Skip to content

feat: Phase 0 — install and initialize gh-aw in .github-private - #276

Merged
don-petry merged 41 commits into
mainfrom
dev-lead/issue-230-20260518-1642
May 20, 2026
Merged

don-petry merged 41 commits into
mainfrom
dev-lead/issue-230-20260518-1642

Conversation

@don-petry

Copy link
Copy Markdown
Collaborator

Summary

  • Adds gh-aw-compile job to lint.yml — installs the gh aw CLI extension, runs gh aw compile on any .github/workflows/*.md files, and skips gracefully when none exist (zero-workflow baseline)
  • Creates .github/agents/agentic-workflows.agent.md — the gh-aw dispatcher agent config, referencing Claude (CLAUDE_CODE_OAUTH_TOKEN) as the execution engine
  • Creates tests/aw/README.md — documents the three-level test methodology: compile validation (CI gate), staged smoke tests, and integration tests; includes scenario spec format and Definition of Done checklist
  • Creates tests/aw/issue-triage/ and tests/aw/ci-failure-analyst/ placeholder directories for the first two planned workflows

Closes #230

Test plan

  • gh-aw-compile CI job runs and exits 0 (skips compile since no *.md workflow files exist yet)
  • .github/agents/agentic-workflows.agent.md present with Claude engine reference
  • tests/aw/README.md covers scenario spec format, staged smoke tests, and DoD checklist
  • Placeholder directories exist: tests/aw/issue-triage/, tests/aw/ci-failure-analyst/

🤖 Generated with Claude Code

#230)

- Add gh-aw-compile job to lint.yml that installs the gh-aw extension and
  runs `gh aw compile`; skips gracefully if no .github/workflows/*.md exist
- Create .github/agents/agentic-workflows.agent.md dispatcher config
  referencing Claude (CLAUDE_CODE_OAUTH_TOKEN) as the execution engine
- Create tests/aw/README.md with scenario spec format, staged smoke test
  instructions, compile-gate CI docs, and Definition of Done checklist
- Create tests/aw/issue-triage/ and tests/aw/ci-failure-analyst/ placeholder
  directories for the first two planned workflows

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings May 18, 2026 16:45
@coderabbitai

coderabbitai Bot commented May 18, 2026 •

Copy link
Copy Markdown

Warning

Rate limit exceeded

@don-petry has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 22 minutes and 46 seconds before requesting another review.

You’ve run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: a5bd0bf1-4124-4e32-97b6-ea974fd05a11

📥 Commits

Reviewing files that changed from the base of the PR and between 6dcc2bc and 2ba36c7.

📒 Files selected for processing (6)
  • .github/workflows/lint.yml
  • AGENTS.md
  • agents/agentic-workflows.md
  • tests/aw/README.md
  • tests/aw/ci-failure-analyst/.gitkeep
  • tests/aw/issue-triage/.gitkeep
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev-lead/issue-230-20260518-1642

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — human-pr (no-changes)

No changes were needed for this PR.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-bot-comment (no-changes)

Engine ran but made no changes.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a dispatcher for agentic workflows and a comprehensive testing guide. The review feedback highlights several improvements: moving the agent profile to the root directory to comply with repository standards, ensuring the agent's name matches its filename, and enhancing the security of the installation script by adding a failure flag to the curl command.

Comment thread .github/agents/agentic-workflows.agent.md Outdated
Comment thread .github/agents/agentic-workflows.agent.md Outdated
Comment thread tests/aw/README.md Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Phase 0 scaffolding for the gh-aw (GitHub Agentic Workflows) rollout. Adds a CI compile-gate job, the dispatcher agent config, test methodology docs, and placeholder directories so subsequent phases can land individual workflows on a known-good baseline.

Changes:

  • New gh-aw-compile job in lint.yml that installs the gh aw extension and runs gh aw compile (gracefully skipped when no .github/workflows/*.md files exist).
  • New .github/agents/agentic-workflows.agent.md dispatcher config wired to Claude (CLAUDE_CODE_OAUTH_TOKEN).
  • New tests/aw/README.md documenting the three-level test methodology, scenario spec format, and Definition of Done, plus .gitkeep placeholders for the first two planned workflows.

Reviewed changes

Copilot reviewed 3 out of 5 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
.github/workflows/lint.yml Adds gh-aw-compile job: installs gh-aw and conditionally runs gh aw compile.
.github/agents/agentic-workflows.agent.md Dispatcher agent frontmatter + dispatch rules, referencing Claude as engine.
tests/aw/README.md Documents three-level test methodology, scenario spec format, DoD checklist.
tests/aw/issue-triage/.gitkeep Placeholder for upcoming issue-triage workflow tests.
tests/aw/ci-failure-analyst/.gitkeep Placeholder for upcoming ci-failure-analyst workflow tests.
Comments suppressed due to low confidence (2)

.github/workflows/lint.yml:53

  • gh aw compile is a gh CLI extension command and typically requires gh to be authenticated (GH_TOKEN / GITHUB_TOKEN env). This step sets no env: and the job has only the workflow-level permissions: contents: read token, which isn't exposed to gh automatically. If/when a .github/workflows/*.md file is added, this step may fail with an auth error. Consider passing GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} (or GITHUB_TOKEN) to the compile step so gh is authenticated when the branch starts shipping real *.md workflows.
      - name: Compile agentic workflows
        run: |
          if ls .github/workflows/*.md > /dev/null 2>&1; then
            gh aw compile
          else
            echo "No .github/workflows/*.md files found — skipping compile."
          fi

