Repository navigation
refactor(workflows): repoint the review lanes at the claude-lane composites (PR-A2) - #276
Conversation
…osites (PR-A2) Both reusable review lanes replace their embedded freshness, outcome, and marker-comment steps with the composite trio merged in PR-A1, pinned at its merge SHA b5d54bf (self-reference pins resolve only post-merge; a local ./ ref resolves against the caller's checkout in a reusable workflow). The four generated-embed classifier files retire with the embeds, along with their ci.yml test step and their selector-conformance.yml path triggers + test step. The security lane keeps #266's fail-closed contract through the repoint: the outcome composite records a failure without failing, so a new inline "Fail closed on an in-scope non-run" step owns the required-check red under the same pull_request-only carve-out. Its expanded marker body rides the composite's body-copy input as blockquote-continuation lines (input description updated to sanction multiline use). Tests move with the behavior: the superseded-guard suite pins the freshness composite reference instead of the inline github-script; the fail-closed suite drops the executed-bash classifier cases (owned by the composite's classify.test.cjs corpus) and pins the new wiring — resolve-attempt inputs, composite outputs, and the fail-closed step's exact condition. Phase 1 closes out in PLAN.md with merged-main sanity evidence, and the 2a-addendum records this execution shape. Known cosmetic delta until 2g: the composite annotation says "not a code-quality signal" on both lanes; the 2g copy rewrite aligns the security wording. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The four classify-infra-failure files were staged for the repoint commit but a stash round-trip during the zizmor baseline comparison silently unstaged the deletions. Without this, the render tripwire test still ships and fails against workflows whose embeds are gone. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 4m 2s —— View job PR Review
|
|
Claude finished @kyle-sexton's task in 2m 39s —— View job Security Review
No security issues found. The changes are a clean structural refactoring from inline steps to the pinned composite trio. All load-bearing security invariants are preserved. Detailed reasoning follows. Trust Boundary and Fail-Closed IntegrityThe most security-sensitive change is the migration of the fail-closed logic in
This is strictly more robust than the old approach. The old bash check treated an unset The The superseded-head path is correct: if Output Name Change (snake_case → kebab-case)The composite exposes Composite Pin SecurityBoth workflows reference the composites at the full 40-char SHA Tripwire PreservationBoth Fork Guard PreservationThe fork-scoped job Deleted Code SurfaceRemoving Prompt ConstructionThe
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b3b292bcbd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…retry, kill-switches, copy (PR-B, 2b-2i) (#280) Phase 2 feature set of the claude-review-lanes plan (`docs/topics/claude-review-lanes/PLAN.md`), delivered as PR-B on top of the merged composite extraction (PR-A1 #274) and repoint (PR-A2 #276). ## What's in here - **2b config currency**: claude-code-action pinned at v1.0.183; `claude-sonnet-5` defaults on all three lanes; inline-comment MCP tool allowed on both review lanes; `exclude_comments_by_actor` widened to both Dependabot spellings (upstream #1514) and lifted to an input on the security lane; skip-actors self-trigger ban; org-secret posture corrected (visibility: all); code-review default prompt names its lane and defers security scope to REVIEW.md's split. - **2c cadence**: code-review lane reviews on open/ready/reopen only (draft gate + no `synchronize`, dogfooded in the self-caller); `max-reviews-per-pr` (default 5) counted via a visible status comment that doubles as the human signal — fail-open, deletion resets. Security lane keeps `synchronize` (its check certifies execution at the merge head). - **2d retry**: gated, jittered single retry on all three lanes — retries only on a parsed execution file proving zero assistant turns AND a non-auth failure class; orphan tracking-comment cleanup between attempts; step-level attempt timeouts inside documented job budgets. Replaces the #266-era unconditional retry. - **2e**: per-lane caller concurrency shapes documented (review: per-PR cancel + repo-wide `queue: max`; security: `cancel-in-progress: false`, no queue — a cancelled required check is not a skip). - **2f kill-switches**: `CLAUDE_LANES_DISABLED` + per-lane variables on all three lanes; name-stable skip; repo overrides org; README + headers record the security-lane coverage-gap window. - **2g copy**: single-pass-correct marker copy (live via explicit body-copy; composite defaults follow at the Phase 3g re-pin); lane-aware annotation noun in the outcome composite. - **2h**: e2e lane gets the mechanical set only (pin, model, kill-switch, retry) — no marker/class adoption. - **2i dependabot**: daily; claude-code-action exempt from cooldown and grouped batching. - Post-review steps swap `always()` for `!cancelled()` across all lanes — cancellation is the concurrency group's retirement mechanism. ## Verification Two fresh-context verifier passes (2b/2i/2c and 2d-2g) — all checks PASS, overall SHIP; their findings (doc drift, count-gate hardening, tracking-comment authorship, retry evidence guard) are folded in as dedicated commits. 280 script tests + 10 composite tests green; actionlint clean; zizmor identical to baseline. ## Related - Closes #150 — `synchronize` dropped for the code-review lane; the security lane deliberately keeps it (QF1: a required execution check must report on the latest head; the paths gate makes non-relevant pushes skip in seconds). - Part of the claude-review-lanes effort (#228/#237/#238 observability workstream; #266 fail-closed posture preserved). Issue sweep for the remaining mapping happens in Phase 3f per the plan. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>

Summary
PR-A2 of the claude-review-lanes plan (
docs/topics/claude-review-lanes/PLAN.md, Phase 2a): both reusable review lanes replace their embedded freshness / outcome / marker-comment steps with the composite trio merged in PR-A1 (#274), pinned at its merge SHAb5d54bf7cb386b1f2c35426c6c5fb8d1686671bd. Local./refs cannot work from a reusable workflow (they resolve against the caller's checkout), so the references are full-SHA self-reference pins with# <short-sha> <date>comments.claude-review.yml+claude-security-review.yml: freshness, outcome, and both marker-comment steps become composite references; downstream gates move to the composites' kebab-case outputs (review-failed,failure-class,review-detail).classify-infra-failure.sh, its.test.sh,render-classify-infra-failure.cjs,classify-infra-failure-render.test.cjs), with theirci.ymltest step andselector-conformance.ymlpath triggers + test step.Fail closed on an in-scope non-runstep owns the required-check red under the same pull_request-only carve-out. Its expanded marker body ridesbody-copyas blockquote-continuation lines (input description updated — docs-only, behavior identical at the pinned SHA).classify.test.cjs's ported corpus) and pins the new wiring shape.Verified locally:
node --test .github/scripts/*.test.cjs(276 pass),node --test .github/actions/claude-lane-outcome/*.test.cjs, actionlint on all four touched workflows, zizmor findings identical to the pre-change baseline, markdownlint clean.No linked issue.
Related
🤖 Generated with Claude Code