Skip to content

hotfix: DeepSeek CI — pull_request_review_comment + pip verify - #212

Merged
timerloggedout-spec merged 4 commits into
masterfrom
hotfix/deepseek-ci-review-comment
Aug 14, 2026
Merged

timerloggedout-spec merged 4 commits into
masterfrom
hotfix/deepseek-ci-review-comment

Conversation

@timerloggedout-spec

@timerloggedout-spec timerloggedout-spec commented Aug 14, 2026 •

Copy link
Copy Markdown
Owner

Summary

Minimal, non-regressive fix for DeepSeek CI comment triggers.

Closes the gap left by rejected #209 / #210 (those pointed at the old broken feat/gh-actions/deepseek-integrates-itself tip and would have wiped master’s working issue_comment + soft-skip stack).

Changes (1 file)

  • Add pull_request_review_comment: types: [created] so inline review comments can trigger the agent
  • Extend the job if to apply the same bot/mention filter to review comments
  • Pip: python -m pip install --upgrade pip + verify requests import/version

Already on master (kept intact)

  • issue_comment trigger + @deepseek / @deepCore mention filter
  • Soft-skip on missing/expired DeepSeek tokens
  • ci_agent._handle_issue_comment reply path
  • WASM staging, session cache, account-1 priority

Related

cc @timerloggedout-spec


Open in Devin Review

Summary by CodeRabbit

  • Chores
    • Updated automation to respond to newly created pull request review comments.
    • Improved filtering to exclude bot-generated comment noise.
    • Enhanced Python setup by upgrading package tools and reporting the installed requests version.

@blocksorg

blocksorg Bot commented Aug 14, 2026

Copy link
Copy Markdown

Mention Blocks like a regular teammate with your question or request:

@blocks review this pull request
@blocks make the following changes ...
@blocks create an issue from what was mentioned in the following comment ...
@blocks explain the following code ...
@blocks are there any security or performance concerns?

Run @blocks /help for more information.

Workspace settings | Disable this message

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@vercel

vercel Bot commented Aug 14, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
termux-monorepo Ready Ready Preview, v0 Aug 14, 2026 3:19pm

@gitar-bot

gitar-bot Bot commented Aug 14, 2026 •

Copy link
Copy Markdown

Gitar is working

Gitar

@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Fix DeepSeek CI: trigger on review comments and verify pip/requests

🐞 Bug fix ⚙️ Configuration changes 🕐 10-20 Minutes

Grey Divider

AI Description

• Enable DeepSeek CI to run on inline PR review comments.
• Apply the same bot/mention filter logic to review-comment events.
• Harden Python setup by upgrading pip and sanity-checking requests import/version.
Diagram

graph TD
  A["GitHub Events"] --> B["deepseek-ci.yml"] --> C{ "Event is comment?" } --> D["Mention/Bot Filter"] --> E["deepseek-agent job"] --> F["Install deps + verify"]
  C -->|"PR / dispatch"| E
  C -->|"issue_comment / review_comment"| D
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Use pull_request_review (submitted) instead of review_comment
  • ➕ Captures review submission events (approve/request changes) beyond inline comment creation
  • ➖ Does not trigger on inline comment creation; changes behavior vs the stated goal
2. Split comment triggers into a dedicated job
  • ➕ Keeps comment gating logic isolated and easier to reason about
  • ➕ Allows different timeouts/permissions for comment-driven runs
  • ➖ More workflow complexity for a small hotfix
  • ➖ Risk of duplicating setup steps or diverging behavior
3. Centralize gating via a reusable workflow
  • ➕ Standardizes the bot/mention filter across workflows
  • ➕ Reduces repetition if multiple agents exist
  • ➖ Overkill for a single workflow change
  • ➖ Adds indirection that can slow down hotfix iteration

Recommendation: The current approach (adding pull_request_review_comment + extending the existing if-guard) is the best fit for a minimal, non-regressive hotfix: it preserves established behavior for issue_comment while closing the review-comment trigger gap with minimal workflow complexity.

Files changed (1) +8 / -3

Other (1) +8 / -3
deepseek-ci.ymlTrigger on PR review comments; extend gating; upgrade pip and verify requests +8/-3

Trigger on PR review comments; extend gating; upgrade pip and verify requests

• Adds the pull_request_review_comment(created) trigger so inline review comments can invoke the workflow. Extends the job-level conditional to apply the existing bot/mention gating to both issue comments and review comments. Hardens dependency setup by upgrading pip and verifying the installed requests version via an import check.

.github/workflows/deepseek-ci.yml

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 4 potential issues.

Open in Devin Review

Comment thread .github/workflows/deepseek-ci.yml
Comment on lines +40 to 43
(github.event_name != 'issue_comment' && github.event_name != 'pull_request_review_comment') ||
(
github.event.comment.user.type != 'Bot' &&
(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Broad mention filter now also fires on every review comment containing "deepseek"

The mention filter includes bare contains(github.event.comment.body, 'deepseek') / 'DeepSeek', so any inline code-review comment that merely mentions DeepSeek in prose (very likely in this repo, whose code is DeepSeek-centric) will start the job. Combined with cancel-in-progress: true on a concurrency group keyed by PR number, a review pass that leaves several inline comments will repeatedly cancel and restart the agent for the same PR. Consider tightening the filter to explicit @ mentions for the review-comment path.

(Refers to lines 40-51)

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +16 to +17
pull_request_review_comment:
types: [created]

@devin-ai-integration devin-ai-integration Bot Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Documented trigger list in AGENTS.md is now out of date

AGENTS.md (CI/CD section) still states the DeepSeek workflow triggers on "PR opened, synchronize, reopened, manual dispatch", and deepcli/ci_agent.py docstring was updated but the ops doc referenced by the workflow header (docs/ops/DEEPSEEK-CI.md) was not checked in this PR. Consider updating both so the trigger matrix (now including issue_comment and pull_request_review_comment) is documented in one place.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +103 to +106
run: |
python -m pip install --upgrade pip
pip install requests pyyaml
python -c "import requests; print('requests', requests.__version__)"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Pip verification step does not validate pyyaml

The added verification only imports requests; pyyaml is installed in the same command but never verified, even though the agent code paths use YAML config loading. A single python -c "import requests, yaml" would cover both without extra cost.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@github-actions

Copy link
Copy Markdown
Contributor

@jules Auto-resolve (heyVern lane / GHA agent-review-auto-jules) — do not wait for a human ping.
Bot feedback from devin-ai-integration[bot] on PR #212 (branch hotfix/deepseek-ci-review-comment).
File: .github/workflows/deepseek-ci.yml

Feedback excerpt

<!-- devin-review-comment {"id": "BUG_pr-review-job-fdc076b5b44343eda1df077e95e77358_0001", "file_path": ".github/workflows/deepseek-ci.yml", "start_line": 16, "end_line": 17, "side": "RIGHT", "based_on_repo_rules": false} -->

🔴 **Inline review comments trigger the workflow but the assistant never replies**

Inline pull request review comments are now allowed to start the automation (new `pull_request_review_comment` trigger at `.github/workflows/deepseek-ci.yml:16-17`) even though the agent has no handling for them, so mentioning the bot in an inline comment burns a run and silently produces no answer.
Impact: Users who mention the bot in an inline code review comment get no response at all, while the run still appears green.

