Skip to content

fix: re-pin agent_ref inputs to v-form (missed by #657 uses:-only re-pin) - #1206

Merged
don-petry merged 3 commits into
mainfrom
chore/agent-ref-vform-20260714
Jul 14, 2026
Merged

don-petry merged 3 commits into
mainfrom
chore/agent-ref-vform-20260714

Conversation

@don-petry

Copy link
Copy Markdown
Collaborator

The #657 migration re-pinned uses: refs to @<agent>/v<M>-<tier> but MISSED the agent_ref: inputs (no @ prefix), which the reusable uses to checkout its tooling at that channel. Retiring the bare tags broke dev-lead (checkout of the deleted bare tag). This re-pins agent_ref to match. Unblocks safe bare-tag retirement. #657 / gap #704.

@don-petry
don-petry requested a review from a team as a code owner July 14, 2026 02:52
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@gemini-code-assist

Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@don-petry, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 52 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 817422a6-98cc-4b82-939b-2358ed5be940

📥 Commits

Reviewing files that changed from the base of the PR and between d83b3b1 and a446ffe.

📒 Files selected for processing (2)
  • .github/workflows/add-to-project.yml
  • .github/workflows/dev-lead.yml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/agent-ref-vform-20260714

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@don-petry
don-petry enabled auto-merge (squash) July 14, 2026 02:54
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — review-changes (applied)

Changes committed and pushed.

@sonarqubecloud

Copy link
Copy Markdown

@don-petry
don-petry disabled auto-merge July 14, 2026 03:00
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
- Quality gate passed: no actionable issues found
Files changed: None
Skipped (informational): 0
```
The PR is clean — the bot comment is informational only, confirming that the code quality gate has passed. No fixes are needed.

@don-petry
don-petry enabled auto-merge (squash) July 14, 2026 03:00
@donpetry-bot

Copy link
Copy Markdown
Contributor

Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-07-14T04:01:30Z.

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: MEDIUM
Reviewed commit: a446ffe1003ca06592084923cbc7497f83259bfc
Review mode: triage-approved (single reviewer)

Summary

Two-line workflow-config fix: re-pins the agent_ref: inputs in the add-to-project.yml and dev-lead.yml caller stubs from bare channel tags (add-to-project/stable, dev-lead/next) to the versioned v-form (add-to-project/v1-stable, dev-lead/v1-next), matching the uses: refs already migrated by #657. This closes the gap where the reusable checked out its tooling at a bare tag slated for retirement (retiring the bare tags had broken dev-lead checkout). Verified via the GitHub API: both target tags exist (add-to-project/v1-stable in petry-projects/.github, dev-lead/v1-next in this repo), and each agent_ref now exactly matches its caller's uses: ref. Triage assessment (low-risk) confirmed.

Linked issue analysis

No closing issue references; the PR is a follow-up gap fix for the #657 migration (uses:-only re-pin missed the agent_ref: inputs). The change substantively addresses the described gap for both callers whose v-form tags exist. Note for the bare-tag retirement work: pr-review-trigger.yml still (consistently) uses bare pr-review/next for both uses: and agent_ref: — no pr-review/v1-* channel tags exist yet, so it is correctly out of this PR's scope, but pr-review/* bare tags must be excluded from retirement until that agent is migrated.

Findings

No blocking findings.

  • Mutable channel tags are the documented first-party exception in AGENTS.md ("Release channel tags & the mutable-ref exception"); modifying the agent_ref input on these thin caller stubs is within allowed changes.
  • Secret scan: run_secret_scanning MCP tool not available in this run; gitleaks CI check passed and the diff contains only first-party tag refs — no secret-bearing content.
  • Advisory bots: SonarCloud submitted (quality gate passed, 0 issues); Gemini cannot review these file types; Codex and CodeRabbit were rate-limited/out of quota. Per the post-#657 advisory-gate policy, rate-limited bots are non-participating and do not withhold approval; a rate-limited marker posted at 2026-07-14T03:01:31Z by a gate-deferred run is superseded by this review.
  • Non-blocking observation: pr-review-trigger.yml remains on bare pr-review/next tags (see issue analysis).

CI status

All substantive checks green at a446ffe1003ca06592084923cbc7497f83259bfc: CodeQL (actions, python), Secret scan (gitleaks), Agent Security Scan, AgentShield, SonarCloud quality gate, Lint/ShellCheck/bats, unit-tests, full dev-lead test suite (stub-structure, permissions, fixtures), holdout-guard, template-drift, gh-aw-compile, validate-personas/agent-profiles. CANCELLED: dev-lead / dispatch and dev-lead / ci-relay — intentional, head commit is a bot commit tagged [skip ci-relay]. PENDING: review / review (this review). SKIPPED: dependency-audit ecosystem jobs (no matching ecosystems) and dependabot-automerge (not a Dependabot PR).


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

@don-petry
don-petry merged commit f59cb73 into main Jul 14, 2026
37 of 40 checks passed
@don-petry
don-petry deleted the chore/agent-ref-vform-20260714 branch July 14, 2026 03:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants