hotfix: DeepSeek CI — pull_request_review_comment + pip verify - #212
Conversation
|
Mention Blocks like a regular teammate with your question or request: @blocks review this pull request Run |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
PR Summary by QodoFix DeepSeek CI: trigger on review comments and verify pip/requests
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
| (github.event_name != 'issue_comment' && github.event_name != 'pull_request_review_comment') || | ||
| ( | ||
| github.event.comment.user.type != 'Bot' && | ||
| ( |
There was a problem hiding this comment.
🔍 Broad mention filter now also fires on every review comment containing "deepseek"
The mention filter includes bare contains(github.event.comment.body, 'deepseek') / 'DeepSeek', so any inline code-review comment that merely mentions DeepSeek in prose (very likely in this repo, whose code is DeepSeek-centric) will start the job. Combined with cancel-in-progress: true on a concurrency group keyed by PR number, a review pass that leaves several inline comments will repeatedly cancel and restart the agent for the same PR. Consider tightening the filter to explicit @ mentions for the review-comment path.
(Refers to lines 40-51)
Was this helpful? React with 👍 or 👎 to provide feedback.
| pull_request_review_comment: | ||
| types: [created] |
There was a problem hiding this comment.
📝 Info: Documented trigger list in AGENTS.md is now out of date
AGENTS.md (CI/CD section) still states the DeepSeek workflow triggers on "PR opened, synchronize, reopened, manual dispatch", and deepcli/ci_agent.py docstring was updated but the ops doc referenced by the workflow header (docs/ops/DEEPSEEK-CI.md) was not checked in this PR. Consider updating both so the trigger matrix (now including issue_comment and pull_request_review_comment) is documented in one place.
Was this helpful? React with 👍 or 👎 to provide feedback.
| run: | | ||
| python -m pip install --upgrade pip | ||
| pip install requests pyyaml | ||
| python -c "import requests; print('requests', requests.__version__)" |
There was a problem hiding this comment.
📝 Info: Pip verification step does not validate pyyaml
The added verification only imports requests; pyyaml is installed in the same command but never verified, even though the agent code paths use YAML config loading. A single python -c "import requests, yaml" would cover both without extra cost.
Was this helpful? React with 👍 or 👎 to provide feedback.
|
@jules Auto-resolve (heyVern lane / GHA agent-review-auto-jules) — do not wait for a human ping. Feedback excerptInstructions
|
|
head_sha: 2e8be18 Peer review gate (ready for second-pass agents)External reviewers polled: CodeRabbit, Devin, Aikido, Sentry, Copilot. Peer activity (truncated): Downstream: |
🔀 OpenRouter review (
|
|
Warning Review limit reached
Next review available in: 44 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThe DeepSeek CI workflow now responds to new pull request review comments, filters bot-generated comment events, and uses an expanded Python dependency setup that reports the installed ChangesDeepSeek CI workflow
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: 🟡 Moderate · up to This change enables inline review comments to trigger DeepSeek CI, but the current workflow does not handle those payloads correctly, so comments may trigger work without receiving the intended response. Merge should wait for the handler/API path to be implemented or the trigger removed, with credential exposure for untrusted review-comment runs explicitly confirmed. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review by Qodo
1.
|
Fixes Applied SuccessfullyFixed 1 file(s) based on 1 unresolved review comment. Files modified:
Commit: The changes have been pushed to the Time taken:
Lines 27–33 default: 'account-1'
concurrency:
- group: deepseek-ci-${{ github.event.pull_request.number || github.event.issue.number || github.run_id }}
+ group: deepseek-ci-${{ github.event.pull_request.number || github.event.issue.number || github.event.comment.id || github.run_id }}
cancel-in-progress: true
jobs: |
Fixed 1 file(s) based on 1 unresolved review comment. Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
|
Deployment failed for project termux-monorepo with the following error: Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit |
| pull_request_review_comment: | ||
| types: [created] |
There was a problem hiding this comment.
🟡 Multiple inline review comments on the same pull request cancel each other, so only the last one gets an answer
The new per-comment identifier added to the run grouping key (github.event.comment.id at .github/workflows/deepseek-ci.yml:30) is placed after two values that are always present for comment events, so it never takes effect and every comment on a pull request shares one cancellable run slot.
Impact: When someone leaves several inline review comments at once (or comments while an automated review is running), the earlier runs are cancelled and those comments silently never receive a reply.