<details>
<summary>Dispatch in run_ci has no branch for review-comment payloads</summary>

`deepcli/ci_agent.py:363-366` routes to `_handle_issue_comment` only when the payload contains both `comment` and `issue`. A `pull_request_review_comment` payload contains `comment` and `pull_request` but no `issue`, so it falls through to the PR-lifecycle path at `deepcli/ci_agent.py:369-374`, where `action` is `"created"`, which is not in `["opened", "synchronize",

Instructions

  1. Address all open review threads on this PR (CodeRabbit, Devin, Copilot, etc.).
  2. Prefer minimal diffs; preserve Sentinel 0o600/0o700 if those files are touched.
  3. Push commits to branch hotfix/deepseek-ci-review-comment. Do not retarget away from the PR base without cause.
  4. If conflicts with base exist, resolve them.
  5. Skip pure nits only if they conflict with security/gates; otherwise apply autofixes.
    Monikers: docs/ops/AGENT-MONIKERS.md
    Agent: Grok (archW1z) orchestration · Profile: https://x.com/grok

@github-actions

Copy link
Copy Markdown
Contributor

head_sha: 2e8be18
ready: true
autofix_requested: false
timed_out: false

Peer review gate (ready for second-pass agents)

External reviewers polled: CodeRabbit, Devin, Aikido, Sentry, Copilot.
Autofix (if any) was requested in a separate comment on this SHA.

Peer activity (truncated):

review @devin-ai-integration[bot] state=COMMENTED sha=2e8be18

Downstream: gemini-after-peers. Jules: agent-review-auto-jules.

@github-actions

Copy link
Copy Markdown
Contributor

🔀 OpenRouter review (cohere/north-mini-code:free)

Second‑pass review (PR #212)

  • AGENTS.md – The DeepSeek PoW CI job appears new. Add a line for the DeepSeek agent (e.g., deepseek‑ci) under the appropriate “CI/Automation” section so it’s documented for downstream tooling and auditors.

  • File/permissions – The workflow file (.github/workflows/deepseek-ci.yml) should be 644 (owner rw, group r, other r). If any secret files or tokens are added elsewhere, they must be 600. Verify current modes (stat -c %a .github/workflows/deepseek-ci.yml and any *‑keys, env files).

  • Class 3/4 artifacts – No obvious secrets, keys, or binary payloads introduced in the diff. Still, run a quick git diff --name-only HEAD~1 to ensure no new artifacts slipped in, and run grep -R “api_key\|password\|secret\" .github/ (excluding .git/) to be safe.

  • Residual risks –

    • The workflow now listens to pull_request_review_comment events; ensure the if: guard truly blocks bot noise and you haven’t inadvertently opened a surface for unwanted actions.
    • The pip install upgrade and the python -c "import requests; …" debug line are fine for logs but could be removed for production if you prefer minimal output.
    • Confirm the job’s permissions (permissions: block) are scoped minimally (e.g., contents: read only) and that any required secrets are referenced via secrets.<name> with proper masking.

Action checklist before merge

  1. Update AGENTS.md with a brief entry for the DeepSeek PoW agent.
  2. Verify deepseek-ci.yml mode (should be 644) and any secret files (600).
  3. Run a secret‑scan over .github/ (or equivalent) to confirm no Class 3/4 artifacts.
  4. Double‑check the workflow’s if: condition and permissions: block.

If those are cleared, the PR is ready to merge.


Peer router: Omni ↔ OpenRouter by desired model; Gemini residual. role=review

@coderabbitai

coderabbitai Bot commented Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@timerloggedout-spec, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 44 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: eaaea09e-79ef-4663-8f50-061cc1ce5cc8

📥 Commits

Reviewing files that changed from the base of the PR and between 2e8be18 and b847429.

📒 Files selected for processing (2)
  • .github/workflows/deepseek-ci.yml
  • deepcli/ci_agent.py
📝 Walkthrough

Walkthrough

The DeepSeek CI workflow now responds to new pull request review comments, filters bot-generated comment events, and uses an expanded Python dependency setup that reports the installed requests version.

Changes

DeepSeek CI workflow

Layer / File(s) Summary
Review comment trigger and filtering
.github/workflows/deepseek-ci.yml
The workflow triggers on newly created pull request review comments. The job filter excludes bot-generated issue and review comments while allowing other supported events.
Python dependency setup
.github/workflows/deepseek-ci.yml
The workflow upgrades pip, installs requests and pyyaml, and prints the installed requests version.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: 🟡 Moderate · up to 2e8be

This change enables inline review comments to trigger DeepSeek CI, but the current workflow does not handle those payloads correctly, so comments may trigger work without receiving the intended response. Merge should wait for the handler/API path to be implemented or the trigger removed, with credential exposure for untrusted review-comment runs explicitly confirmed.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the review-comment trigger and pip verification changes in the pull request.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch hotfix/deepseek-ci-review-comment

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-code-review

qodo-code-review Bot commented Aug 14, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Review-comment trigger no-op ✓ Resolved 🐞 Bug ≡ Correctness
Description
deepseek-ci.yml now triggers on pull_request_review_comment (created), but
deepcli.ci_agent.run_ci() only handles issue_comment events (requires event.issue) or PR
lifecycle actions opened/synchronize/reopened. Review-comment events therefore run the job and
then exit without posting any DeepSeek response.
Code

.github/workflows/deepseek-ci.yml[R16-17]

+  pull_request_review_comment:
+    types: [created]
Relevance

●●● Strong

Team previously fixed similar no-op/trigger mismatches; review-comment support was explicitly
accepted in workflow logic.

PR-#163
PR-#193

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The workflow explicitly enables pull_request_review_comment created events. In the agent
dispatcher, the only comment-handling path requires event.issue, and the only PR-handling path is
restricted to opened/synchronize/reopened; therefore pull_request_review_comment with action
created falls through with no actions performed.

.github/workflows/deepseek-ci.yml[11-17]
deepcli/ci_agent.py[363-367]
deepcli/ci_agent.py[368-377]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
The workflow now triggers on `pull_request_review_comment` events, but the CI agent dispatcher (`deepcli/ci_agent.py:run_ci`) does not have a branch for that event type/action. As a result, runs triggered by inline review comments (action `created`) do nothing besides environment/session setup.

