Repository navigation
feat(copilot): add repo-level Copilot instruction files - #357
Conversation
Deploys .github/copilot-instructions.md customized for .github-private's CI infrastructure stack (GitHub Actions YAML, Bash scripts, gh-aw agentic workflows, org-wide agent profiles), plus the shell language instruction file. Part of the org-wide rollout from petry-projects/.github PR #328. Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
|
Warning Rate limit exceeded
You’ve run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThis PR adds two documentation files that establish development guidance for the ChangesCopilot Instructions and Development Standards
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~5 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — human-pr (no-changes)No changes were needed for this PR. |
Dev-Lead — fix-bot-comment (no-changes)Engine ran but made no changes. |
There was a problem hiding this comment.
Pull request overview
Adds repository-scoped GitHub Copilot instruction files intended to guide agents/contributors working in petry-projects/.github-private, with emphasis on CI/workflow infrastructure and shell scripting practices.
Changes:
- Adds
.github/copilot-instructions.mdwith repo-specific context, structure, and workflow guidance. - Adds
.github/instructions/shell.instructions.mdproviding shell scripting standards and safety/linting guidance.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 6 comments.
| File | Description |
|---|---|
| .github/instructions/shell.instructions.md | New shell-focused instruction file with safety, ShellCheck, quoting, error-handling, and testing guidance. |
| .github/copilot-instructions.md | New repo-level Copilot instructions describing stack, structure, local commands, env vars, and repo-specific workflow rules. |
Comments suppressed due to low confidence (1)
.github/copilot-instructions.md:48
- The “Lint agentic flows” command uses
gh-aw compile .github/aw/, but this repo’s CI uses the GitHub CLI extension invocationgh aw compile --no-emitand the source files live under.github/workflows/*.md(not.github/aw/, which only contains actions-lock.json). Update the command and path so contributors can reproduce the CI gate locally.
## Local Dev Commands
- Lint scripts: `shellcheck scripts/*.sh`
- Lint agentic flows: `gh-aw compile .github/aw/`
- No install or test commands (infrastructure-only)
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7c4e004b00
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…mple Markdownlint MD010 flags hard tabs in code blocks. The Makefile recipe lines used literal tab characters; replaced with spaces for display purposes in the Markdown file.
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: 39bf1f456c3d4a89422adafe6531f4dad6664c37
Review mode: triage-approved (single reviewer)
Summary
Docs-only PR adding two Copilot instruction files:
.github/copilot-instructions.md(76 lines) — repo-scoped guidance covering.github-private's CI infrastructure stack (Bash, GitHub Actions,gh-aw, ShellCheck), thedev-lead.ymlvsdev-lead-reusable.ymldistinction, theagent-shield.ymlexemption,frameworks/subtree management, and agent profile conventions..github/instructions/shell.instructions.md(139 lines) — shell scripting standards (set -euo pipefail, ShellCheck compliance, quoting, error handling, command-injection prevention, Makefile conventions).
No executable code, no workflow changes, no secrets, no migrations. Pure additive documentation. Triage tier already cleared this as low-risk; this confirmation review concurs.
Linked issue analysis
No linked issues. PR body references the org-wide rollout (petry-projects/.github PR #328) as the driving context, which is appropriate for an infrastructure doc deployment.
Findings
Nit (non-blocking) — doc accuracy: The "Local Dev Commands" section in .github/copilot-instructions.md:48 says:
Lint agentic flows: `gh-aw compile .github/aw/`
The Copilot reviewer flagged this and the codebase confirms: agentic workflow .md source files actually live in .github/workflows/ (e.g., ci-failure-analyst.md, issue-triage.md, release-notes.md, stale-manager.md), while .github/aw/ only contains actions-lock.json. The CI gate (Compile agentic workflows job in lint.yml) itself runs correctly — this discrepancy only affects contributors trying to reproduce the lint locally from this doc.
Non-blocking because (a) the doc is new and can be corrected in a follow-up, (b) the actual CI gate is unaffected, and (c) the rest of the file is accurate. A one-line fix in a future PR is fine.
No security concerns, no anti-patterns, no standards violations. The shell-instructions file correctly recommends set -euo pipefail, ShellCheck, proper quoting, and command-injection prevention — all aligned with org conventions.
CI status
All required checks passing:
- ✅ Lint, ShellCheck, Compile agentic workflows, Agent Security Scan, Secret scan (gitleaks)
- ✅ CodeQL (actions), agent-shield/AgentShield
- ✅ SonarCloud (Quality Gate passed, 0 new issues)
- ✅ Tests (unit-tests), PR Review Agent
- Dependency-audit ecosystems all SKIPPED (no language deps in this PR, expected)
- Dependabot auto-merge SKIPPED (not a Dependabot PR, expected)
Note: mergeStateStatus is BLOCKED pending review approval, which this review resolves.