Why the comment.id fallback is unreachable and what cancel-in-progress does
For pull_request_review_comment, the payload always contains pull_request.number, so github.event.pull_request.number wins the || chain and github.event.comment.id is never evaluated. For issue_comment, github.event.issue.number is always present, so again comment.id is dead. The resulting group is therefore identical to the pre-PR group (deepseek-ci-<pr/issue number>), while cancel-in-progress: true (.github/workflows/deepseek-ci.yml:31) kills any in-flight run in that group.
GitHub delivers one pull_request_review_comment event per inline comment, so submitting a review containing N mentioning comments creates N runs in the same group — N-1 get cancelled. A review comment also cancels an in-progress pull_request synchronize review for the same PR, and vice-versa. A comparable workflow in this repo avoids this by using cancel-in-progress: false (.github/workflows/agent-review-auto-jules.yml:16-17).
Putting comment.id first (when present) restores per-comment isolation, which appears to be the intent of the commit "fix(ci): include comment.id in DeepSeek concurrency group".
Was this helpful? React with 👍 or 👎 to provide feedback.
| pull_request_review_comment: | ||
| types: [created] |
There was a problem hiding this comment.
🟡 Change does not reference a tracked work item as required by the repository process
The commits and PR body introducing the new comment trigger (pull_request_review_comment at .github/workflows/deepseek-ci.yml:16-17) omit the mandatory Implements: <ITEM-ID> citation required by the repository's agent rules.
Impact: The change cannot be traced back to an approved work item, breaking the project's tracking process.
Rule reference
AGENTS.md Hard Rules require: "Do not invent work outside docs/proposals/active/<id>/ITEMS.md — add a row first." and "Cite Implements: <ITEM-ID> on PRs/commits." Neither commit message (2e8be18, 325a1f0) nor the PR body contains an Implements: line.
Was this helpful? React with 👍 or 👎 to provide feedback.
| # Parentheses required: && binds tighter than || in GHA expressions. | ||
| if: >- | ||
| github.event_name != 'issue_comment' || | ||
| (github.event_name != 'issue_comment' && github.event_name != 'pull_request_review_comment') || | ||
| ( | ||
| github.event.comment.user.type != 'Bot' && | ||
| ( |
There was a problem hiding this comment.
🔍 Self-triggering loop risk: the agent's own review reply can re-trigger the workflow
The reply is posted with the operator PAT (GH_TOKEN set from OPERATOR_TOKEN in deepcli/ci_agent.py:358), and comments created with a PAT (unlike GITHUB_TOKEN) do trigger further workflow runs. The job filter (.github/workflows/deepseek-ci.yml:38-49) only excludes comment.user.type == 'Bot' and otherwise matches on any case-insensitive occurrence of deepseek/deepcore. Since the posted reply is **deepCore**\n\n{analysis} and the model output frequently mentions "DeepSeek", the reply can satisfy the mention filter and cause the agent to answer itself repeatedly. This risk already existed for the issue_comment path on master, but this PR extends it to review threads. A cheap mitigation is to also require that comment.user.login differs from the operator account, or to skip bodies starting with the deepCore moniker.
Was this helpful? React with 👍 or 👎 to provide feedback.
| # --- pull_request_review_comment path --- | ||
| # Review comments have comment + pull_request but no issue key. | ||
| # Handle them as PR comments (reply to review thread). | ||
| if event.get("comment") and event.get("pull_request") and not event.get("issue"): | ||
| comment = event.get("comment") or {} | ||
| body = (comment.get("body") or "").strip() | ||
| pr = event.get("pull_request") or {} | ||
| pr_number = pr.get("number") | ||
| repo = (event.get("repository") or {}).get("full_name") | ||
|
|
||
| if not pr_number or not repo: | ||
| return { | ||
| "actions": [], | ||
| "error": "pull_request_review_comment missing pull_request.number or repository.full_name", | ||
| "event": "pull_request_review_comment", | ||
| } | ||
|
|
||
| # Strip trigger tokens so the model sees the actual request. | ||
| prompt = _TRIGGER_RE.sub("", body).strip() | ||
| if not prompt: | ||
| prompt = ( | ||
| "You were mentioned in a pull request review comment. " | ||
| "Acknowledge and ask how you can help (one short paragraph)." | ||
| ) | ||
|
|
||
| pr_title = pr.get("title") or "" | ||
| messages = [ | ||
| { | ||
| "role": "system", | ||
| "content": ( | ||
| "You are deepCore (DeepSeek CI agent) in Expert mode with thinking enabled. " | ||
| "Reply helpfully and concisely to the user's request on this GitHub pull request review. " | ||
| "Do not invent secrets, tokens, or private data. Keep the reply under ~1500 chars." | ||
| ), | ||
| }, | ||
| { | ||
| "role": "user", | ||
| "content": ( | ||
| f"PR #{pr_number}: {pr_title}\n\n" | ||
| f"User request in review comment:\n{prompt}" | ||
| ), | ||
| }, | ||
| ] | ||
|
|
There was a problem hiding this comment.
📝 Info: Review-comment handler duplicates the issue-comment handler inline instead of extracting a helper
The new ~100-line block inside run_ci is a near copy of _handle_issue_comment (deepcli/ci_agent.py:248-340): trigger stripping, system/user message construction, error/return shapes. Existing convention in this file factors comment handling into a private helper; keeping the review path inline makes run_ci long and means future fixes (e.g. prompt wording, soft-skip flags) must be applied twice. Consider a _handle_review_comment(event, session, peer, gh_env, thinking) helper mirroring the existing one.
Was this helpful? React with 👍 or 👎 to provide feedback.
| if event.get("comment") and event.get("pull_request") and not event.get("issue"): | ||
| comment = event.get("comment") or {} | ||
| body = (comment.get("body") or "").strip() | ||
| pr = event.get("pull_request") or {} | ||
| pr_number = pr.get("number") | ||
| repo = (event.get("repository") or {}).get("full_name") | ||
|
|
||
| if not pr_number or not repo: | ||
| return { | ||
| "actions": [], | ||
| "error": "pull_request_review_comment missing pull_request.number or repository.full_name", | ||
| "event": "pull_request_review_comment", | ||
| } | ||
|
|
||
| # Strip trigger tokens so the model sees the actual request. | ||
| prompt = _TRIGGER_RE.sub("", body).strip() |
There was a problem hiding this comment.
📝 Info: Trigger filter enforced only in workflow YAML, not in the Python handler
Neither _handle_issue_comment nor the new review-comment branch re-checks that the comment actually mentions the agent; the mention/bot filter lives solely in the job-level if. That means workflow_dispatch with a hand-crafted event_payload containing a comment + pull_request will unconditionally call the model and post a PR comment. Pre-existing for issue comments, now extended to review comments; a cheap _TRIGGER_RE.search(body) guard in the handlers would make the two layers consistent.
Was this helpful? React with 👍 or 👎 to provide feedback.
|
head_sha: 325a1f0 Peer review gate (ready for second-pass agents)External reviewers polled: CodeRabbit, Devin, Aikido, Sentry, Copilot. Peer activity (truncated): Downstream: |
🔀 OpenRouter review (
|
|
@coderabbitai fix |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
repo="timerloggedout-spec/termux-monorepo"
printf '%s\n' '=== Linked issue comments ==='
for comment_id in 5294326848 5294234358; do
gh api "repos/${repo}/issues/comments/${comment_id}" \
--jq '"ID: \(.id)\nURL: \(.html_url)\nAuthor: \(.user.login)\nCreated: \(.created_at)\nBody:\n\(.body)\n---"'
done
printf '%s\n' '=== Relevant repository files ==='
fd -a '^(deepseek-ci\.yml|ci_agent\.py)$' . | sort
printf '%s\n' '=== Workflow outline and content ==='
ast-grep outline .github/workflows/deepseek-ci.yml --items all 2>/dev/null || true
cat -n .github/workflows/deepseek-ci.yml
printf '%s\n' '=== DeepSeek CI agent outline ==='
agent_file="$(fd -a '^ci_agent\.py$' . | head -n 1)"
if [ -n "$agent_file" ]; then
ast-grep outline "$agent_file" --items all
fiLength of output: 12343 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo="timerloggedout-spec/termux-monorepo"
pr_number="212"
printf '%s\n' '=== Pull request review comments ==='
for review_id in 4937921881 4937883037; do
gh api "repos/${repo}/pulls/${pr_number}/reviews/${review_id}" \
--jq '"ID: \(.id)\nURL: \(.html_url)\nAuthor: \(.user.login)\nState: \(.state)\nBody:\n\(.body)\n---"'
done
printf '%s\n' '=== Inline pull request discussion ==='
gh api "repos/${repo}/pulls/comments/3784349710" \
--jq '"ID: \(.id)\nURL: \(.html_url)\nPath: \(.path)\nLine: \(.line)\nBody:\n\(.body)\n---"'
printf '%s\n' '=== Remaining issue comments ==='
for comment_id in 5294196495 5294190959; do
gh api "repos/${repo}/issues/comments/${comment_id}" \
--jq '"ID: \(.id)\nURL: \(.html_url)\nAuthor: \(.user.login)\nBody:\n\(.body)\n---"'
done
printf '%s\n' '=== Failed job metadata and failed steps ==='
gh api "repos/${repo}/actions/jobs/94788837585" \
--jq '{name, status, conclusion, started_at, completed_at, html_url, steps: [.steps[] | select(.conclusion == "failure") | {name, number, conclusion}]}'
gh api "repos/${repo}/actions/jobs/94788837585/logs" 2>&1 | tail -n 160 || true
printf '%s\n' '=== AGENTS.md candidates and contents ==='
fd -a -i '^agents\.md$' . | sort | while IFS= read -r file; do
printf '%s\n' "--- $file ---"
cat -n "$file"
done
printf '%s\n' '=== Review-comment event handling ==='
ast-grep run --pattern 'def $FUNC($$$):
$$$' --lang python deepcli/ci_agent.py | sed -n '/def _handle_issue_comment/,/def run_ci/p'
sed -n '220,410p' deepcli/ci_agent.pyLength of output: 55451 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '=== Remaining review-comment handler ==='
sed -n '344,470p' deepcli/ci_agent.py
printf '%s\n' '=== ci_agent tests and related test patterns ==='
fd -a -i '(^test_.*ci_agent.*\.py$|^.*ci_agent.*test.*\.py$|^conftest\.py$)' . | sort
rg -n -C 3 --glob '*.py' \
'run_ci\s*\(|_handle_issue_comment\s*\(|_post_gh_comment\s*\(|subprocess\.run\s*\(' \
. \
-g '!deepcli/ci_agent.py'
printf '%s\n' '=== Existing GitHub API reply patterns ==='
rg -n -C 3 --glob '*.py' \
'in_reply_to|pulls/comments|/comments' \
. \
-g '!deepcli/ci_agent.py'Length of output: 121600
The current partial fix prevents the no-op. However, it posts a general PR comment. It does not reply in the originating review thread. The implementation must use:
with the triggering review comment ID as It must also require The cancelled Actions job has no retained logs. It does not provide evidence of another runtime failure. The plan includes:
You are interacting with an AI system. |
|
@jules Auto-resolve (heyVern lane / GHA agent-review-auto-jules) — do not wait for a human ping. Feedback excerptLength of output: 12343 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo="timerloggedout-spec/termux-monorepo"
pr_number="212"
printf '%s\n' '=== Pull request reInstructions
|
|
@coderabbitai implement your plan: |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '=== Relevant files ==='
fd -a -i '^(deepseek-ci\.yml|ci_agent\.py|test_ci_agent\.py|agents\.md)$' . | sort
printf '%s\n' '=== Workflow ==='
cat -n .github/workflows/deepseek-ci.yml
printf '%s\n' '=== Agent structure ==='
ast-grep outline deepcli/ci_agent.py --items all
printf '%s\n' '=== Review and comment handling ==='
rg -n -C 8 --glob 'ci_agent.py' \
'def (_handle_issue_comment|_post_gh_comment|run_ci)|review_comment|issue_comment|in_reply_to|pulls/comments' \
deepcli
printf '%s\n' '=== Focused tests ==='
test_file="$(fd -a -i '^test_ci_agent\.py$' . | head -n 1 || true)"
if [ -n "$test_file" ]; then
ast-grep outline "$test_file" --items all
rg -n -C 5 'run_ci|_handle_issue_comment|_post_gh_comment|review_comment|issue_comment' "$test_file"
fi
printf '%s\n' '=== AGENTS documentation ==='
fd -a -i '^agents\.md$' . | sort | while IFS= read -r file; do
printf '%s\n' "--- $file ---"
rg -n -C 4 'DeepSeek|deepseek|issue_comment|review_comment|trigger' "$file" || true
doneLength of output: 28913 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '=== Review-comment handler and lifecycle boundary ==='
sed -n '344,535p' deepcli/ci_agent.py
printf '%s\n' '=== Existing Python tests and configuration ==='
fd -a -i '(^test_.*\.py$|^.*_test\.py$|^pytest\.ini$|^pyproject\.toml$|^tox\.ini$|^setup\.cfg$)' . \
-E .git -E node_modules -E dist -E build | sort | head -n 240
printf '%s\n' '=== Test imports and mocking conventions ==='
rg -n -C 4 --glob 'test_*.py' --glob '*_test.py' \
'(unittest|pytest|mock|patch|monkeypatch|subprocess\.run|deepcli)' . \
-g '!**/node_modules/**' -g '!**/dist/**' -g '!**/build/**' | head -n 500
printf '%s\n' '=== Python project configuration ==='
for file in pyproject.toml pytest.ini tox.ini setup.cfg; do
if [ -f "$file" ]; then
printf '%s\n' "--- $file ---"
cat -n "$file"
fi
doneLength of output: 39790
You are interacting with an AI system. |
|
@jules Auto-resolve (heyVern lane / GHA agent-review-auto-jules) — do not wait for a human ping. Feedback excerptInstructions
|
|
The requested changes were prepared, but the pull request could not be created. Warning I couldn't create the pull request branch. This branch's GitHub Actions workflow files ( How to fix: update this branch with If this branch is already up to date with |
|
@coderabbitai resolve merge conflict && create the PR from: #212 (comment) |
|
✅ No merge conflicts detected when merging into Your branch is good to go! |
|
sha: 325a1f0 @jules opsSweep (heyVern lane) — high-perf unattended advance. PR #212 · Instructions
Monikers: docs/ops/AGENT-MONIKERS.md · Read AGENTS.md. |
|
The requested changes were prepared, but the pull request could not be created. Warning I couldn't create the pull request branch. This branch's GitHub Actions workflow files ( How to fix: update this branch with If this branch is already up to date with |
|
@jules Auto-resolve (heyVern lane / GHA agent-review-auto-jules) — do not wait for a human ping. Feedback excerptInstructions
|
OPERATOR eval — CodeRabbit permissions / workflow blockers (comment)What the comment meansTwo independent GitHub platform constraints hit CodeRabbit:
This is not a CodeRabbit bug. Refreshing “repository write access” alone does not grant workflow-file write unless the GitHub App is explicitly allowed to modify Actions workflows (rare for review bots by design). What already landed on this branch
What OPERATOR just applied
Optional follow-ups (not blockers for merge)
Merge postureFunctional gap that caused the original “no-op on review comments” is closed. Remaining items are polish. Vercel free-tier rate limit is unrelated noise. |
|
head_sha: b847429 Peer review gate (ready for second-pass agents)External reviewers polled: CodeRabbit, Devin, Aikido, Sentry, Copilot. Peer activity (truncated): Downstream: |
| messages = [ | ||
| { | ||
| "role": "system", | ||
| "content": ( | ||
| "You are deepCore (DeepSeek CI agent) in Expert mode with thinking enabled. " | ||
| "Reply helpfully and concisely to the user's request on this GitHub pull request review. " | ||
| "Do not invent secrets, tokens, or private data. Keep the reply under ~1500 chars." | ||
| ), | ||
| }, | ||
| { | ||
| "role": "user", | ||
| "content": ( | ||
| f"PR #{pr_number}: {pr_title}\n\n" | ||
| f"User request in review comment:\n{prompt}" | ||
| ), | ||
| }, | ||
| ] |
There was a problem hiding this comment.
📝 Info: Review-comment handler ignores the inline diff context
The prompt built for review comments only includes the PR number, PR title and the comment text (deepcli/ci_agent.py:396-412). pull_request_review_comment payloads carry comment.path, comment.line and comment.diff_hunk, which are exactly the context a reviewer expects the agent to reason about. Without them the model answers inline code questions blind. Also note the ~90 lines are inlined into run_ci rather than factored into a _handle_review_comment helper mirroring _handle_issue_comment (deepcli/ci_agent.py:249), duplicating the prompt/post/error-result structure.
Was this helpful? React with 👍 or 👎 to provide feedback.
| run: | | ||
| python -m pip install --upgrade pip | ||
| pip install requests pyyaml | ||
| python -c "import requests; print('requests', requests.__version__)" |
There was a problem hiding this comment.
📝 Info: New pip step relies on default shell -e rather than the explicit pipefail pattern used elsewhere
Other multi-line run blocks in this workflow start with set -euo pipefail (e.g. .github/workflows/deepseek-ci.yml:110). The new block omits it; GitHub's default bash -e {0} still aborts on a failing command, so the verification line does gate the step, but the inconsistency is worth normalizing. The python -c "import requests; ..." check only proves the import works on the runner, which is unrelated to the reported CI failure mode (DeepSeek auth/soft-skip), so it is diagnostics rather than a fix.
Was this helpful? React with 👍 or 👎 to provide feedback.
🔀 OpenRouter review (
|
OPERATOR — CodeRabbit "full workflow scope" reality checkCannot grant what the app does not request.
What YOU can still do (human, 30s)
DeepSeek path (done by OPERATOR, not CodeRabbit)
Bottom line: CodeRabbit stays a reviewer/autofixer for non-workflow files. Workflow files = OPERATOR. That’s the correct security model, not a regression. |
|
Tip For best results, initiate chat on the files or code changes.
The workflow write block is a GitHub App permission limitation. It is separate from repository access and GitHub Actions For this repository, workflow changes should remain with the OPERATOR or another credential that has GitHub Workflows write permission. CodeRabbit can continue to review and autofix non-workflow files. The DeepSeek review-comment path and concurrency update are now covered by the operator changes. 🐇 ✏️ Learnings added
🧠 Learnings usedYou are interacting with an AI system. |
|
head_sha: a39c317 Peer review gate (ready for second-pass agents)External reviewers polled: CodeRabbit, Devin, Aikido, Sentry, Copilot. Peer activity (truncated): Downstream: |
| cmd = [ | ||
| "gh", | ||
| "api", | ||
| "--method", | ||
| "POST", | ||
| f"repos/{repo}/pulls/{pr_number}/comments", | ||
| "-f", | ||
| f"body={body[:2000]}", | ||
| "-F", | ||
| f"in_reply_to={comment_id}", | ||
| ] |
There was a problem hiding this comment.
📝 Info: Threaded reply API usage verified
gh api POST repos/{repo}/pulls/{n}/comments with in_reply_to is a supported way to create a reply in an existing review thread (all other body params are ignored when in_reply_to is set), and -F sends the id as a number as the API expects. pull-requests: write in the job permissions covers this write, so the call itself should work.
Was this helpful? React with 👍 or 👎 to provide feedback.
| # --- pull_request_review_comment path --- | ||
| # Review comments have comment + pull_request but no issue key. | ||
| # Handle them as threaded replies within the review thread. | ||
| if event.get("comment") and event.get("pull_request") and not event.get("issue"): |
There was a problem hiding this comment.
📝 Info: Event routing relies on payload key presence rather than an explicit event name
Routing distinguishes review comments from issue comments by comment && pull_request && not issue. This holds for real GitHub payloads, but workflow_dispatch accepts an arbitrary event_payload JSON (.github/workflows/deepseek-ci.yml:18-21), so a hand-crafted payload containing both comment and pull_request would take the review-reply path and attempt an in_reply_to post with an arbitrary comment id. Using GITHUB_EVENT_NAME (or a passed-in event name) would make routing unambiguous.
Was this helpful? React with 👍 or 👎 to provide feedback.
| pull_request_review_comment: | ||
| types: [created] |
There was a problem hiding this comment.
🟨 Untrusted inline review comment text drives an authenticated agent that posts back with an elevated PAT
The new pull_request_review_comment trigger lets any user able to comment on a PR feed arbitrary text into the model prompt (deepcli/ci_agent.py:427-451), and the resulting model output is posted back to the repository using the operator PAT (.github/workflows/deepseek-ci.yml:57-58). Only a bot-type and mention-substring filter gates execution (.github/workflows/deepseek-ci.yml:38-51); there is no association/permission check (e.g. author_association OWNER/MEMBER/COLLABORATOR) as done for other automation. Because the workflow runs in the base-repo context with pull-requests: write and issues: write and a long-lived PAT, an outside contributor's comment can drive prompt-controlled content into repository comments and consume the privileged token's quota.
Was this helpful? React with 👍 or 👎 to provide feedback.
Summary
Minimal, non-regressive fix for DeepSeek CI comment triggers.
Closes the gap left by rejected #209 / #210 (those pointed at the old broken
feat/gh-actions/deepseek-integrates-itselftip and would have wiped master’s workingissue_comment+ soft-skip stack).Changes (1 file)
pull_request_review_comment: types: [created]so inline review comments can trigger the agentifto apply the same bot/mention filter to review commentspython -m pip install --upgrade pip+ verifyrequestsimport/versionAlready on master (kept intact)
issue_commenttrigger +@deepseek/@deepCoremention filterci_agent._handle_issue_commentreply pathRelated
gh/gitActions Workflows integration #109 scopecc @timerloggedout-spec
Summary by CodeRabbit
requestsversion.