### Issue Context
- `pull_request_review_comment` payloads include `comment` and `pull_request`, but do not include `issue`.
- The current dispatcher only:
 - routes to `_handle_issue_comment` when both `event.comment` and `event.issue` exist, or
 - runs PR review when `action in [opened, synchronize, reopened]`.

### Fix Focus Areas
- .github/workflows/deepseek-ci.yml[11-17]
- deepcli/ci_agent.py[363-377]

### Suggested implementation direction
1. Add a new dispatch branch in `run_ci()` for review comment events:
  - Detect: `action == 'created'` AND `event.get('comment')` AND `event.get('pull_request')`.
  - Decide behavior:
    - (Minimal) reuse the existing PR-review path (fetch diff via `gh pr diff` and post a PR comment) when invoked from a review-comment trigger.
    - (Better UX) include the review comment body/path as additional prompt context.
2. Alternatively, if you do not intend to support this event yet, remove the new workflow trigger to avoid no-op CI runs.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context
✅ Compliance rules (platform): 11 rules
Review mode: ⚖️ Balanced: This changes GitHub Actions event routing and job eligibility plus dependency setup, so it has real CI behavior and security-adjacent trigger implications despite the small, localized diff.

Grey Divider

Tip of the day
💡 Did you know, you can describe a rule in plain language on the Rules page and Qodo drafts it for you

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

coderabbitai[bot]

This comment was marked as resolved.

qodo-code-review[bot]

This comment was marked as resolved.

@coderabbitai

coderabbitai Bot commented Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Fixes Applied Successfully

Fixed 1 file(s) based on 1 unresolved review comment.

Files modified:

  • deepcli/ci_agent.py

Commit: 325a1f00b22785ebc305d05da21bf97dba00529e

The changes have been pushed to the hotfix/deepseek-ci-review-comment branch.

Time taken: 3m 44s


⚠️ 1 file(s) could not be committed — the agent does not have permission to push to .github/workflows/. Please apply these changes manually:

.github/workflows/deepseek-ci.yml — 1 change:

Lines 27–33
         default: 'account-1'
 
 concurrency:
-  group: deepseek-ci-${{ github.event.pull_request.number || github.event.issue.number || github.run_id }}
+  group: deepseek-ci-${{ github.event.pull_request.number || github.event.issue.number || github.event.comment.id || github.run_id }}
   cancel-in-progress: true
 
 jobs:

Fixed 1 file(s) based on 1 unresolved review comment.

Co-authored-by: CodeRabbit <noreply@coderabbit.ai>
@vercel

vercel Bot commented Aug 14, 2026

Copy link
Copy Markdown

Deployment failed for project termux-monorepo with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 7 new potential issues.

Open in Devin Review

Comment on lines +16 to +17
pull_request_review_comment:
types: [created]

@devin-ai-integration devin-ai-integration Bot Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Multiple inline review comments on the same pull request cancel each other, so only the last one gets an answer

The new per-comment identifier added to the run grouping key (github.event.comment.id at .github/workflows/deepseek-ci.yml:30) is placed after two values that are always present for comment events, so it never takes effect and every comment on a pull request shares one cancellable run slot.
Impact: When someone leaves several inline review comments at once (or comments while an automated review is running), the earlier runs are cancelled and those comments silently never receive a reply.

Why the comment.id fallback is unreachable and what cancel-in-progress does

For pull_request_review_comment, the payload always contains pull_request.number, so github.event.pull_request.number wins the || chain and github.event.comment.id is never evaluated. For issue_comment, github.event.issue.number is always present, so again comment.id is dead. The resulting group is therefore identical to the pre-PR group (deepseek-ci-<pr/issue number>), while cancel-in-progress: true (.github/workflows/deepseek-ci.yml:31) kills any in-flight run in that group.

GitHub delivers one pull_request_review_comment event per inline comment, so submitting a review containing N mentioning comments creates N runs in the same group — N-1 get cancelled. A review comment also cancels an in-progress pull_request synchronize review for the same PR, and vice-versa. A comparable workflow in this repo avoids this by using cancel-in-progress: false (.github/workflows/agent-review-auto-jules.yml:16-17).

Putting comment.id first (when present) restores per-comment isolation, which appears to be the intent of the commit "fix(ci): include comment.id in DeepSeek concurrency group".

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread deepcli/ci_agent.py Outdated
Comment on lines +16 to +17
pull_request_review_comment:
types: [created]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Change does not reference a tracked work item as required by the repository process

The commits and PR body introducing the new comment trigger (pull_request_review_comment at .github/workflows/deepseek-ci.yml:16-17) omit the mandatory Implements: <ITEM-ID> citation required by the repository's agent rules.

Impact: The change cannot be traced back to an approved work item, breaking the project's tracking process.

Rule reference

AGENTS.md Hard Rules require: "Do not invent work outside docs/proposals/active/<id>/ITEMS.md — add a row first." and "Cite Implements: <ITEM-ID> on PRs/commits." Neither commit message (2e8be18, 325a1f0) nor the PR body contains an Implements: line.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines 38 to 43
# Parentheses required: && binds tighter than || in GHA expressions.
if: >-
github.event_name != 'issue_comment' ||
(github.event_name != 'issue_comment' && github.event_name != 'pull_request_review_comment') ||
(
github.event.comment.user.type != 'Bot' &&
(

@devin-ai-integration devin-ai-integration Bot Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Self-triggering loop risk: the agent's own review reply can re-trigger the workflow

The reply is posted with the operator PAT (GH_TOKEN set from OPERATOR_TOKEN in deepcli/ci_agent.py:358), and comments created with a PAT (unlike GITHUB_TOKEN) do trigger further workflow runs. The job filter (.github/workflows/deepseek-ci.yml:38-49) only excludes comment.user.type == 'Bot' and otherwise matches on any case-insensitive occurrence of deepseek/deepcore. Since the posted reply is **deepCore**\n\n{analysis} and the model output frequently mentions "DeepSeek", the reply can satisfy the mention filter and cause the agent to answer itself repeatedly. This risk already existed for the issue_comment path on master, but this PR extends it to review threads. A cheap mitigation is to also require that comment.user.login differs from the operator account, or to skip bodies starting with the deepCore moniker.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread deepcli/ci_agent.py
Comment on lines +370 to +413
# --- pull_request_review_comment path ---
# Review comments have comment + pull_request but no issue key.
# Handle them as PR comments (reply to review thread).
if event.get("comment") and event.get("pull_request") and not event.get("issue"):
comment = event.get("comment") or {}
body = (comment.get("body") or "").strip()
pr = event.get("pull_request") or {}
pr_number = pr.get("number")
repo = (event.get("repository") or {}).get("full_name")

if not pr_number or not repo:
return {
"actions": [],
"error": "pull_request_review_comment missing pull_request.number or repository.full_name",
"event": "pull_request_review_comment",
}

# Strip trigger tokens so the model sees the actual request.
prompt = _TRIGGER_RE.sub("", body).strip()
if not prompt:
prompt = (
"You were mentioned in a pull request review comment. "
"Acknowledge and ask how you can help (one short paragraph)."
)

pr_title = pr.get("title") or ""
messages = [
{
"role": "system",
"content": (
"You are deepCore (DeepSeek CI agent) in Expert mode with thinking enabled. "
"Reply helpfully and concisely to the user's request on this GitHub pull request review. "
"Do not invent secrets, tokens, or private data. Keep the reply under ~1500 chars."
),
},
{
"role": "user",
"content": (
f"PR #{pr_number}: {pr_title}\n\n"
f"User request in review comment:\n{prompt}"
),
},
]

@devin-ai-integration devin-ai-integration Bot Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Review-comment handler duplicates the issue-comment handler inline instead of extracting a helper

The new ~100-line block inside run_ci is a near copy of _handle_issue_comment (deepcli/ci_agent.py:248-340): trigger stripping, system/user message construction, error/return shapes. Existing convention in this file factors comment handling into a private helper; keeping the review path inline makes run_ci long and means future fixes (e.g. prompt wording, soft-skip flags) must be applied twice. Consider a _handle_review_comment(event, session, peer, gh_env, thinking) helper mirroring the existing one.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread deepcli/ci_agent.py
Comment on lines +373 to +388
if event.get("comment") and event.get("pull_request") and not event.get("issue"):
comment = event.get("comment") or {}
body = (comment.get("body") or "").strip()
pr = event.get("pull_request") or {}
pr_number = pr.get("number")
repo = (event.get("repository") or {}).get("full_name")

if not pr_number or not repo:
return {
"actions": [],
"error": "pull_request_review_comment missing pull_request.number or repository.full_name",
"event": "pull_request_review_comment",
}

# Strip trigger tokens so the model sees the actual request.
prompt = _TRIGGER_RE.sub("", body).strip()

@devin-ai-integration devin-ai-integration Bot Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Trigger filter enforced only in workflow YAML, not in the Python handler

Neither _handle_issue_comment nor the new review-comment branch re-checks that the comment actually mentions the agent; the mention/bot filter lives solely in the job-level if. That means workflow_dispatch with a hand-crafted event_payload containing a comment + pull_request will unconditionally call the model and post a PR comment. Pre-existing for issue comments, now extended to review comments; a cheap _TRIGGER_RE.search(body) guard in the handlers would make the two layers consistent.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread .github/workflows/deepseek-ci.yml
@github-actions

Copy link
Copy Markdown
Contributor

head_sha: 325a1f0
ready: true
autofix_requested: false
timed_out: false

Peer review gate (ready for second-pass agents)

External reviewers polled: CodeRabbit, Devin, Aikido, Sentry, Copilot.
Autofix (if any) was requested in a separate comment on this SHA.

Peer activity (truncated):

review @devin-ai-integration[bot] state=COMMENTED sha=325a1f0 | review @devin-ai-integration[bot] state=COMMENTED sha=325a1f0

Downstream: gemini-after-peers. Jules: agent-review-auto-jules.

@github-actions

Copy link
Copy Markdown
Contributor

🔀 OpenRouter review (cohere/north-mini-code:free)

Second‑Pass Summary (PR #212)

  • Security / Permissions – No new executable bits introduced; existing file modes stay safe (workflow YAMLs remain 0o644, .py stays non‑executable). No secrets or tokens exposed in logs (debug requests version printed only to CI run logs).

  • Class 3/4 Artifacts – The added debug line and new handling path are low‑risk; they emit only non‑sensitive metadata and use the same safe _post_gh_comment flow as existing PR/issue comment handling.

  • AGENTS.md – Missing – The doc currently lists deepCore events (PR opened, issue_comment with triggers) but does not document the new pull_request_review_comment trigger added in this PR. Update AGENTS.md to include a brief entry for this event (e.g., “Responds to /deepcore … in PR review comments, posts concise replies”).

  • Residual Risk – Primarily documentation‑only; no functional regression. Ensure AGENTS.md is refreshed before merge.


Peer router: Omni ↔ OpenRouter by desired model; Gemini residual. role=review

@timerloggedout-spec

Copy link
Copy Markdown
Owner Author

@coderabbitai fix
#212 (comment)
&&
#212 (comment)
&& Issues linked here:
#212 (comment)

@coderabbitai

coderabbitai Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="timerloggedout-spec/termux-monorepo"

printf '%s\n' '=== Linked issue comments ==='
for comment_id in 5294326848 5294234358; do
  gh api "repos/${repo}/issues/comments/${comment_id}" \
    --jq '"ID: \(.id)\nURL: \(.html_url)\nAuthor: \(.user.login)\nCreated: \(.created_at)\nBody:\n\(.body)\n---"'
done

printf '%s\n' '=== Relevant repository files ==='
fd -a '^(deepseek-ci\.yml|ci_agent\.py)$' . | sort

printf '%s\n' '=== Workflow outline and content ==='
ast-grep outline .github/workflows/deepseek-ci.yml --items all 2>/dev/null || true
cat -n .github/workflows/deepseek-ci.yml

printf '%s\n' '=== DeepSeek CI agent outline ==='
agent_file="$(fd -a '^ci_agent\.py$' . | head -n 1)"
if [ -n "$agent_file" ]; then
  ast-grep outline "$agent_file" --items all
fi

Length of output: 12343


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="timerloggedout-spec/termux-monorepo"
pr_number="212"

printf '%s\n' '=== Pull request review comments ==='
for review_id in 4937921881 4937883037; do
  gh api "repos/${repo}/pulls/${pr_number}/reviews/${review_id}" \
    --jq '"ID: \(.id)\nURL: \(.html_url)\nAuthor: \(.user.login)\nState: \(.state)\nBody:\n\(.body)\n---"'
done

printf '%s\n' '=== Inline pull request discussion ==='
gh api "repos/${repo}/pulls/comments/3784349710" \
  --jq '"ID: \(.id)\nURL: \(.html_url)\nPath: \(.path)\nLine: \(.line)\nBody:\n\(.body)\n---"'

printf '%s\n' '=== Remaining issue comments ==='
for comment_id in 5294196495 5294190959; do
  gh api "repos/${repo}/issues/comments/${comment_id}" \
    --jq '"ID: \(.id)\nURL: \(.html_url)\nAuthor: \(.user.login)\nBody:\n\(.body)\n---"'
done

printf '%s\n' '=== Failed job metadata and failed steps ==='
gh api "repos/${repo}/actions/jobs/94788837585" \
  --jq '{name, status, conclusion, started_at, completed_at, html_url, steps: [.steps[] | select(.conclusion == "failure") | {name, number, conclusion}]}'
gh api "repos/${repo}/actions/jobs/94788837585/logs" 2>&1 | tail -n 160 || true

printf '%s\n' '=== AGENTS.md candidates and contents ==='
fd -a -i '^agents\.md$' . | sort | while IFS= read -r file; do
  printf '%s\n' "--- $file ---"
  cat -n "$file"
done

printf '%s\n' '=== Review-comment event handling ==='
ast-grep run --pattern 'def $FUNC($$$):
  $$$' --lang python deepcli/ci_agent.py | sed -n '/def _handle_issue_comment/,/def run_ci/p'
sed -n '220,410p' deepcli/ci_agent.py

Length of output: 55451


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '=== Remaining review-comment handler ==='
sed -n '344,470p' deepcli/ci_agent.py

printf '%s\n' '=== ci_agent tests and related test patterns ==='
fd -a -i '(^test_.*ci_agent.*\.py$|^.*ci_agent.*test.*\.py$|^conftest\.py$)' . | sort
rg -n -C 3 --glob '*.py' \
  'run_ci\s*\(|_handle_issue_comment\s*\(|_post_gh_comment\s*\(|subprocess\.run\s*\(' \
  . \
  -g '!deepcli/ci_agent.py'

printf '%s\n' '=== Existing GitHub API reply patterns ==='
rg -n -C 3 --glob '*.py' \
  'in_reply_to|pulls/comments|/comments' \
  . \
  -g '!deepcli/ci_agent.py'

Length of output: 121600


@timerloggedout-spec, the requested fixes are fully scoped.

The current partial fix prevents the no-op. However, it posts a general PR comment. It does not reply in the originating review thread.

The implementation must use:

POST /repos/{owner}/{repo}/pulls/{pull_number}/comments

with the triggering review comment ID as in_reply_to.

It must also require event.action == "created". This prevents unsupported review-comment actions from dispatching a response.

The cancelled Actions job has no retained logs. It does not provide evidence of another runtime failure.

The plan includes:

  • Threaded review-comment replies in deepcli/ci_agent.py.
  • Focused new tests in tests/test_ci_agent.py.
  • The workflow concurrency key update.
  • AGENTS.md trigger documentation.

You are interacting with an AI system.

@github-actions

Copy link
Copy Markdown
Contributor

@jules Auto-resolve (heyVern lane / GHA agent-review-auto-jules) — do not wait for a human ping.
Bot feedback from coderabbitai[bot] on PR #212 (branch hotfix/deepseek-ci-review-comment).

Feedback excerpt

<!-- This is an auto-generated reply by CodeRabbit -->
> [!TIP]
> For best results, initiate chat on the files or code changes.

<details>
<summary>🧩 Analysis chain</summary>

🏁 Script executed:

```shell
#!/bin/bash
set -euo pipefail

repo="timerloggedout-spec/termux-monorepo"

printf '%s\n' '=== Linked issue comments ==='
for comment_id in 5294326848 5294234358; do
  gh api "repos/${repo}/issues/comments/${comment_id}" \
    --jq '"ID: \(.id)\nURL: \(.html_url)\nAuthor: \(.user.login)\nCreated: \(.created_at)\nBody:\n\(.body)\n---"'
done

printf '%s\n' '=== Relevant repository files ==='
fd -a '^(deepseek-ci\.yml|ci_agent\.py)$' . | sort

printf '%s\n' '=== Workflow outline and content ==='
ast-grep outline .github/workflows/deepseek-ci.yml --items all 2>/dev/null || true
cat -n .github/workflows/deepseek-ci.yml

printf '%s\n' '=== DeepSeek CI agent outline ==='
agent_file="$(fd -a '^ci_agent\.py$' . | head -n 1)"
if [ -n "$agent_file" ]; then
  ast-grep outline "$agent_file" --items all
fi

Length of output: 12343


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo="timerloggedout-spec/termux-monorepo"
pr_number="212"

printf '%s\n' '=== Pull request re

Instructions

  1. Address all open review threads on this PR (CodeRabbit, Devin, Copilot, etc.).
  2. Prefer minimal diffs; preserve Sentinel 0o600/0o700 if those files are touched.
  3. Push commits to branch hotfix/deepseek-ci-review-comment. Do not retarget away from the PR base without cause.
  4. If conflicts with base exist, resolve them.
  5. Skip pure nits only if they conflict with security/gates; otherwise apply autofixes.
    Monikers: docs/ops/AGENT-MONIKERS.md
    Agent: Grok (archW1z) orchestration · Profile: https://x.com/grok

@timerloggedout-spec

Copy link
Copy Markdown
Owner Author

@coderabbitai implement your plan:
#212 (comment)

@coderabbitai

coderabbitai Bot commented Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '=== Relevant files ==='
fd -a -i '^(deepseek-ci\.yml|ci_agent\.py|test_ci_agent\.py|agents\.md)$' . | sort

printf '%s\n' '=== Workflow ==='
cat -n .github/workflows/deepseek-ci.yml

printf '%s\n' '=== Agent structure ==='
ast-grep outline deepcli/ci_agent.py --items all
printf '%s\n' '=== Review and comment handling ==='
rg -n -C 8 --glob 'ci_agent.py' \
  'def (_handle_issue_comment|_post_gh_comment|run_ci)|review_comment|issue_comment|in_reply_to|pulls/comments' \
  deepcli

printf '%s\n' '=== Focused tests ==='
test_file="$(fd -a -i '^test_ci_agent\.py$' . | head -n 1 || true)"
if [ -n "$test_file" ]; then
  ast-grep outline "$test_file" --items all
  rg -n -C 5 'run_ci|_handle_issue_comment|_post_gh_comment|review_comment|issue_comment' "$test_file"
fi

printf '%s\n' '=== AGENTS documentation ==='
fd -a -i '^agents\.md$' . | sort | while IFS= read -r file; do
  printf '%s\n' "--- $file ---"
  rg -n -C 4 'DeepSeek|deepseek|issue_comment|review_comment|trigger' "$file" || true
done

Length of output: 28913


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '=== Review-comment handler and lifecycle boundary ==='
sed -n '344,535p' deepcli/ci_agent.py

printf '%s\n' '=== Existing Python tests and configuration ==='
fd -a -i '(^test_.*\.py$|^.*_test\.py$|^pytest\.ini$|^pyproject\.toml$|^tox\.ini$|^setup\.cfg$)' . \
  -E .git -E node_modules -E dist -E build | sort | head -n 240

printf '%s\n' '=== Test imports and mocking conventions ==='
rg -n -C 4 --glob 'test_*.py' --glob '*_test.py' \
  '(unittest|pytest|mock|patch|monkeypatch|subprocess\.run|deepcli)' . \
  -g '!**/node_modules/**' -g '!**/dist/**' -g '!**/build/**' | head -n 500

printf '%s\n' '=== Python project configuration ==='
for file in pyproject.toml pytest.ini tox.ini setup.cfg; do
  if [ -f "$file" ]; then
    printf '%s\n' "--- $file ---"
    cat -n "$file"
  fi
done

Length of output: 39790


  • Add a pull request review-comment action gate.
  • Post each reply in the source review thread.
  • Preserve the issue-comment and PR lifecycle paths.
  • Add pytest coverage.
  • Update workflow concurrency and trigger documentation.

  • ❌ Failed to create pull request - (🔄 Check again to retry)

You are interacting with an AI system.

@github-actions

Copy link
Copy Markdown
Contributor

@jules Auto-resolve (heyVern lane / GHA agent-review-auto-jules) — do not wait for a human ping.
Bot feedback from coderabbitai[bot] on PR #212 (branch hotfix/deepseek-ci-review-comment).

Feedback excerpt

<!-- This is an auto-generated reply by CodeRabbit -->
> [!TIP]
> For best results, initiate chat on the files or code changes.

<details>
<summary>🧩 Analysis chain</summary>

🏁 Script executed:

```shell
#!/bin/bash
set -euo pipefail

printf '%s\n' '=== Relevant files ==='
fd -a -i '^(deepseek-ci\.yml|ci_agent\.py|test_ci_agent\.py|agents\.md)$' . | sort

printf '%s\n' '=== Workflow ==='
cat -n .github/workflows/deepseek-ci.yml

printf '%s\n' '=== Agent structure ==='
ast-grep outline deepcli/ci_agent.py --items all
printf '%s\n' '=== Review and comment handling ==='
rg -n -C 8 --glob 'ci_agent.py' \
  'def (_handle_issue_comment|_post_gh_comment|run_ci)|review_comment|issue_comment|in_reply_to|pulls/comments' \
  deepcli

printf '%s\n' '=== Focused tests ==='
test_file="$(fd -a -i '^test_ci_agent\.py$' . | head -n 1 || true)"
if [ -n "$test_file" ]; then
  ast-grep outline "$test_file" --items all
  rg -n -C 5 'run_ci|_handle_issue_comment|_post_gh_comment|review_comment|issue_comment' "$test_file"
fi

printf '%s\n' '=== AGENTS documentation ==='
fd -a -i '^agents\.md$' . | sort | while IFS= read -r file; do
  printf '%s\n' "--- $file ---"
  rg -n -C 4 'DeepSeek|deepseek|issue_

Instructions

  1. Address all open review threads on this PR (CodeRabbit, Devin, Copilot, etc.).
  2. Prefer minimal diffs; preserve Sentinel 0o600/0o700 if those files are touched.
  3. Push commits to branch hotfix/deepseek-ci-review-comment. Do not retarget away from the PR base without cause.
  4. If conflicts with base exist, resolve them.
  5. Skip pure nits only if they conflict with security/gates; otherwise apply autofixes.
    Monikers: docs/ops/AGENT-MONIKERS.md
    Agent: Grok (archW1z) orchestration · Profile: https://x.com/grok

@coderabbitai

coderabbitai Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

The requested changes were prepared, but the pull request could not be created.

Warning

I couldn't create the pull request branch. This branch's GitHub Actions workflow files (.github/workflows/) have diverged from master, and GitHub blocks CodeRabbit from creating a branch that carries them.

How to fix: update this branch with master (merge or rebase), then re-run this command and I'll open the pull request. If updating causes merge conflicts, comment @coderabbitai resolve merge conflict and I'll resolve them first.

If this branch is already up to date with master, CodeRabbit may be missing repository write access — ask a repository admin to refresh its permissions.

@timerloggedout-spec

Copy link
Copy Markdown
Owner Author

@coderabbitai resolve merge conflict && create the PR from: #212 (comment)

@coderabbitai

coderabbitai Bot commented Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

✅ No merge conflicts detected when merging into master.

Your branch is good to go!

@timerloggedout-spec

Copy link
Copy Markdown
Owner Author

sha: 325a1f0
state: unstable
threads_open: 12

@jules opsSweep (heyVern lane) — high-perf unattended advance.

PR #212 · hotfix/deepseek-ci-review-comment → master
Why: 12 unresolved review thread(s)

Instructions

  • Address all open review threads (CodeRabbit, Devin, Copilot).
  • Prefer minimal diffs; preserve Sentinel 0o600/0o700.
  • Push to existing head branch. No Class 3/4 artifacts.

Monikers: docs/ops/AGENT-MONIKERS.md · Read AGENTS.md.
Agent: Grok (archW1z) orchestration · https://x.com/grok

@coderabbitai

coderabbitai Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

The requested changes were prepared, but the pull request could not be created.

Warning

I couldn't create the pull request branch. This branch's GitHub Actions workflow files (.github/workflows/) have diverged from master, and GitHub blocks CodeRabbit from creating a branch that carries them.

How to fix: update this branch with master (merge or rebase), then re-run this command and I'll open the pull request. If updating causes merge conflicts, comment @coderabbitai resolve merge conflict and I'll resolve them first.

If this branch is already up to date with master, CodeRabbit may be missing repository write access — ask a repository admin to refresh its permissions.

@github-actions

Copy link
Copy Markdown
Contributor

@jules Auto-resolve (heyVern lane / GHA agent-review-auto-jules) — do not wait for a human ping.
Bot feedback from coderabbitai[bot] on PR #212 (branch hotfix/deepseek-ci-review-comment).

Feedback excerpt

<!-- This is an auto-generated reply by CodeRabbit -->
The requested changes were prepared, but the pull request could not be created.

> [!WARNING]
> I couldn't create the pull request branch. This branch's GitHub Actions workflow files (`.github/workflows/`) have diverged from `master`, and GitHub blocks CodeRabbit from creating a branch that carries them.
>
> **How to fix:** update this branch with `master` (merge or rebase), then re-run this command and I'll open the pull request. If updating causes merge conflicts, comment `@coderabbitai resolve merge conflict` and I'll resolve them first.
>
> If this branch is already up to date with `master`, CodeRabbit may be missing repository write access — ask a repository admin to refresh its permissions.

Instructions

  1. Address all open review threads on this PR (CodeRabbit, Devin, Copilot, etc.).
  2. Prefer minimal diffs; preserve Sentinel 0o600/0o700 if those files are touched.
  3. Push commits to branch hotfix/deepseek-ci-review-comment. Do not retarget away from the PR base without cause.
  4. If conflicts with base exist, resolve them.
  5. Skip pure nits only if they conflict with security/gates; otherwise apply autofixes.
    Monikers: docs/ops/AGENT-MONIKERS.md
    Agent: Grok (archW1z) orchestration · Profile: https://x.com/grok

Copy link
Copy Markdown
Owner Author

OPERATOR eval — CodeRabbit permissions / workflow blockers (comment)

What the comment means

Two independent GitHub platform constraints hit CodeRabbit:

Constraint Effect
Workflow write block Apps cannot push to .github/workflows/ on a branch whose workflow files diverge from the default branch (or without the workflows scope). CodeRabbit applied ci_agent.py (325a1f0) but could not push the concurrency-key change.
Stacked-PR branch create Same rule: CodeRabbit could not open a follow-up branch that carries modified workflows → “couldn't create the pull request branch”.

This is not a CodeRabbit bug. Refreshing “repository write access” alone does not grant workflow-file write unless the GitHub App is explicitly allowed to modify Actions workflows (rare for review bots by design).

What already landed on this branch

  • pull_request_review_comment trigger + mention/bot filter
  • pip upgrade + requests verify
  • ci_agent path for review comments (posts via gh pr comment — functional, not yet threaded in_reply_to)

What OPERATOR just applied

  • Concurrency group now includes github.event.comment.id (the change CodeRabbit could not push)

Optional follow-ups (not blockers for merge)

  1. Threaded replies — POST .../pulls/{n}/comments with in_reply_to=<comment.id> + action == "created" gate (CodeRabbit plan). Nice UX; current general PR comment still works.
  2. AGENTS.md — document pull_request_review_comment: created under DeepSeek CI triggers.
  3. pytest — tests/test_ci_agent.py for the new path.
  4. CodeRabbit permissions — leave as-is for workflows; OPERATOR/humans own .github/workflows/**. No need to escalate bot scopes for this PR.

Merge posture

Functional gap that caused the original “no-op on review comments” is closed. Remaining items are polish. Vercel free-tier rate limit is unrelated noise.

@github-actions

Copy link
Copy Markdown
Contributor

head_sha: b847429
ready: true
autofix_requested: false
timed_out: false

Peer review gate (ready for second-pass agents)

External reviewers polled: CodeRabbit, Devin, Aikido, Sentry, Copilot.
Autofix (if any) was requested in a separate comment on this SHA.

Peer activity (truncated):

comment @coderabbitai[bot]: <!-- This is an auto-generated reply by CodeRabbit --> The requested changes were prepared, but the pull request could n

Downstream: gemini-after-peers. Jules: agent-review-auto-jules.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 new potential issues.

Open in Devin Review

Comment thread deepcli/ci_agent.py
Comment on lines +396 to +412
messages = [
{
"role": "system",
"content": (
"You are deepCore (DeepSeek CI agent) in Expert mode with thinking enabled. "
"Reply helpfully and concisely to the user's request on this GitHub pull request review. "
"Do not invent secrets, tokens, or private data. Keep the reply under ~1500 chars."
),
},
{
"role": "user",
"content": (
f"PR #{pr_number}: {pr_title}\n\n"
f"User request in review comment:\n{prompt}"
),
},
]

@devin-ai-integration devin-ai-integration Bot Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Review-comment handler ignores the inline diff context

The prompt built for review comments only includes the PR number, PR title and the comment text (deepcli/ci_agent.py:396-412). pull_request_review_comment payloads carry comment.path, comment.line and comment.diff_hunk, which are exactly the context a reviewer expects the agent to reason about. Without them the model answers inline code questions blind. Also note the ~90 lines are inlined into run_ci rather than factored into a _handle_review_comment helper mirroring _handle_issue_comment (deepcli/ci_agent.py:249), duplicating the prompt/post/error-result structure.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +103 to +106
run: |
python -m pip install --upgrade pip
pip install requests pyyaml
python -c "import requests; print('requests', requests.__version__)"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: New pip step relies on default shell -e rather than the explicit pipefail pattern used elsewhere

Other multi-line run blocks in this workflow start with set -euo pipefail (e.g. .github/workflows/deepseek-ci.yml:110). The new block omits it; GitHub's default bash -e {0} still aborts on a failing command, so the verification line does gate the step, but the inconsistency is worth normalizing. The python -c "import requests; ..." check only proves the import works on the runner, which is unrelated to the reported CI failure mode (DeepSeek auth/soft-skip), so it is diagnostics rather than a fix.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@github-actions

Copy link
Copy Markdown
Contributor

🔀 OpenRouter review (cohere/north-mini-code:free)

Secondary review summary (focus on gaps peers may have missed)

1. Security permissions & secrets

  • ci_agent.py – verify the file is not world‑readable (ideally chmod 0o600 if it contains any tokens or chat‑session data). The new review‑comment block uses gh_env (presumably GITHUB_TOKEN) – ensure no accidental leak in logs or prints.
  • deepseek‑ci.yml – confirm the workflow uses GITHUB_TOKEN only via secrets: none and that any new step that writes outputs (e.g., the Stage DeepSeek PoW WASM & solver step) does not expose tokens in artifact names or debug logs.

2. Artifact classification (Class 3/4)

  • The workflow creates “DeepSeek PoW WASM & solver” artifacts. Check that the upload-artifact step (if present) is tagged with retention-days and if-no-files-found appropriate for classified data. If the artifacts contain proprietary or sensitive data, they should be marked class: 4 (or 3 depending on policy). Ensure the upload-artifact action uses the --class flag or the repo’s artifact‑classification labeler.

3. AGENTS.md update

  • AGENTS.md should reflect the expanded trigger list for the DeepSeek CI agent. Add an entry (or update the existing deepseek‑ci/deepCore description) noting it now also watches pull_request_review_comment events and will reply to mentions. This keeps the agent catalogue accurate for downstream automation.

Residual risks before merge

  • Replay / webhook‑abuse – the new handler strips trigger mentions before feeding to the model; double‑check that the regex (_TRIGGER_RE) captures all mention forms (e.g., @deepcore, @deepseek).
  • Rate‑limit handling – the existing is_soft_skippable_error is used for API errors but not for GitHub API POST failures in the review‑comment path; ensure the error path respects the same soft‑skip logic.
  • Permissions propagation – after merging, run git diff --check and git ls-files -m to ensure no stray .pyc/.env files slipped in.