.github/workflows/lint.yml:53

  • The installer script writes the gh aw extension into gh's extension directory, but that requires gh itself to be on PATH and (depending on the installer) may also need gh extension install to be invoked. There's no verification step here (e.g. gh aw --version) before the compile step runs. If the install silently fails or installs to a path not on PATH, the skip-branch (else echo) will still hide it as long as no *.md files exist — meaning the CI gate looks green today but might be broken the moment the first workflow file lands. Adding a gh aw --version smoke check after install would surface install regressions immediately.
      - name: Install gh-aw
        run: curl -sL https://raw.githubusercontent.com/github/gh-aw/main/install-gh-aw.sh | bash

      - name: Compile agentic workflows
        run: |
          if ls .github/workflows/*.md > /dev/null 2>&1; then
            gh aw compile
          else
            echo "No .github/workflows/*.md files found — skipping compile."
          fi

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/workflows/lint.yml Outdated
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-bot-comment (no-changes)

Engine ran but made no changes.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-reviews (no-changes)

No changes were needed for the open review threads.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 845671758f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/lint.yml Outdated
Comment thread .github/agents/agentic-workflows.agent.md Outdated
Comment thread .github/workflows/lint.yml Outdated
Comment thread .github/workflows/lint.yml Outdated
Comment thread .github/workflows/lint.yml Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 788f6cd1f7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tests/aw/README.md Outdated
Comment thread .github/workflows/lint.yml
Comment thread .github/agents/agentic-workflows.agent.md Outdated
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — human-pr (no-changes)

No changes were needed for this PR.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8d5ac05942

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/agents/agentic-workflows.agent.md Outdated
@don-petry

Copy link
Copy Markdown
Collaborator Author

No description provided.

@don-petry

Copy link
Copy Markdown
Collaborator Author

No description provided.

don-petry added a commit that referenced this pull request May 19, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
@don-petry

Copy link
Copy Markdown
Collaborator Author

No description provided.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0472e86eed

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/agents/agentic-workflows.agent.md Outdated
Comment thread .github/agents/agentic-workflows.agent.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6d3902c8ad

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/agents/agentic-workflows.agent.md Outdated
@don-petry

Copy link
Copy Markdown
Collaborator Author

No description provided.

don-petry added a commit that referenced this pull request Jun 23, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 2, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 18, 2026
)

* fix(dev-lead): handle SonarQube failures — relay, hotspot context, external gate logs

Three bugs prevented the dev-lead agent from ever fixing a SonarQube
Quality Gate failure (observed on PR #276, tracked in issue #279):

1. ci-relay skipped GitHub App check_runs (SonarCloud, CodeQL, etc.)
   because check_run.pull_requests is empty for App-sourced checks.
   Fix: fall back to GET /commits/{sha}/pulls when pull_requests is [],
   including fork protection using head.repo.full_name from that API.

2. fix-bot-comment had no guidance for SonarQube comments that list
   hotspot counts with no file/line references, leaving the agent with
   nothing actionable. Fix: add a SonarQube-specific section instructing
   the agent to diff the PR and scan for known hotspot patterns
   (curl|bash, hardcoded secrets, eval, HTTP downloads).

3. collect_logs() returned a bare "No run logs available" for external
   quality gates (details_url with no /runs/ segment), giving the agent
   empty context. Fix: fall back to gh pr diff output so the agent can
   identify what the gate flagged. fix-ci.md also gains an "External
   quality gate" guidance section matching the new log header.

Tests: two new fix-ci bats tests covering the external quality gate
collect_logs path (non-GHA URL → pr diff; GHA URL → run view).
New fixture: check_run_failure_sonarcloud.json for ci-relay fallback.

Closes #279

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

* fix(dev-lead): address review feedback on PR #280

- Extract ci-relay PR-lookup logic into scripts/dev-lead-ci-relay.sh so
  it can be unit-tested with bats; YAML step now calls the script.
  Includes the open-PR filter (select(.state=="open")) to prevent
  relaying against merged PRs that share the same commit SHA (Copilot).

- Increase PR diff capture from LOG_MAX_LINES (200) to 1000 lines for
  the external quality gate fallback — diffs typically exceed 200 lines
  and hotspots may appear anywhere (Gemini).

- Replace ineffective test 17 with a prompt-file inspection: extract the
  rendered prompt path from dry-run output, then grep for the
  "External quality gate" header and diff content (Gemini/Copilot).

- Replace ineffective test 18 with sentinel files: the gh stub touches
  .ran_run_view or .ran_pr_diff; test asserts run view was called and
  pr diff was not (Gemini/Copilot).

- Add tests/dev-lead/unit/test_ci_relay.bats: 7 unit tests covering
  the new ci-relay script — GHA path, App fallback, fork rejection,
  no-PRs, merged-only PRs, and API failure (Copilot).

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Phase 0: Install and initialize gh-aw in .github-private

3 participants