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 39bf1f456c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
c4fe175
Dev-Lead — human-pr (applied)Changes committed and pushed. |
Dev-Lead — human-pr (no-changes)No changes were needed for this PR. |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: 2a8e74ac492943ba591818a29c691cc0af14c39c
Review mode: triage-approved (single reviewer)
Summary
Docs-only PR adding two Copilot instruction files:
.github/copilot-instructions.md(73 lines) — repo-scoped guidance for.github-private's CI infrastructure stack (Bash, GitHub Actions,gh aw, ShellCheck), thedev-lead.ymlvsdev-lead-reusable.ymldistinction, theagent-shield.ymlthin-caller-stub policy, and agent profile conventions..github/instructions/shell.instructions.md(139 lines) — shell scripting standards (set -euo pipefail, ShellCheck compliance, quoting, error handling, command-injection prevention, Makefile conventions).
No executable code, no workflow changes, no secrets, no migrations. Pure additive documentation. Triage tier cleared this as low-risk; this confirmation review concurs.
Changes since prior automated review (39bf1f4 → 2a8e74a)
The two new commits actually resolved the nit flagged in the prior automated review and tightened several other doc claims:
- ✅ Fixed
gh-aw compile .github/aw/→gh aw compile --no-emit(correct CLI invocation;.lock.ymlfiles live in.github/workflows/, not.github/aw/). Verified against.github/workflows/lint.yml. - ✅ Updated env vars:
GITHUB_TOKEN/ANTHROPIC_API_KEY→GH_TOKEN(fromGH_PAT_WORKFLOWS) /CLAUDE_CODE_OAUTH_TOKEN. Verified — 17 workflow files reference these secret names. - ✅ Rewrote the
agent-shield.ymloverride section from "Never modify" to a more accurate thin-caller-stub explanation enumerating the safewith:inputs. Verified against the actualagent-shield.ymlheader comment. - ✅ Added the real local test command (
bats tests/fleet_report.bats). Verified —tests/fleet_report.batsexists. - ✅ Removed the
frameworks/subtree section (the directory is no longer present in the tree shown). - ✅ Minor wording fix in
shell.instructions.mdsafety-flags intro.
No new issues introduced. All prior findings resolved.
Linked issue analysis
No linked issues. PR body references the org-wide rollout (petry-projects/.github PR #328) as the driving context — appropriate for an infrastructure doc deployment.
Findings
None blocking. The shell-instructions file correctly recommends set -euo pipefail, ShellCheck, proper quoting, command-injection prevention via arrays, and trap cleanup — all aligned with org conventions and the existing scripts in this repo.
One very minor pre-existing nit (not introduced by the new commits, fine to leave): the project-structure tree still lists aw/ with the comment "Agentic workflow definitions (compiled by gh-aw)", but .github/aw/ only contains actions-lock.json — the actual .md/.lock.yml sources live under .github/workflows/. The new "Linting" line is accurate; this tree comment is just stale. Optional follow-up cleanup.
CI status
All required checks passing on 2a8e74a:
- ✅ Lint, ShellCheck, Compile agentic workflows, Agent Security Scan, Secret scan (gitleaks)
- ✅ CodeQL (actions), agent-shield/AgentShield
- ✅ SonarCloud (Quality Gate passed, 0 new issues, 0 security hotspots)
- ✅ Tests (unit-tests), PR Review Agent, Dev-Lead Agent dispatch
- Dependency-audit ecosystems all SKIPPED (no language deps in this PR, expected)
- Dependabot auto-merge SKIPPED (not a Dependabot PR, expected)
mergeStateStatus is BLOCKED pending review approval, which this review resolves.
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c4fe1758b0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: 12a2e3df2a814a75ef60200e7948a472f51fccfd
Review mode: triage-approved (single reviewer)
Summary
Docs-only PR adding two Copilot instruction files:
.github/copilot-instructions.md(73 lines) — repo-scoped guidance for.github-private's CI infrastructure stack (Bash, GitHub Actions,gh aw, ShellCheck), thedev-lead.ymlvsdev-lead-reusable.ymldistinction, theagent-shield.ymlthin-caller-stub policy, and agent profile conventions..github/instructions/shell.instructions.md(139 lines) — shell scripting standards (set -euo pipefail, ShellCheck compliance, quoting, error handling, command-injection prevention via arrays,trapcleanup, Makefile conventions).
No executable code, no workflow changes, no secrets, no migrations. Pure additive documentation. Triage tier cleared this as low-risk; this confirmation review concurs.
Changes since prior automated review (2a8e74a → 12a2e3d)
The new head is a merge-from-main commit. gh api compare shows the only files touched between the prior approved SHA and the current head are scripts/dev-lead-fix-reviews.sh and tests/dev-lead/unit/test_fix_reviews.bats — both arrived via the unrelated PR #363 ("dev-lead: suppress visible body on no-changes terminal comments") merged to main. The two doc files added by this PR are unchanged since the prior approval. No conflicts, no new findings.
Linked issue analysis
No linked issues. PR body references the org-wide rollout (petry-projects/.github PR #328) as the driving context — appropriate for an infrastructure doc deployment.
Findings
None blocking. Prior cycle's nit (a stale aw/ comment in the project-structure tree) remains an optional follow-up; not introduced by these commits and not worth blocking a docs PR over.
CI status
All required checks passing on 12a2e3d:
- ✅ Lint, ShellCheck, Compile agentic workflows, Agent Security Scan, Secret scan (gitleaks)
- ✅ CodeQL (actions), agent-shield/AgentShield
- ✅ SonarCloud (Quality Gate passed, 0 new issues, 0 security hotspots)
- ✅ Tests (unit-tests), PR Review Agent, CodeRabbit
- Dependency-audit ecosystems all SKIPPED (no language deps in this PR, expected)
- Dependabot auto-merge SKIPPED (not a Dependabot PR, expected)
mergeStateStatus is BLOCKED pending review approval, which this review resolves.
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.
Superseded by automated re-review at 12a2e3d.
…ndards Makes the language instruction files discoverable directly from the copilot-instructions.md footer. Addresses CodeRabbit review feedback. Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Automated review — human attention neededThis PR has been through 3 automated review cycles (cap: 3) without converging on an approval-and-merge state. Further automated review has been paused to avoid infinite loops. Please take a look manually, or close this PR if it's no longer needed. Once a human review resolves the situation, remove the Posted by the donpetry-bot PR-review cascade. |
|
No description provided. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 662f3e16ae
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
|
No description provided. |
|
No description provided. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/copilot-instructions.md:
- Line 45: The glob pattern in the lint script command "shellcheck
--severity=warning -x scripts/**/*.sh" uses ** which requires bash globstar;
update the instructions to use a reliable recursive form: either change the
command to scan the directory ("shellcheck --severity=warning -x scripts/"),
replace with a find-based invocation (use find scripts -name \"*.sh\" -exec
shellcheck ...), or explicitly document enabling globstar (add "shopt -s
globstar" before the existing command); pick one and update the line accordingly
so recursive scanning works as intended.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 214fe253-6176-4443-b4f0-8cdde5ac6d7e
📒 Files selected for processing (2)
.github/copilot-instructions.md.github/instructions/shell.instructions.md
|
@coderabbitai resolve |
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
✅ Actions performedComments resolved and changes approved. |
|
|
No description provided. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2e5568cbd8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| - Lint scripts: `find scripts -name "*.sh" -exec shellcheck --severity=warning -x {} +` | ||
| - Lint agentic flows: `gh aw compile --no-emit` | ||
| - Run tests: `bats tests/fleet_report.bats` |
There was a problem hiding this comment.
Align local test command with CI-required suites
The Run tests command only runs bats tests/fleet_report.bats, but this repo’s required test workflows execute additional suites (.github/workflows/test.yml runs tests/test_copilot_chat.sh and tests/test_list_prs_sort.sh, and .github/workflows/test-dev-lead.yml runs multiple dev-lead checks). For changes outside fleet_report, following this instruction can give a false local pass and still fail CI; the local validation section should include or reference the full CI test surface.
Useful? React with 👍 / 👎.
| @@ -0,0 +1,139 @@ | |||
| --- | |||
| description: Shell script development standards for the Petry Projects organization | |||
| applyTo: "**/*.sh,**/*.bash" | |||
There was a problem hiding this comment.
Expand applyTo to include Makefiles
The instruction file includes a full Makefile Standards section, but applyTo only matches **/*.sh,**/*.bash, so these rules are never auto-applied when editing Makefile files. This silently drops intended guidance in the exact context where it is needed, leading to inconsistent Makefile changes despite documented standards.
Useful? React with 👍 / 👎.



Summary
.github/copilot-instructions.mdcustomized for .github-private's CI infrastructure stackshell.instructions.mdfrom the org canonical sourcedev-lead.ymlvsdev-lead-reusable.ymldistinction,gh-aw-compilelint gate,agent-shield.ymlexemption,frameworks/subtree management, agent profile conventionsStack discovered
GitHub Actions (YAML) · Bash ·
ghCLI ·gh-aw(agentic workflow compiler) · ShellCheck · markdownlint · BMad Method (git subtree) · Copilot agent profilesReferences
🤖 Generated with Claude Code
Summary by CodeRabbit