Suggested immediate actions

  1. chmod 0o600 deepcli/ci_agent.py (if not already) and verify no debug prints of tokens.
  2. Add/update the pull_request_review_comment capability in AGENTS.md.
  3. Verify artifact‑upload step in deepseek‑ci.yml includes the proper classification label (or open a follow‑up issue to enforce repo‑wide artifact classification).

If these points are addressed, the PR should be ready for merge.


Peer router: Omni ↔ OpenRouter by desired model; Gemini residual. role=review

@timerloggedout-spec
timerloggedout-spec merged commit 6ab42cc into master Aug 14, 2026
4 of 7 checks passed

Copy link
Copy Markdown
Owner Author

OPERATOR — CodeRabbit "full workflow scope" reality check

Cannot grant what the app does not request.

Claim Fact
"Some agent removed workflow permissions for bots" CodeRabbit’s published GitHub App permissions list Actions: Read-only and do not include Workflows R/W (docs).
"Give @coderabbitai FULL SCOPE" Repo admin cannot inject workflows: write into a third-party app. Only CodeRabbit can update their app manifest → then you Accept new permissions.
What actually blocks .github/workflows/ pushes GitHub platform rule: App tokens need the Workflows permission category. CodeRabbit never asked for it.

What YOU can still do (human, 30s)

  1. https://github.com/settings/installations → CodeRabbit → Configure → Accept any pending permission updates
  2. Settings → Actions → General → Workflow permissions → Read and write (for GITHUB_TOKEN in Actions jobs — different from app scope)
  3. If you need bot-driven workflow edits: use OPERATOR PAT (already has full scope) or a custom GitHub App you own with Workflows R/W

DeepSeek path (done by OPERATOR, not CodeRabbit)

  • Threaded in_reply_to review replies + action==created gate → landed
  • Concurrency comment.id → landed
  • Merging this PR to master now so DeepSeek CI is live with review-comment support

Bottom line: CodeRabbit stays a reviewer/autofixer for non-workflow files. Workflow files = OPERATOR. That’s the correct security model, not a regression.

@coderabbitai

coderabbitai Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

@timerloggedout-spec, thanks for the detailed clarification.

The workflow write block is a GitHub App permission limitation. It is separate from repository access and GitHub Actions GITHUB_TOKEN settings.

For this repository, workflow changes should remain with the OPERATOR or another credential that has GitHub Workflows write permission. CodeRabbit can continue to review and autofix non-workflow files.

The DeepSeek review-comment path and concurrency update are now covered by the operator changes.

🐇


✏️ Learnings added
Learnt from: timerloggedout-spec
URL: https://github.com/timerloggedout-spec/termux-monorepo/pull/212

Timestamp: 2026-08-14T15:19:25.954Z
Learning: In `timerloggedout-spec/termux-monorepo`, CodeRabbit's GitHub App does not request GitHub Workflows write permission. Repository administrators cannot grant an undeclared GitHub App permission. CodeRabbit cannot commit changes under `.github/workflows/`; workflow changes must be applied by the OPERATOR PAT or a custom GitHub App that has GitHub Workflows write permission. This permission is separate from the GitHub Actions `GITHUB_TOKEN` workflow-permission setting.

Note: Learnings are effective only in the context of similar code segments. To apply general coding guidelines, please configure review instructions. You can manage existing learnings in the app.


🧠 Learnings used
Learnt from: timerloggedout-spec
Repo: timerloggedout-spec/termux-monorepo PR: 0
File: :0-0
Timestamp: 2026-08-08T19:37:41.450Z
Learning: In this repository, a `github-actions[bot]` comment that invokes `coderabbitai autofix` does not have sufficient authority for CodeRabbit to commit changes. The peer-review orchestrator should prefer `secrets.OPERATOR_GITHUB_TOKEN`, supplied by a repository owner or collaborator and granted Contents, Pull requests, and Issues read/write permissions. It may fall back to `GITHUB_TOKEN` only with a warning that Autofix can be rejected.

You are interacting with an AI system.

@github-actions

Copy link
Copy Markdown
Contributor

head_sha: a39c317
ready: true
autofix_requested: false
timed_out: false

Peer review gate (ready for second-pass agents)

External reviewers polled: CodeRabbit, Devin, Aikido, Sentry, Copilot.
Autofix (if any) was requested in a separate comment on this SHA.

Peer activity (truncated):

comment @coderabbitai[bot]: <!-- This is an auto-generated reply by CodeRabbit --> > [!TIP] > For best results, initiate chat on the files or code c

Downstream: gemini-after-peers. Jules: agent-review-auto-jules.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 3 new potential issues.

Open in Devin Review

Comment thread deepcli/ci_agent.py
Comment on lines +255 to +265
cmd = [
"gh",
"api",
"--method",
"POST",
f"repos/{repo}/pulls/{pr_number}/comments",
"-f",
f"body={body[:2000]}",
"-F",
f"in_reply_to={comment_id}",
]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Threaded reply API usage verified

gh api POST repos/{repo}/pulls/{n}/comments with in_reply_to is a supported way to create a reply in an existing review thread (all other body params are ignored when in_reply_to is set), and -F sends the id as a number as the API expects. pull-requests: write in the job permissions covers this write, so the call itself should work.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread deepcli/ci_agent.py
# --- pull_request_review_comment path ---
# Review comments have comment + pull_request but no issue key.
# Handle them as threaded replies within the review thread.
if event.get("comment") and event.get("pull_request") and not event.get("issue"):

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Event routing relies on payload key presence rather than an explicit event name

Routing distinguishes review comments from issue comments by comment && pull_request && not issue. This holds for real GitHub payloads, but workflow_dispatch accepts an arbitrary event_payload JSON (.github/workflows/deepseek-ci.yml:18-21), so a hand-crafted payload containing both comment and pull_request would take the review-reply path and attempt an in_reply_to post with an arbitrary comment id. Using GITHUB_EVENT_NAME (or a passed-in event name) would make routing unambiguous.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +16 to +17
pull_request_review_comment:
types: [created]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟨 Untrusted inline review comment text drives an authenticated agent that posts back with an elevated PAT

The new pull_request_review_comment trigger lets any user able to comment on a PR feed arbitrary text into the model prompt (deepcli/ci_agent.py:427-451), and the resulting model output is posted back to the repository using the operator PAT (.github/workflows/deepseek-ci.yml:57-58). Only a bot-type and mention-substring filter gates execution (.github/workflows/deepseek-ci.yml:38-51); there is no association/permission check (e.g. author_association OWNER/MEMBER/COLLABORATOR) as done for other automation. Because the workflow runs in the base-repo context with pull-requests: write and issues: write and a long-lived PAT, an outside contributor's comment can drive prompt-controlled content into repository comments and consume the privileged token's quota.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

This branch was successfully deployed

1 active deployment
Preview — a39c3174 Deployed Aug 14, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant