Skip to content

feat: pre-alpha disclaimers + Cloudflare Pages deploy - #30

Merged
ThePlenkov merged 3 commits into
mainfrom
feat/website-deploy-prealpha
Aug 12, 2026
Merged

ThePlenkov merged 3 commits into
mainfrom
feat/website-deploy-prealpha

Conversation

@ThePlenkov

@ThePlenkov ThePlenkov commented Aug 11, 2026 •

Copy link
Copy Markdown
Contributor

User description

Summary

  • Pre-alpha disclaimer in README.md — warning banner (APIs may change, not production-ready)
  • Pre-alpha banner on website — amber bar at top of all 4 pages (index, getting-started, docs, 404)
  • Cloudflare Pages deploy workflow — .github/workflows/deploy-website.yml using wrangler-action@v4, triggers on push to main when website/** changes

What you need to do (one-time setup)

  1. Cloudflare API token — Dashboard → My Profile → API Tokens → Create (template: "Edit Cloudflare Workers")
  2. Account ID — Dashboard → any domain → bottom right "Account ID"
  3. Create Pages project — Workers & Pages → Create → Pages → name it sverka (Direct Upload, no Git connection)
  4. GitHub secrets — repo Settings → Secrets → Actions: add CLOUDFLARE_API_TOKEN and CLOUDFLARE_ACCOUNT_ID
  5. Custom domain — Pages project → Custom domains → add sverka.dev (DNS + SSL auto-provisioned since domain is on Cloudflare)

Test plan

  • astro check — 0 errors, 0 warnings, 0 hints
  • astro build — 4 pages + sitemap built in 660ms
  • Banner present on all 4 pages (grep verified)
  • First deploy after merge + secrets configured

Generated with Devin


Summary by cubic

Adds pre‑alpha disclaimers to the README and site, and sets up a hardened Cloudflare Pages deploy from main. Clarifies project status and automates safe site releases.

  • New Features

    • Pre‑alpha warning in README (APIs may change without notice).
    • Pre‑alpha banner on all pages (amber; role="status", emoji aria-hidden); text matches README.
    • Deploy workflow .github/workflows/deploy-website.yml: builds with Bun and deploys via cloudflare/wrangler-action@v4; runs on push to main for website/** and the workflow file, and on workflow_dispatch. Hardened with pinned runner/action SHAs, Bun 1.3.14 (no cache) and Wrangler 4.121.0, workflow concurrency (cancel in progress), minimal permissions, no checkout credential persistence, and split install/build before deploy.
  • Migration

    • Create a Cloudflare Pages project named sverka (Direct Upload).
    • Add GitHub Action secrets: CLOUDFLARE_API_TOKEN, CLOUDFLARE_ACCOUNT_ID.
    • Set custom domain sverka.dev in the Pages project.

Written for commit 5c8e31d. Summary will update on new commits.

Review in cubic


CodeAnt-AI Description

Add pre-alpha warnings and automate Cloudflare Pages website deployments

What Changed

  • The README and every website page now clearly state that the project is still in pre-alpha, APIs may change without notice, and it is not ready for production use.
  • The website displays an accessible warning banner at the top of each page.
  • Website changes pushed to main are automatically built and deployed to Cloudflare Pages, with manual deployment also available.
  • Overlapping deployments are canceled, and failed builds stop before publishing.

Impact

✅ Clearer project readiness warnings
✅ Consistent pre-alpha messaging across the website
✅ Automatic website releases after approved changes

🔄 Retrigger CodeAnt AI Review

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

- README.md: pre-alpha warning banner (APIs may change, not production-ready)
- website Base.astro: amber pre-alpha banner on all 4 pages
- website global.css: banner styling (dark amber theme)
- .github/workflows/deploy-website.yml: Cloudflare Pages deployment
  via wrangler-action@v4, triggers on push to main (website/** path filter)
  and manual workflow_dispatch

Requires repo secrets: CLOUDFLARE_API_TOKEN, CLOUDFLARE_ACCOUNT_ID

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 5f888219-2b10-4d44-9bfe-30b86aebd519

📥 Commits

Reviewing files that changed from the base of the PR and between ddb6c12 and 5c8e31d.

📒 Files selected for processing (2)
  • .github/workflows/deploy-website.yml
  • website/src/layouts/Base.astro
📜 Recent review details
⏰ Context from checks skipped due to timeout. (1)
  • GitHub Check: Codacy Static Code Analysis
🔇 Additional comments (4)
.github/workflows/deploy-website.yml (3)

1-17: LGTM!


18-36: LGTM!


38-44: LGTM!

website/src/layouts/Base.astro (1)

39-39: LGTM!


📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Added a prominent pre-alpha warning banner across website pages.
    • Improved banner styling for visibility and readability.
  • Documentation

    • Updated the README to clarify that the project is not production-ready and that APIs may change.
  • Deployment

    • Added automated website builds and deployments for main-branch changes and manual triggers.

Walkthrough

The PR adds a GitHub Actions workflow that builds and deploys the website to Cloudflare Pages. It also adds pre-alpha notices to the README and website, with styling for the website banner.

Changes

Website release readiness

Layer / File(s) Summary
Cloudflare Pages deployment
.github/workflows/deploy-website.yml
The workflow runs on relevant main changes or manual dispatch, installs dependencies with Bun, builds the website, and deploys website/dist to Cloudflare Pages.
Pre-alpha status notices
README.md, website/src/layouts/Base.astro, website/src/styles/global.css
The README and website display pre-alpha status information. The website banner defines matching visual styles.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant GitHubActions
  participant Bun
  participant CloudflarePages
  GitHubActions->>Bun: Install locked dependencies and build website
  Bun->>GitHubActions: Produce website/dist
  GitHubActions->>CloudflarePages: Deploy website/dist with configured credentials
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly summarizes both primary changes: pre-alpha disclaimers and Cloudflare Pages deployment.
Description check ✅ Passed The description directly explains the pre-alpha disclaimers, website banner, deployment workflow, setup requirements, and validation.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/website-deploy-prealpha

Comment @coderabbitai help to get the list of available commands.

@baz-reviewer

baz-reviewer Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Merger

Needs Review

The substantive review findings are addressed and all threads are resolved, but this security-sensitive deployment workflow has no recorded CI run. Human review is needed before merging an unverified workflow that handles Cloudflare deployment credentials.

Commit 5c8e31d · Evaluated 2026-08-12 06:37 UTC

Review this PR on Baz | Customize your next review

@amazon-q-developer amazon-q-developer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary

This PR adds pre-alpha disclaimers to the README and website, and implements Cloudflare Pages deployment automation. The changes are mostly straightforward, but there's one critical issue that needs to be addressed before merge.

Critical Issue

The GitHub Actions workflow will continue to the deploy step even if the build fails, which could deploy broken or non-existent content.

Changes Reviewed

  • ✅ Pre-alpha disclaimer in README.md
  • ✅ Pre-alpha banner on website (Base.astro)
  • ✅ Banner styling (global.css)
  • ⚠️ Cloudflare Pages deployment workflow (1 issue found)

Please address the workflow error handling issue before merging.


You can now have the agent implement changes and create commits directly on your pull request's source branch. Simply comment with /q followed by your request in natural language to ask the agent to make changes.

Comment thread .github/workflows/deploy-website.yml Outdated
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

AI Reviewer: first review requested successfully. AI can make mistakes. Always validate suggestions.

Run reviewer

TIP This summary will be updated as you push new changes.

@qodo-code-review

qodo-code-review Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

PR Summary by Qodo

Add pre-alpha banners and Cloudflare Pages deploy workflow

✨ Enhancement 📝 Documentation ⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Add pre-alpha warning banner to README and all website pages.
• Style a global amber status banner via shared layout + CSS.
• Automate Cloudflare Pages deploy on main pushes affecting website/ (Bun + Wrangler).
Diagram

graph TD
  Dev["Push to main"] --> GA["Deploy workflow"] --> Build["Build (Bun/Astro)"] --> Dist[("Dist artifact")] --> CF["Cloudflare Pages"] --> Users["Visitors"]
  Src["Website source"] --> Build
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Use Cloudflare Pages Git integration (no direct upload)
  • ➕ Removes custom deploy workflow maintenance
  • ➕ Cloudflare builds/deploys directly from GitHub pushes
  • ➖ Less control over pinned toolchain (Bun/Wrangler) and hardening knobs
  • ➖ Build environment and caching behavior are Cloudflare-managed
2. Deploy to GitHub Pages instead of Cloudflare Pages
  • ➕ Fewer external secrets (often just GitHub token)
  • ➕ Simpler setup for OSS docs sites
  • ➖ Not aligned if the project standardizes on Cloudflare and custom domains there
  • ➖ May require different routing/headers behavior vs Pages

Recommendation: The current approach is solid if you want deterministic, hardened deploys: pinned runner/actions, explicit Bun/Wrangler versions, minimal permissions, and a path-filtered trigger to avoid unnecessary deploys. Consider Cloudflare’s Git integration only if you prefer to offload build/deploy maintenance and accept reduced control over the toolchain.

Files changed (4) +59 / -0

Enhancement (2) +13 / -0
Base.astroShow a global pre-alpha status banner on every page +3/-0

Show a global pre-alpha status banner on every page

• Adds an always-visible pre-alpha banner to the shared site layout so all pages inherit it. Includes basic accessibility semantics (role="status" and aria-hidden emoji).

website/src/layouts/Base.astro

global.cssStyle the pre-alpha banner (amber/dark theme) +10/-0

Style the pre-alpha banner (amber/dark theme)

• Adds global CSS rules for the pre-alpha banner background, border, text color, spacing, and typography to ensure consistent presentation site-wide.

website/src/styles/global.css

Documentation (1) +3 / -0
README.mdAdd pre-alpha disclaimer banner +3/-0

Add pre-alpha disclaimer banner

• Adds a prominent pre-alpha warning near the top of the README to set expectations about API stability and production readiness.

README.md

Other (1) +43 / -0
deploy-website.ymlAdd hardened Cloudflare Pages deployment workflow +43/-0

Add hardened Cloudflare Pages deployment workflow

• Introduces a GitHub Actions workflow that triggers on pushes to main when website paths change (or manual dispatch). Builds the Astro site with pinned Bun, then deploys website/dist to Cloudflare Pages via pinned wrangler-action, with concurrency control and reduced permissions.

.github/workflows/deploy-website.yml

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR introduces pre-alpha disclaimers to the README and website layout, alongside a new GitHub Actions workflow for Cloudflare Pages deployment. Codacy analysis shows the PR is up to standards with no new quality issues.

The review highlights a medium-severity issue in the deployment workflow related to dependency installation in a monorepo context. It is recommended to run installation from the root to ensure lockfile consistency. Additionally, a minor accessibility enhancement is suggested for the disclaimer banner to ensure it is correctly interpreted by assistive technologies.

Test suggestions

  • Verify the pre-alpha banner is rendered at the top of the body in the Base layout.
  • Verify the presence of the pre-alpha disclaimer in the README.md content.
  • Verify the GitHub Action workflow correctly targets the 'sverka' project name and 'website/dist' directory for deployment.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify the pre-alpha banner is rendered at the top of the body in the Base layout.
2. Verify the presence of the pre-alpha disclaimer in the README.md content.
3. Verify the GitHub Action workflow correctly targets the 'sverka' project name and 'website/dist' directory for deployment.

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

Comment thread .github/workflows/deploy-website.yml Outdated
Comment thread website/src/layouts/Base.astro Outdated
@qodo-code-review

qodo-code-review Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. Floating deploy toolchain ✓ Resolved 🐞 Bug ☼ Reliability
Description
The workflow uses ubuntu-latest and does not pin the Bun or Wrangler versions, so a runner/tool
update can break astro build or change deploy behavior without any repo changes.
Code

.github/workflows/deploy-website.yml[17]

+    runs-on: ubuntu-latest
Evidence
The workflow explicitly uses ubuntu-latest and does not specify a Bun version. The wrangler-action
docs state that if wranglerVersion is omitted, the action installs/uses a default/latest Wrangler,
which can change over time.

.github/workflows/deploy-website.yml[17-36]
🌐 The action supports wranglerVersion to pin a specific Wrangler version; when omitted it installs/uses a default version (currently defaults to Wrangler v4/latest).

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
The deployment environment is not reproducible because the workflow floats the runner image (`ubuntu-latest`) and toolchain versions (Bun/Wrangler). This can introduce sudden CI failures or behavioral changes in deploy.

### Issue Context
`bun install --frozen-lockfile` pins JavaScript deps from `bun.lock`, but it does not pin the Bun runtime, the GitHub runner image, or the Wrangler CLI version used by the deployment action.

### Fix Focus Areas
- .github/workflows/deploy-website.yml[17-36]

### Suggested fix
- Pin the runner image, e.g. `runs-on: ubuntu-24.04`.
- Pin Bun via `oven-sh/setup-bun`:
 ```yaml
 - uses: oven-sh/setup-bun@<sha>
   with:
     bun-version: "<known-good-version>"
 ```
- Pin Wrangler via wrangler-action input:
 ```yaml
 - uses: cloudflare/wrangler-action@<sha>
   with:
     wranglerVersion: "<known-good-version>"
 ```

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


2. No deploy concurrency ✓ Resolved 🐞 Bug ☼ Reliability
Description
The workflow lacks a concurrency policy, so multiple pushes to main can run overlapping deploys,
wasting CI and potentially producing confusing deployment status/ordering.
Code

.github/workflows/deploy-website.yml[R15-17]

+jobs:
+  deploy:
+    runs-on: ubuntu-latest
Evidence
The new workflow defines a deploy job but does not set concurrency, so GitHub will allow multiple
runs to execute simultaneously when multiple pushes occur.

.github/workflows/deploy-website.yml[3-36]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
Rapid pushes to `main` can trigger multiple deploy runs concurrently. For a production website deploy, this is usually undesirable.

### Issue Context
GitHub Actions supports `concurrency` at the workflow or job level to serialize deployments and/or cancel superseded runs.

### Fix Focus Areas
- .github/workflows/deploy-website.yml[1-36]

### Suggested fix
Add a concurrency block (either top-level or under the `deploy` job). Example (top-level):
```yaml
concurrency:
 group: website-pages-production
 cancel-in-progress: true
```
This cancels older deploys when newer commits are pushed to `main`.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


3. Unpinned action versions ✓ Resolved 🐞 Bug ⛨ Security
Description
The deploy workflow uses mutable action tags (e.g., @v4/@v2) rather than immutable commit SHAs, so a
compromised or retagged action release could run attacker-controlled code with access to Cloudflare
deploy secrets.
Code

.github/workflows/deploy-website.yml[R31-34]

+        uses: cloudflare/wrangler-action@v4
+        with:
+          apiToken: ${{ secrets.CLOUDFLARE_API_TOKEN }}
+          accountId: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }}
Evidence
The workflow invokes multiple actions via tags (mutable references). GitHub recommends pinning
actions to full commit SHAs to limit the blast radius if an action tag/release is compromised or
changed.

.github/workflows/deploy-website.yml[20-36]
🌐 GitHub recommends pinning workflow dependencies (actions) to a specific commit SHA to limit the impact of a compromised dependency.

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
The workflow references third-party actions by tag (`@v4`, `@v2`). Tags can be moved/retagged, which increases supply-chain risk because this workflow runs with Cloudflare credentials.

### Issue Context
This workflow deploys to Cloudflare Pages and passes `CLOUDFLARE_API_TOKEN`/`CLOUDFLARE_ACCOUNT_ID`.

### Fix Focus Areas
- .github/workflows/deploy-website.yml[20-36]

### Suggested fix
- Replace:
 - `actions/checkout@v4`
 - `oven-sh/setup-bun@v2`
 - `cloudflare/wrangler-action@v4`
 with pinned commit SHAs, e.g. `actions/checkout@<full_sha>`.
- (Optional) Add a comment noting which tag/release the SHA corresponds to and enable Dependabot updates for GitHub Actions to keep SHAs current.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context
✅ Compliance rules (platform): 8 rules
✅ Web pages:
  +12 more
Review mode: ⚖️ Balanced: This push changes a deployment workflow and runtime website accessibility markup; the workflow's permissions, pinned actions, build, and deploy behavior carry genuine operational risk, but the localized patch is not dense enough to warrant redundant extended review.

Grey Divider

Tip of the day
💡 Did you know, you can enable the Remediation agent and Qodo fixes findings in a dedicated fix PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread .github/workflows/deploy-website.yml Outdated
Comment thread .github/workflows/deploy-website.yml Outdated
Comment thread .github/workflows/deploy-website.yml Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/deploy-website.yml:
- Around line 11-14: Confirm whether GitHub Deployment records are required for
the workflow. If they are not, remove the gitHubToken configuration from the
Cloudflare Wrangler action and remove deployments: write from the workflow
permissions; if they are required, retain both and document the purpose beside
the deployments permission.
- Around line 20-22: Pin the workflow actions used in the deployment job to
immutable full commit SHAs: update actions/checkout, oven-sh/setup-bun, and
cloudflare/wrangler-action to the exact SHAs specified in the review comment,
replacing their mutable tags while preserving the existing workflow
configuration.
- Line 20: Update the actions/checkout@v4 step to set persist-credentials to
false, ensuring the checkout token is not retained in local Git configuration
during subsequent workflow steps.
- Around line 3-9: Add workflow-level concurrency configuration alongside the
existing on and deployment settings in the website deployment workflow, using a
stable group for this workflow and setting cancel-in-progress to true. Ensure
newer runs cancel older in-progress deployments to prevent stale production
updates.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 6ed47953-859f-48ed-b036-a67d67630a45

📥 Commits

Reviewing files that changed from the base of the PR and between 1ffc0bd and 77fb72f.

📒 Files selected for processing (4)
  • .github/workflows/deploy-website.yml
  • README.md
  • website/src/layouts/Base.astro
  • website/src/styles/global.css
📜 Review details
⏰ Context from checks skipped due to timeout. (1)
  • GitHub Check: Codacy Static Code Analysis
🧰 Additional context used
🪛 GitHub Check: SonarCloud Code Analysis
.github/workflows/deploy-website.yml

[failure] 22-22: Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=sverka-dev_sverka&issues=AZ_zCAayxzD3XMBc_4zh&open=AZ_zCAayxzD3XMBc_4zh&pullRequest=30


[warning] 27-27: Omitting "--ignore-scripts" allows lifecycle scripts to run during package installation.

See more on https://sonarcloud.io/project/issues?id=sverka-dev_sverka&issues=AZ_zCAayxzD3XMBc_4zi&open=AZ_zCAayxzD3XMBc_4zi&pullRequest=30


[failure] 31-31: Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=sverka-dev_sverka&issues=AZ_zCAayxzD3XMBc_4zj&open=AZ_zCAayxzD3XMBc_4zj&pullRequest=30

🪛 zizmor (1.29.0)
.github/workflows/deploy-website.yml

[warning] 20-20: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false

(artipacked)


[error] 13-13: overly broad permissions (excessive-permissions): deployments: write is overly broad at the workflow level

(excessive-permissions)


[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 22-22: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[error] 31-31: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)


[warning] 13-13: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment

(undocumented-permissions)


[error] 22-22: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default

(cache-poisoning)


[warning] 3-9: insufficient job-level concurrency limits (concurrency-limits): workflow is missing concurrency setting

(concurrency-limits)

🔇 Additional comments (6)
.github/workflows/deploy-website.yml (3)

1-2: LGTM!

Also applies to: 15-18


24-25: LGTM!

Also applies to: 28-28, 30-30, 32-35


27-27: 🔒 Security & Privacy

Keep Bun’s default lifecycle-script policy.

Bun does not execute arbitrary dependency lifecycle scripts by default. It runs scripts only for trusted or allowlisted packages. This project does not define trustedDependencies, and its Astro dependency tree includes native tooling such as esbuild and sharp. Forcing --ignore-scripts could break astro build.

			> Likely an incorrect or invalid review comment.
README.md (1)

10-12: LGTM!

website/src/layouts/Base.astro (1)

38-40: LGTM!

website/src/styles/global.css (1)

33-41: LGTM!

Comment thread .github/workflows/deploy-website.yml
Comment thread .github/workflows/deploy-website.yml
Comment thread .github/workflows/deploy-website.yml Outdated
Comment thread .github/workflows/deploy-website.yml Outdated
@ThePlenkov
ThePlenkov marked this pull request as draft August 12, 2026 06:26
- Pin runner (ubuntu-24.04) and action SHAs.
- Pin Bun 1.3.14 and Wrangler 4.121.0 versions.
- Add workflow concurrency with cancel-in-progress.
- Disable checkout credential persistence.
- Remove gitHubToken and deployments:write permission.
- Split install/build so build failures stop before deploy.
- Add role="status" and aria-hidden emoji wrapper to banner.

Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
@ThePlenkov
ThePlenkov marked this pull request as ready for review August 12, 2026 06:28

@codacy-production codacy-production Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Codacy analysis indicates the code is up to standards with no new quality issues. The implementation aligns with the goal of establishing pre-alpha status transparency and automating deployments.

A notable gap exists regarding verification; there are currently no automated test scenarios to validate the rendering of the new disclaimer banner or the GitHub Actions filter logic. While no blocking security or logic flaws were identified, a refactor of the deployment workflow is recommended to improve maintainability by utilizing standard GitHub Action configuration patterns.

1 comment outside of the diff
[REDACTED:HIGH_ENTROPY]

line 19 ⚪ LOW RISK
Suggestion: Simplify the workflow by using working-directory settings instead of repeating the path and absolute variables in every command. This reduces noise and makes the workflow easier to update if the directory structure changes.

Try running the following prompt in your coding agent:

Refactor the deploy job in the GitHub Actions workflow to use defaults.run.working-directory: website. Also, update the wrangler-action step to use its workingDirectory: website input and update the deploy command to use the relative dist path.

Test suggestions

  • Verify that the pre-alpha-banner component is correctly rendered in the Base layout with expected ARIA attributes.
  • Verify the CSS for the banner applies the expected background, color, and text alignment.
  • Validate the GitHub Actions YAML syntax and filter logic for 'main' branch and 'website/**' paths.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify that the pre-alpha-banner component is correctly rendered in the Base layout with expected ARIA attributes.
2. Verify the CSS for the banner applies the expected background, color, and text alignment.
3. Validate the GitHub Actions YAML syntax and filter logic for 'main' branch and 'website/**' paths.

TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback

@qodo-code-review

Copy link
Copy Markdown

Code review by qodo was updated up to the latest commit ddb6c12

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/deploy-website.yml:
- Around line 27-29: Update the oven-sh/setup-bun step in the publishing
workflow to disable executable caching while retaining Bun version 1.3.14, using
the action’s supported cache-control input.

In `@website/src/layouts/Base.astro`:
- Line 39: Update the release-status banner text in the Base layout to include
“without notice,” matching the wording in README.md while preserving the rest of
the banner content.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 96fea079-4713-499f-887f-d61f63bd64b3

📥 Commits

Reviewing files that changed from the base of the PR and between 77fb72f and ddb6c12.

📒 Files selected for processing (2)
  • .github/workflows/deploy-website.yml
  • website/src/layouts/Base.astro
📜 Review details
⏰ Context from checks skipped due to timeout. (1)
  • GitHub Check: Codacy Static Code Analysis
🧰 Additional context used
🪛 zizmor (1.29.0)
.github/workflows/deploy-website.yml

[warning] 32-32: code injection via template expansion (template-injection): may expand into attacker-controllable code

(template-injection)


[warning] 35-35: code injection via template expansion (template-injection): may expand into attacker-controllable code

(template-injection)


[error] 27-27: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default

(cache-poisoning)

🔇 Additional comments (4)
.github/workflows/deploy-website.yml (4)

20-25: LGTM!


31-35: LGTM!


37-43: LGTM!


3-5: 🗄️ Data Integrity & Integration

Check the sverka production branch before changing concurrency.

workflow_dispatch can select any branch. actions/checkout checks out branch refs, and Wrangler associates the deployment with that branch. Cloudflare treats it as a preview unless that branch is configured as production. The repository does not contain the Pages production-branch setting, so a production race cannot be determined from this workflow. If main is production, the current branch-scoped group is appropriate; a fixed group would cancel unrelated branch runs.

Comment thread .github/workflows/deploy-website.yml
Comment thread website/src/layouts/Base.astro Outdated
- Add no-cache: true to oven-sh/setup-bun to prevent cache poisoning.
- Update pre-alpha banner text to include "without notice" matching README.md.

Co-Authored-By: Petr Plenkov <petr.plenkov@gmail.com>
@codeant-ai

codeant-ai Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Incremental review completed 5c8e31d Aug 12, 2026 · 06:36 06:37

@codeant-ai codeant-ai Bot added the size:M This PR changes 30-99 lines, ignoring generated files label Aug 12, 2026
@sonarqubecloud

Copy link
Copy Markdown

@ThePlenkov
ThePlenkov merged commit 599880c into main Aug 12, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

baz: needs review size:M This PR changes 30-99 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant