Repository navigation
fix(claude-review): post no review-count comment when the cap is disabled - #621
Conversation
…bled With max-reviews-per-pr <= 0 the lane now skips the count lookup and never creates or updates the "Claude has reviewed this PR N times" comment. A positive cap keeps the comment and its gate unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 2m 2s —— View job Claude code review
No high-signal findings. Traced the fix end-to-end and it holds up:
One note, not a finding: the I was not able to independently execute |
|
Claude finished @kyle-sexton's task in 1m 45s —— View job Security review
Scope: this PR only changes the review-count cap logic in two Findings: none.
No security-relevant issues identified in this change. |
|
Last security-reviewed head: |
|
Claude has reviewed this PR 2 times. The lane skips further automatic reviews after 5; deleting this comment resets the count. |
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 2m 5s —— View job Claude code review
No high-signal findings. The only change since the last review (
I was not able to execute |
No related issue: ships ci-workflows v0.28.1 (no review-count comment when the cap is disabled) to the synced lane callers. ## Summary ci-workflows v0.28.1 stops the code-review lane from reading or posting its "Claude has reviewed this PR N times" comment when `max-reviews-per-pr` is 0 or less. The `claude-lanes` caller component sets 0, so moving its pins to v0.28.1 removes that comment from dotfiles, github-iac, medley and provisioning. ## Fix - `components/claude-lanes/claude-review.yml` and `claude-security-review.yml` pin `cc0462990687534e9597de9e00ab89d3dcca61d2 # v0.28.1`. - `components/runner-policy/policy.json`: contracts for both lanes at `cc046299…`, verbatim copies of the v0.28.0 (`39390344…`) entries. - `components/runner-policy/README.md`: rollout record. `git diff 39390344..cc046299 -- .github/workflows/` touches only `claude-review.yml` (ci-workflows#621); no input, secret, permission or routing moved. The repin lane (#615) declined to copy forward because the `max-reviews-per-pr` description text changed. ## Verification - `npm run test:runner-policy`: 257 pass, 0 fail. `npm run lint:runner-policy`: passed. - `harness/shell/run-tests.sh` over `claude-lanes.test.sh` and `repin-callers.test.sh`: 2 passed. ## Related - melodic-software/ci-workflows#621, release v0.28.1. - #615 (repin lane PR; its remaining delta after this merges is `sync.yml`, `managed-files-guard` and this repo's own caller). 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ure visibility (#622) No related issue: operator-approved removal of lane bookkeeping. ## Summary Slims `claude-review.yml` (1,462 to 241 lines) and `claude-security-review.yml` (1,749 to 228 lines) to three purposes: running the review (plugin command, `pull_request` triggers, draft skip), security (fork skip, bot skip, privileged-trigger tripwire, least-privilege permissions, one named secret, credential strip, `display_report: false`, `exclude-comments-by-actor`), and failure visibility (`claude-lane-outcome` classification and an always-on status job per lane). ## Fix Removed from both lanes: - **Dispatch re-review:** `pr-number` input, "Resolve PR context", dispatch delivery snapshot/collect, and the `workflow_dispatch` triggers in both self callers. Steps read `github.event.pull_request.*` directly. - **Retry:** the retry gate, back-off, retry attempt, "Resolve the effective review attempt", and `retry-delay-seconds`. One attempt with `continue-on-error` and a step timeout; job timeouts sized for one attempt (15 and 25 minutes). - **Freshness:** the `claude-lane-freshness` step, every `superseded` gate, and the job-level per-head concurrency blocks. Callers own concurrency. - **Kill-switches:** `CLAUDE_LANES_DISABLED`, `CLAUDE_REVIEW_DISABLED`, `CLAUDE_SECURITY_REVIEW_DISABLED`. - **Marker comments:** both infra-status post/clear steps. - **Inputs:** `prompt` (the plugin command text