due to timeout. (1)
- GitHub Check: Codacy Static Code Analysis
🧰 Additional context used
🪛 GitHub Check: SonarCloud Code Analysis
.github/workflows/deploy-website.yml
[failure] 22-22: Use full commit SHA hash for this dependency.
[warning] 27-27: Omitting "--ignore-scripts" allows lifecycle scripts to run during package installation.
[failure] 31-31: Use full commit SHA hash for this dependency.
🪛 zizmor (1.29.0)
.github/workflows/deploy-website.yml
[warning] 20-20: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 13-13: overly broad permissions (excessive-permissions): deployments: write is overly broad at the workflow level
(excessive-permissions)
[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 22-22: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 31-31: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[warning] 13-13: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment
(undocumented-permissions)
[error] 22-22: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[warning] 3-9: insufficient job-level concurrency limits (concurrency-limits): workflow is missing concurrency setting
(concurrency-limits)
🔇 Additional comments (6)
.github/workflows/deploy-website.yml (3)
1-2: LGTM!Also applies to: 15-18
24-25: LGTM!Also applies to: 28-28, 30-30, 32-35
27-27: 🔒 Security & PrivacyKeep Bun’s default lifecycle-script policy.
Bun does not execute arbitrary dependency lifecycle scripts by default. It runs scripts only for trusted or allowlisted packages. This project does not define
trustedDependencies, and its Astro dependency tree includes native tooling such asesbuildandsharp. Forcing--ignore-scriptscould breakastro build.> Likely an incorrect or invalid review comment.README.md (1)
10-12: LGTM!website/src/layouts/Base.astro (1)
38-40: LGTM!website/src/styles/global.css (1)
33-41: LGTM!
- Pin runner (ubuntu-24.04) and action SHAs. - Pin Bun 1.3.14 and Wrangler 4.121.0 versions. - Add workflow concurrency with cancel-in-progress. - Disable checkout credential persistence. - Remove gitHubToken and deployments:write permission. - Split install/build so build failures stop before deploy. - Add role="status" and aria-hidden emoji wrapper to banner. Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
There was a problem hiding this comment.
Pull Request Overview
Codacy analysis indicates the code is up to standards with no new quality issues. The implementation aligns with the goal of establishing pre-alpha status transparency and automating deployments.
A notable gap exists regarding verification; there are currently no automated test scenarios to validate the rendering of the new disclaimer banner or the GitHub Actions filter logic. While no blocking security or logic flaws were identified, a refactor of the deployment workflow is recommended to improve maintainability by utilizing standard GitHub Action configuration patterns.
1 comment outside of the diff
[REDACTED:HIGH_ENTROPY]
line 19⚪ LOW RISK
Suggestion: Simplify the workflow by usingworking-directorysettings instead of repeating the path and absolute variables in every command. This reduces noise and makes the workflow easier to update if the directory structure changes.Try running the following prompt in your coding agent:
Refactor the
deployjob in the GitHub Actions workflow to usedefaults.run.working-directory: website. Also, update thewrangler-actionstep to use itsworkingDirectory: websiteinput and update the deploy command to use the relativedistpath.
Test suggestions
- Verify that the pre-alpha-banner component is correctly rendered in the Base layout with expected ARIA attributes.
- Verify the CSS for the banner applies the expected background, color, and text alignment.
- Validate the GitHub Actions YAML syntax and filter logic for 'main' branch and 'website/**' paths.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify that the pre-alpha-banner component is correctly rendered in the Base layout with expected ARIA attributes.
2. Verify the CSS for the banner applies the expected background, color, and text alignment.
3. Validate the GitHub Actions YAML syntax and filter logic for 'main' branch and 'website/**' paths.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
|
Code review by qodo was updated up to the latest commit ddb6c12 |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/deploy-website.yml:
- Around line 27-29: Update the oven-sh/setup-bun step in the publishing
workflow to disable executable caching while retaining Bun version 1.3.14, using
the action’s supported cache-control input.
In `@website/src/layouts/Base.astro`:
- Line 39: Update the release-status banner text in the Base layout to include
“without notice,” matching the wording in README.md while preserving the rest of
the banner content.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 96fea079-4713-499f-887f-d61f63bd64b3
📒 Files selected for processing (2)
.github/workflows/deploy-website.ymlwebsite/src/layouts/Base.astro
📜 Review details
⏰ Context from checks skipped due to timeout. (1)
- GitHub Check: Codacy Static Code Analysis
🧰 Additional context used
🪛 zizmor (1.29.0)
.github/workflows/deploy-website.yml
[warning] 32-32: code injection via template expansion (template-injection): may expand into attacker-controllable code
(template-injection)
[warning] 35-35: code injection via template expansion (template-injection): may expand into attacker-controllable code
(template-injection)
[error] 27-27: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
🔇 Additional comments (4)
.github/workflows/deploy-website.yml (4)
20-25: LGTM!
31-35: LGTM!
37-43: LGTM!
3-5: 🗄️ Data Integrity & IntegrationCheck the
sverkaproduction branch before changing concurrency.
workflow_dispatchcan select any branch.actions/checkoutchecks out branch refs, and Wrangler associates the deployment with that branch. Cloudflare treats it as a preview unless that branch is configured as production. The repository does not contain the Pages production-branch setting, so a production race cannot be determined from this workflow. Ifmainis production, the current branch-scoped group is appropriate; a fixed group would cancel unrelated branch runs.
- Add no-cache: true to oven-sh/setup-bun to prevent cache poisoning. - Update pre-alpha banner text to include "without notice" matching README.md. Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
🤖 CodeAnt AI — Review Status
|
|



User description
Summary
.github/workflows/deploy-website.ymlusingwrangler-action@v4, triggers on push to main whenwebsite/**changesWhat you need to do (one-time setup)
sverka(Direct Upload, no Git connection)CLOUDFLARE_API_TOKENandCLOUDFLARE_ACCOUNT_IDsverka.dev(DNS + SSL auto-provisioned since domain is on Cloudflare)Test plan
astro check— 0 errors, 0 warnings, 0 hintsastro build— 4 pages + sitemap built in 660msGenerated with Devin
Summary by cubic
Adds pre‑alpha disclaimers to the README and site, and sets up a hardened Cloudflare Pages deploy from
main. Clarifies project status and automates safe site releases.New Features
role="status", emojiaria-hidden); text matches README..github/workflows/deploy-website.yml: builds withBunand deploys viacloudflare/wrangler-action@v4; runs on push tomainforwebsite/**and the workflow file, and onworkflow_dispatch. Hardened with pinned runner/action SHAs,Bun1.3.14 (no cache) and Wrangler 4.121.0, workflow concurrency (cancel in progress), minimal permissions, no checkout credential persistence, and split install/build before deploy.Migration
sverka(Direct Upload).CLOUDFLARE_API_TOKEN,CLOUDFLARE_ACCOUNT_ID.sverka.devin the Pages project.Written for commit 5c8e31d. Summary will update on new commits.
CodeAnt-AI Description
Add pre-alpha warnings and automate Cloudflare Pages website deployments
What Changed
mainare automatically built and deployed to Cloudflare Pages, with manual deployment also available.Impact
✅ Clearer project readiness warnings✅ Consistent pre-alpha messaging across the website✅ Automatic website releases after approved changes🔄 Retrigger CodeAnt AI Review
💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.