fix: re-pin agent_ref inputs to v-form (missed by #657 uses:-only re-pin) - #1206
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
|
Warning Review limit reached
Next review available in: 52 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — review-changes (applied)Changes committed and pushed. |
|
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
|
Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-07-14T04:01:30Z. |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: MEDIUM
Reviewed commit: a446ffe1003ca06592084923cbc7497f83259bfc
Review mode: triage-approved (single reviewer)
Summary
Two-line workflow-config fix: re-pins the agent_ref: inputs in the add-to-project.yml and dev-lead.yml caller stubs from bare channel tags (add-to-project/stable, dev-lead/next) to the versioned v-form (add-to-project/v1-stable, dev-lead/v1-next), matching the uses: refs already migrated by #657. This closes the gap where the reusable checked out its tooling at a bare tag slated for retirement (retiring the bare tags had broken dev-lead checkout). Verified via the GitHub API: both target tags exist (add-to-project/v1-stable in petry-projects/.github, dev-lead/v1-next in this repo), and each agent_ref now exactly matches its caller's uses: ref. Triage assessment (low-risk) confirmed.
Linked issue analysis
No closing issue references; the PR is a follow-up gap fix for the #657 migration (uses:-only re-pin missed the agent_ref: inputs). The change substantively addresses the described gap for both callers whose v-form tags exist. Note for the bare-tag retirement work: pr-review-trigger.yml still (consistently) uses bare pr-review/next for both uses: and agent_ref: — no pr-review/v1-* channel tags exist yet, so it is correctly out of this PR's scope, but pr-review/* bare tags must be excluded from retirement until that agent is migrated.
Findings
No blocking findings.
- Mutable channel tags are the documented first-party exception in AGENTS.md ("Release channel tags & the mutable-ref exception"); modifying the
agent_refinput on these thin caller stubs is within allowed changes. - Secret scan:
run_secret_scanningMCP tool not available in this run; gitleaks CI check passed and the diff contains only first-party tag refs — no secret-bearing content. - Advisory bots: SonarCloud submitted (quality gate passed, 0 issues); Gemini cannot review these file types; Codex and CodeRabbit were rate-limited/out of quota. Per the post-#657 advisory-gate policy, rate-limited bots are non-participating and do not withhold approval; a rate-limited marker posted at 2026-07-14T03:01:31Z by a gate-deferred run is superseded by this review.
- Non-blocking observation:
pr-review-trigger.ymlremains on barepr-review/nexttags (see issue analysis).
CI status
All substantive checks green at a446ffe1003ca06592084923cbc7497f83259bfc: CodeQL (actions, python), Secret scan (gitleaks), Agent Security Scan, AgentShield, SonarCloud quality gate, Lint/ShellCheck/bats, unit-tests, full dev-lead test suite (stub-structure, permissions, fixtures), holdout-guard, template-drift, gh-aw-compile, validate-personas/agent-profiles. CANCELLED: dev-lead / dispatch and dev-lead / ci-relay — intentional, head commit is a bot commit tagged [skip ci-relay]. PENDING: review / review (this review). SKIPPED: dependency-audit ecosystem jobs (no matching ecosystems) and dependabot-automerge (not a Dependabot PR).
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.



The #657 migration re-pinned
uses:refs to@<agent>/v<M>-<tier>but MISSED theagent_ref:inputs (no@prefix), which the reusable uses to checkout its tooling at that channel. Retiring the bare tags broke dev-lead (checkout of the deleted bare tag). This re-pins agent_ref to match. Unblocks safe bare-tag retirement. #657 / gap #704.