is now inline in `prompt:`), `skip-actors` (replaced by `!endsWith(github.actor, '[bot]')`), and `status-check` (status jobs run on `always()`). Removed from the code-review lane: - **Review-count cap:** `max-reviews-per-pr`, the count check, and the count comment upsert. - **Standards mount:** `standards-ref`, the `STANDARDS_REVIEW_APP_*` secrets, the token/clear/checkout steps, and the `--add-dir` branch. - **Inputs:** `track-progress` (hardcoded true), `display-report` (hardcoded false), `timeout-minutes`, and `allowed-bots`. The #443 author-association clause is unreachable once every bot actor skips, so it is gone and `allowed_bots` is no longer passed. - **Outputs:** `review-ran`. Removed from the security lane: - **Path gating:** `paths`, `paths-file`, the `changes` job with its incremental last-reviewed-head listing (#259), and "Persist the last-reviewed head". The lane runs on every non-draft PR. - **Ruling:** "Rule on an in-scope non-run". - **Outputs:** `relevant`, `review-ran`, `review-failed`, `failure-class`. Shared composites: deleted `claude-lane-freshness` and `claude-lane-marker-comment`. `claude-lane-outcome` drops `dispatch-evidence.cjs`, the `event-name`/`delivery-evidence` inputs, and the `no-delivery` class. The lanes keep their `claude-lane-outcome@ac06265` (v0.27.0) pin. Tests and docs: deleted the tests of removed features; pruned compose-args, status-check, plugin-path, declared-outputs, outcome-wiring and outcome-step; renamed `claude-lane-bot-association.test.cjs` to `claude-lane-job-gates.test.cjs`, which now pins the bot, draft and fork skips and the tripwire for both lanes. Rewrote the README lane sections and deleted `security-review-absent-mitigation.md`. Beyond the brief: - The code-review lane now skips fork PRs like the security lane. With the status check always on, a secretless fork run would otherwise redden `claude-review-status` on every fork PR. - `cursor[bot]` pushes are no longer reviewed. It was in `allowed_bots` on both lanes and passed the #443 clause when the PR author was OWNER, MEMBER or COLLABORATOR; the blanket bot skip now skips it. ## Verification - `node --test .github/scripts/*.test.cjs`: 157 tests, 157 pass, 0 fail. - `node --test .github/actions/claude-lane-outcome/*.test.cjs`: 15 tests, 15 pass, 0 fail. - `actionlint`: clean. - `npx -y @biomejs/biome@2.5.11 check --config-path=fixtures/typescript/good/biome.json` on the 7 changed `.cjs` files: clean. - `npx markdownlint-cli2 README.md`: 0 issues. `typos` on the changed files: clean. `lychee --offline README.md`: 0 errors. - The pinned-revision check in `claude-review-outcome-wiring.test.cjs` ran against `ac06265` (not skipped) and passes: both consumed outputs, `review-failed` and `failure-class`, are declared at that pin. ## Related - #280 - #619 - #621 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eview-lane guards (#4465) No related issue: operator-approved removal of review-lane bookkeeping. ## Summary Removes the repo-owned bookkeeping around the two Claude review lanes and the local skill-evidence system from #4210. Each lane is now its caller plus the reusable's `status-check`. The lanes are not re-pinned and `.github/standards/**` is untouched; a later PR does both. ## Fix **Lane callers (CI)** - `claude-review.yml`: removed the `review-skill-evidence` job and its header paragraph. The reusable call's inputs and the `workflow_dispatch` trigger are unchanged. - `claude-security-review.yml`: removed the `skip-actors` and `security-review-evidence` jobs. `skip-actors` is now the inline literal `dependabot[bot],claude[bot],melodic-ai[bot],melodic-standards-sync[bot],cursor[bot]`. - `ci.yml` ci-status: removed the `skill_evidence_checkout` and `skill_evidence` steps, plus their lane-coverage opt-outs. - Deleted `.github/claude-skip-actors`, `scripts/read-skip-actors.sh`, `verify-claude-review-skill.sh`, `verify-security-review-evidence.sh`, `pr-skill-evidence-ci.sh`, their tests, and `scripts/lib/review-lane-guard.sh`. **Skill-evidence system (source-control 0.58.0, breaking)** - Deleted `scripts/skill-evidence.sh` and its suite, and the `pr-ready-evidence-{gate,mcp-gate,verdict}` hooks with their registrations and tests. - Removed the `pr_ready_evidence_gate_enabled` and `skill_evidence_store` options. - Removed the `pr_skill_evidence` key: its grammar in `config-resolution.md`, the setup report row, and the map in `.claude/source-control.md`. - pull-request `ready` now merges the base, runs the security review over the PR diff and the verify gate on the merged head, then flips. It no longer checks or renders evidence. Prep classifies changed files by a table instead of the map. Create no longer writes `branch.<name>.pr-number`. - babysit: removed the PR-body parser, the `skillEvidence` record, the `skill_evidence_gap` worker reason, and their tests. **claude-ops 0.61.0** - `skill-usage.jsonl` rows no longer carry `sha` or `pr`. Their only reader was `skill-evidence.sh`; `audit_skill_visibility.py`, `skill-pair-cooccurrence.sh` and the observability pruner never read them. A store write now spawns 3 git processes instead of 4 (measured with strace). **`.github/claude-security-paths`**: deleted. Its only readers were the map's `security` class and the ci.yml reporter; the security lane stopped reading it under the ADR 0038 addendum. **Records**: dated addenda in ADR 0002 (skip-actors), ADR 0037 (evidence system removed), and ADR 0038 (lanes are the callers plus status-check). Also updated AGENTS.md and both READMEs. ## Verification - `actionlint` and `zizmor --offline` on the three changed workflows: clean. - `scripts/check-lane-coverage.sh --check`: 5 lanes reachable, 60 gate steps fed, 2 opted out. - `scripts/check-changelog-parity.sh --check`, `--check-bump origin/main`, `--check-preserved origin/main`: pass. - `scripts/check-hook-userconfig-argv.sh` and `scripts/check-purged-em-dashes.sh`: pass. - `scripts/check-changed-skills.sh origin/main`: 4 skills checked, 0 failed. - `markdownlint-cli2` on the 22 changed markdown files: 0 issues. `shellcheck` on the changed shell files: clean. - babysit `python3 -m unittest discover`: 703 tests OK. `scripts/run-ruff.sh check` and `format --check` on the 9 changed Python files: clean. - `pr-linkage-spawn-budget.test.sh`: 23 passed. `skill-usage-audit.test.sh`: 31 passed. `claude-ops-paths.test.sh`: 37 passed. - `scripts/affected-tests.sh --run --jobs 16` (306 suites): 9 failed. Re-run on a clean `origin/main` worktree, 8 of them fail there too (markdown-format, the three worktree-create/containment suites, check-html-assets, work-item-tracker, check-script-contract, code-metrics dispatch). The ninth, `lib/hook-utils.test.sh`, passed 524/524 on its own re-run on this branch. ## Related - #4210 (introduced the skill-evidence system) - ADR 0037, ADR 0038, ADR 0002 - melodic-software/ci-workflows#621 (review-count comment dropped when the cap is disabled) 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
No related issue: operator request to drop the review-count status comment every fleet caller disables.
Summary
Every caller in the fleet sets
max-reviews-per-pr: 0, yet the lane still looked up and upserted the "Claude has reviewed this PR N times" comment after every review. With the cap disabled the comment carries a count nothing reads.Fix
Check the per-PR review countreturns before the comment lookup when the cap is<= 0.Update the review-count status commentreturns before any write when the cap is<= 0; its body now always states the cap, since it only runs with one.The security lane posts no count comment; its
last-reviewed headmarker is functional (incremental relevance) and is untouched.Verification
claude-review-outcome-wiring.test.cjsexecute both step scripts against a recording client: cap0makes no API call (no read, no create/update); cap5still lists comments and creates one.node --test .github/scripts/*.test.cjs: 264 pass, 0 fail.actionlintclean.Related
🤖 Generated with Claude Code