Skip to content

feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments - #366

Merged
don-petry merged 3 commits into
mainfrom
dev-lead/issue-365-20260523-0133
May 23, 2026
Merged

don-petry merged 3 commits into
mainfrom
dev-lead/issue-365-20260523-0133

Conversation

@don-petry

@don-petry don-petry commented May 23, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #365

Implemented by dev-lead agent. Please review.

Summary by CodeRabbit

  • Improvements
    • Session reasoning is now captured and displayed in "no changes" outcomes within a collapsible "Agent reasoning" section
    • Session output is preserved for enhanced visibility and debugging purposes

Review Change Stack

Copilot AI review requested due to automatic review settings May 23, 2026 01:40
@coderabbitai

coderabbitai Bot commented May 23, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@don-petry, we couldn't start this review because you've used your available PR reviews for now.

Your plan currently allows 1 review/hour. Refill in 37 minutes and 10 seconds.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more review capacity refills, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than trial, open-source, and free plans. In all cases, review capacity refills continuously over time.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: b2011582-5aa3-43b0-a5a2-7ea1eebda3df

📥 Commits

Reviewing files that changed from the base of the PR and between bad4e7f and 66faa2e.

📒 Files selected for processing (4)
  • scripts/dev-lead-fix-reviews.sh
  • scripts/engine.sh
  • tests/dev-lead/unit/test_engine_writer.bats
  • tests/dev-lead/unit/test_fix_reviews.bats
📝 Walkthrough

Walkthrough

This PR implements persistent session output capture and enriched no-changes comments. The engine now saves agent output to GitHub Actions logs and a temp file; dev-lead-fix-reviews reads this output and embeds it as a collapsible "Agent reasoning" block in no-changes PR comments across all intent handlers.

Changes

Session Output Persistence and No-Changes Enrichment

Layer / File(s) Summary
Session output persistence in engine.sh
scripts/engine.sh, tests/dev-lead/unit/test_engine_writer.bats
run_writer appends captured output to GITHUB_STEP_SUMMARY (when set), copies it to /tmp/dev-lead-session-output.txt, then deletes the temp file. Tests verify output is persisted on success, appended to step summary when configured, and omitted during rate-limits or dry-run mode.
No-changes comment enrichment with agent reasoning
scripts/dev-lead-fix-reviews.sh, tests/dev-lead/unit/test_fix_reviews.bats
read_session_summary() extracts agent output from the saved file; post_no_changes(intent) embeds it in a collapsible "Agent reasoning" details block. All five intent handlers (fix-reviews, fix-bot-comment, human, human-pr, rebase) replace direct terminal posting with post_no_changes. Tests validate the details block appears when session output exists and is omitted otherwise.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related issues

Possibly related PRs

  • petry-projects/.github-private#297: Also modifies scripts/dev-lead-fix-reviews.sh no-changes completion logic, including terminal comment posting and auto-merge integration.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately reflects the main changes: preserving session output in Actions logs and surfacing agent reasoning in no-changes comments, matching issue #365.
Linked Issues check ✅ Passed All coding requirements from issue #365 are met: session output appended to GITHUB_STEP_SUMMARY and copied to /tmp/dev-lead-session-output.txt [engine.sh], read_session_summary() added to extract structured output [dev-lead-fix-reviews.sh], post_no_changes() updated all no-changes call sites [fix-reviews, fix-bot-comment, human, human-pr, rebase], applied and rate-limited behaviors unchanged.
Out of Scope Changes check ✅ Passed All changes are directly scoped to issue #365 requirements: modifications to engine.sh and dev-lead-fix-reviews.sh implement session persistence and reasoning display, while test updates validate the new functionality without introducing unrelated changes.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev-lead/issue-365-20260523-0133

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — human-pr (no-changes)

Agent reasoning
The open review threads list is empty — there are no human reviewer threads to address on PR #366.

PR: #366 -
Human review threads addressed: 0
Files changed: none

@don-petry

Copy link
Copy Markdown
Collaborator Author

No description provided.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request implements a mechanism to capture and display agent session summaries when no code changes are applied. It updates the engine to persist session logs to a temporary file and the GitHub Step Summary, and modifies the review script to include these logs as 'Agent reasoning' in PR comments. Feedback suggests refining the regex used for summary extraction to handle whitespace-only lines and wrapping the GitHub Step Summary output in a collapsible block for better readability.

Comment thread scripts/dev-lead-fix-reviews.sh Outdated
Comment thread scripts/engine.sh
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-reviews (applied)

Changes committed and pushed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses issue #365 by preserving dev-lead agent session output in GitHub Actions (step summary + a known temp file) and re-surfacing that output as collapsed “Agent reasoning” context in no-changes PR comments, while adding unit tests to cover the new behavior.

Changes:

  • Persist run_writer session output by appending it to GITHUB_STEP_SUMMARY and copying it to /tmp/dev-lead-session-output.txt.
  • Add read_session_summary + post_no_changes helper to include a collapsed reasoning block in no-changes markers across intents.
  • Add/extend Bats tests to validate session persistence and no-changes comment rendering behavior.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

File Description
tests/dev-lead/unit/test_fix_reviews.bats Adds coverage for no-changes dry-run output including/excluding the “Agent reasoning” details block.
tests/dev-lead/unit/test_engine_writer.bats Adds coverage for session output persistence to /tmp/... and GITHUB_STEP_SUMMARY, including rate-limit/dry-run cases.
scripts/engine.sh Persists writer session output to step summary and a stable temp file.
scripts/dev-lead-fix-reviews.sh Adds helpers to read persisted session output and embed it in no-changes PR comments.

Comment on lines +89 to +103
read_session_summary() {
local log="/tmp/dev-lead-session-output.txt"
[ -f "$log" ] || return
# The agent output format is always at the end; grab last non-empty paragraph
tail -30 "$log" | sed '/^[[:space:]]*$/d' | tail -10
}

post_no_changes() {
local intent="$1"
local _summary
_summary=$(read_session_summary)
if [ -n "$_summary" ]; then
post_reviews_terminal "$intent" "no-changes" \
"<details><summary>Agent reasoning</summary>

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — human-pr (applied)

Changes committed and pushed.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: bad4e7f8be

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/dev-lead-fix-reviews.sh Outdated

read_session_summary() {
local log="/tmp/dev-lead-session-output.txt"
[ -f "$log" ] || return

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Return success when session log is missing

Make this guard return 0 instead of inheriting a failing status: post_no_changes captures read_session_summary via command substitution, and under set -e a non-zero return here aborts the whole script before posting the no-changes terminal marker. In practice, when /tmp/dev-lead-session-output.txt is absent (e.g., dry-run paths or any run where writer output was not persisted), the intent exits with status 1 instead of completing normally.

Useful? React with 👍 / 👎.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/dev-lead-fix-reviews.sh`:
- Around line 102-107: The rendered reasoning block risk breaks when _summary
contains triple backticks; before interpolating _summary into the
"<details><summary>Agent reasoning</summary>```...```</details>" string,
sanitize/escape triple-backtick sequences (or HTML-escape the whole summary and
wrap it in a <pre><code> block) so fences cannot be injected; implement this in
the code that builds the string (e.g., add a sanitizeSummary function used where
_summary is inserted) to replace or neutralize "```" (and optionally escape
HTML) prior to interpolation.
- Around line 91-100: The helper read_session_summary currently exits non-zero
when the log file is absent which causes _summary=$(read_session_summary) in
post_no_changes to fail under set -e; update read_session_summary so it returns
an empty string and a zero exit status when the target log file is missing (do
not use a non-zero return/path), or alternatively change the caller
post_no_changes to invoke read_session_summary in a safe way (e.g., capture its
output with a fallback like _summary=$(read_session_summary || true)),
referencing the read_session_summary function and the post_no_changes function
to locate where to apply the change.

In `@scripts/engine.sh`:
- Around line 582-588: The session output persistence currently runs commands
(cat "$_tmp" >> "$GITHUB_STEP_SUMMARY", cp "$_tmp"
/tmp/dev-lead-session-output.txt) that can trigger set -e and turn a successful
writer run into a hard failure; make these persistence steps best-effort by
guarding them so failures don't abort the script—wrap the GITHUB_STEP_SUMMARY
append and the cp into conditional checks or append "|| true" to the commands
that reference $_tmp and GITHUB_STEP_SUMMARY, or perform explicit if-checks
around cat and cp to ignore non-zero exits while still attempting to write the
file and summary (references: $_tmp, GITHUB_STEP_SUMMARY, and
/tmp/dev-lead-session-output.txt).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 949bb94c-084d-4945-ad61-fada4ed530b4

📥 Commits

Reviewing files that changed from the base of the PR and between 69e9774 and bad4e7f.

📒 Files selected for processing (4)
  • scripts/dev-lead-fix-reviews.sh
  • scripts/engine.sh
  • tests/dev-lead/unit/test_engine_writer.bats
  • tests/dev-lead/unit/test_fix_reviews.bats

Comment thread scripts/dev-lead-fix-reviews.sh Outdated
Comment thread scripts/dev-lead-fix-reviews.sh
Comment thread scripts/engine.sh
@don-petry

Copy link
Copy Markdown
Collaborator Author

@coderabbitai resolve

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — human-pr (no-changes)

Agent reasoning
Per the constraints, I must not resolve bot review threads.
Additionally, the concern the bot raised is **already addressed** by the current code: line 91 has `[ -f "$log" ] || return 0`, which causes `read_session_summary` to exit with status 0 (success, empty output) when the session log is absent. This means `_summary=$(read_session_summary)` won't trigger `errexit` under `set -euo pipefail`, and `post_no_changes` correctly falls back to the plain `no-changes` marker.
---

PR: #366 -
Human review threads addressed: 0

  • Thread copilot-pull-request-reviewer: skipped — bot reviewer (not a human); concern is also
    already addressed by the existing return 0 on line 91 [left open]
    Files changed: none

coderabbitai[bot]
coderabbitai Bot previously approved these changes May 23, 2026
@coderabbitai

coderabbitai Bot commented May 23, 2026

Copy link
Copy Markdown
✅ Actions performed

Comments resolved and changes approved.

@don-petry

Copy link
Copy Markdown
Collaborator Author

No description provided.

donpetry-bot
donpetry-bot previously approved these changes May 23, 2026

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: d3e417cd66569e419018dd2d50f9e68febff5ff9
Review mode: triage-approved (single reviewer)

Summary

Small, well-scoped implementation of issue #365. scripts/engine.sh run_writer now (a) appends the writer transcript to $GITHUB_STEP_SUMMARY inside a collapsible block when running under Actions, and (b) copies it to /tmp/dev-lead-session-output.txt before deletion. scripts/dev-lead-fix-reviews.sh adds read_session_summary + post_no_changes helpers and routes all five no-changes call-sites (fix-reviews, fix-bot-comment, human, human-pr, rebase) through the new helper so reasoning shows up as a collapsed <details> block. Bats coverage is added for both engine-side persistence (success, rate-limit, dry-run, GITHUB_STEP_SUMMARY set/unset) and the fix-reviews rendering paths.

Linked issue analysis

Issue #365 is substantively addressed and the implementation closely tracks the proposed approach (same file path, same helper shape, same five call-sites). Issue will auto-close on merge.

Findings

  • read_session_summary set -e safety: addressed — [ -f "$log" ] || return 0 returns success with empty output when the log is absent, so _summary=$(read_session_summary) doesn't trip errexit.
  • Minor (not blocking) — triple-backtick injection in rendered block: ${_summary} is interpolated between literal triple-backtick fences in post_no_changes. If the agent's structured output ever contains ```, the rendered markdown will break out of the code fence. Today's agent output formats don't emit fences, so the risk is theoretical; consider sanitizing or using an indented code block / <pre> if you want belt-and-suspenders.
  • Minor (not blocking) — best-effort persistence in run_writer: under set -euo pipefail, the new cat $_tmp >> $GITHUB_STEP_SUMMARY and cp $_tmp /tmp/... will abort a successful writer run on the (very unlikely) event they fail in CI. A trailing || true would make the persistence strictly best-effort.
  • Tests: new bats cases cover the success path, GITHUB_STEP_SUMMARY presence/absence, rate-limit, and dry-run; teardown cleans /tmp/dev-lead-session-output.txt in both test files so cases don't bleed.

CI status

All required checks green: CodeQL, SonarCloud, ShellCheck/shellcheck, bats, unit-tests, Agent Security Scan, Secret scan (gitleaks), AgentShield, validate-agent-profiles, gh-aw-compile, Compile agentic workflows. CodeRabbit's latest review is APPROVED.


Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.

donpetry-bot
donpetry-bot previously approved these changes May 23, 2026

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: 56d19b575bf661bdcfedc212b199c192094b48e2
Review mode: triage-approved (single reviewer)

Summary

Confirming triage assessment. The PR implements issue #365 exactly as specified — preserving dev-lead writer session output and surfacing structured agent reasoning in no-changes PR comments. Scope is limited to internal dev-lead automation; tests are thorough.

Linked issue analysis

Closes #365. The two-part spec in the issue is faithfully implemented:

  1. scripts/engine.sh — run_writer persistence. After the rate-limit check, output is appended to $GITHUB_STEP_SUMMARY (wrapped in a <details> block for cleanliness — a small UX improvement over the spec) and copied to /tmp/dev-lead-session-output.txt before the temp file is removed. Crucially the persistence sits after the rate-limit branch, so rate-limited runs do not leak the rate-limit banner into the next run's reasoning (verified by the new bats test run_writer does not write session file when rate-limited).
  2. scripts/dev-lead-fix-reviews.sh — surface reasoning. New read_session_summary (tail -30 → strip blank lines → tail -10) and post_no_changes helpers wrap the agent's structured output in a collapsed <details><summary>Agent reasoning</summary> block. All 5 no-changes call-sites (fix-reviews, fix-bot-comment, human, human-pr, rebase) are updated. Behavior gracefully degrades when the session file is absent.

Findings

No blocking issues.

Minor (non-blocking) observation: the agent's session output is embedded inside a triple-backtick code fence in the PR comment. If the agent ever emits a line containing ``` in its last ~10 lines, that could break out of the fence and cause cosmetic markdown rendering issues in the comment. Since the agent's Output Format is structured (Bot/Issues/Files lines), this is unlikely in practice — flagging only for awareness. Not worth blocking on.

CI status

All required checks green:

  • AgentShield ✓
  • Agent Security Scan ✓
  • CodeQL (actions) ✓
  • SonarCloud / SonarCloud Code Analysis ✓
  • Secret scan (gitleaks) ✓
  • ShellCheck + shellcheck ✓
  • bats, unit-tests ✓
  • validate-agent-profiles, gh-aw-compile, Compile agentic workflows ✓
  • review (PR Review Agent), CodeRabbit, dependency-audit ✓ / SKIPPED (no matching ecosystems)

Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Auto-rebase failed — merge conflict — this branch has conflicts with main that must be resolved.

Claude will attempt to resolve this automatically. If it cannot, a follow-up comment will explain what needs manual attention.

To resolve manually instead:

git fetch origin
git merge origin/main
# resolve conflicts, then:
git add .
git commit
git push

@donpetry-bot
donpetry-bot dismissed their stale review May 23, 2026 02:41

Superseded by automated re-review at 56d19b5.

@don-petry
don-petry dismissed stale reviews from donpetry-bot and coderabbitai[bot] via 66faa2e May 23, 2026 02:45
@don-petry
don-petry force-pushed the dev-lead/issue-365-20260523-0133 branch from 56d19b5 to 66faa2e Compare May 23, 2026 02:45
@don-petry

Copy link
Copy Markdown
Collaborator Author

No description provided.

@sonarqubecloud

Copy link
Copy Markdown

@don-petry

Copy link
Copy Markdown
Collaborator Author

No description provided.

don-petry added a commit that referenced this pull request Jun 18, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 18, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 18, 2026
…ession summary (#375)

Two follow-ups from issue #374 that PR #371 didn't cover. Rebased onto current main
(post-PR #371 merge) and folded in PR #375 review-comment fixes for jq injection,
memory efficiency, ACTOR forwarding, and pagination cap.

1. `resolve_actor_outdated_threads` — script-level safety net.
   The no-changes path used to rely on the agent to call `resolveReviewThread`.
   When the agent decided "no code change needed because already fixed," it tended
   to skip the resolve step, leaving outdated threads stuck open (e.g. PR #366's
   Copilot and ChatGPT-Codex threads). New helper queries reviewThreads,
   filters for `isResolved=false AND isOutdated=true AND author matches ACTOR`
   (with the GitHub Actions `[bot]` suffix optionally stripped to match
   GraphQL's `author.login`), and resolves each. Best-effort: failures emit
   warnings but don't fail the script. Wired into the no-changes branches of
   `fix-reviews`, `fix-bot-comment`, and `review-changes`.

   - ACTOR is passed via jq's `--arg` (gh's --jq does not accept --arg, so we
     pipe gh's output into jq directly) so a hostile actor value cannot escape
     the filter (gemini security-medium).
   - `reviewThreads(first:100)` — bumped from 50 to the GraphQL single-page max
     (copilot finding). Full cursor pagination is overkill for a safety net.
   - Workflow's review-changes step now sets `ACTOR: env.INTENT_ACTOR` so the
     helper can scrub outdated threads in the no-changes branch (was missing).
   - fix-reviews handler derives ACTOR from TRIGGERING_REVIEWER when not
     explicitly set, so the helper works without further workflow changes.

2. `read_session_summary` — marker-based extraction.
   The prior `tail -30 | sed | tail -10` assumed the agent's structured summary
   landed in the last 30 lines. When the agent ran many tool calls and emitted
   long trailing output, the summary was off-window and the helper returned
   empty, leaving the no-changes comment with only the fallback message
   instead of the agent's actual reasoning.

   Rewritten with `grep -nE` to find the last known output header
   (`Bot:`, `PR: #`, `Addressed N threads:`, `Human review threads addressed:`,
   `Issues addressed:`) and `sed -n "${mark},\$p"` to emit from there to EOF,
   capped at 30 non-blank lines. Falls back to the prior tail-window behaviour
   when no marker is present. Uses grep/sed rather than awk to avoid loading
   the full log into a memory array (gemini medium finding); redundant
   `head -30` removed.

   Redaction runs before the marker search, so PEM blocks straddling the kept
   window are still fully scrubbed (no header/body leakage across the
   boundary).

Tests: 33 fix-reviews tests (5 new — buried summary extraction, tail fallback,
dry-run announce, [bot]-stripped match, ACTOR-unset skip). 33 engine writer
tests unchanged. shellcheck clean.

Closes #374

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 21, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 21, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 23, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 23, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 23, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 23, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 23, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 23, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…ession summary (#375)

Two follow-ups from issue #374 that PR #371 didn't cover. Rebased onto current main
(post-PR #371 merge) and folded in PR #375 review-comment fixes for jq injection,
memory efficiency, ACTOR forwarding, and pagination cap.

1. `resolve_actor_outdated_threads` — script-level safety net.
   The no-changes path used to rely on the agent to call `resolveReviewThread`.
   When the agent decided "no code change needed because already fixed," it tended
   to skip the resolve step, leaving outdated threads stuck open (e.g. PR #366's
   Copilot and ChatGPT-Codex threads). New helper queries reviewThreads,
   filters for `isResolved=false AND isOutdated=true AND author matches ACTOR`
   (with the GitHub Actions `[bot]` suffix optionally stripped to match
   GraphQL's `author.login`), and resolves each. Best-effort: failures emit
   warnings but don't fail the script. Wired into the no-changes branches of
   `fix-reviews`, `fix-bot-comment`, and `review-changes`.

   - ACTOR is passed via jq's `--arg` (gh's --jq does not accept --arg, so we
     pipe gh's output into jq directly) so a hostile actor value cannot escape
     the filter (gemini security-medium).
   - `reviewThreads(first:100)` — bumped from 50 to the GraphQL single-page max
     (copilot finding). Full cursor pagination is overkill for a safety net.
   - Workflow's review-changes step now sets `ACTOR: env.INTENT_ACTOR` so the
     helper can scrub outdated threads in the no-changes branch (was missing).
   - fix-reviews handler derives ACTOR from TRIGGERING_REVIEWER when not
     explicitly set, so the helper works without further workflow changes.

2. `read_session_summary` — marker-based extraction.
   The prior `tail -30 | sed | tail -10` assumed the agent's structured summary
   landed in the last 30 lines. When the agent ran many tool calls and emitted
   long trailing output, the summary was off-window and the helper returned
   empty, leaving the no-changes comment with only the fallback message
   instead of the agent's actual reasoning.

   Rewritten with `grep -nE` to find the last known output header
   (`Bot:`, `PR: #`, `Addressed N threads:`, `Human review threads addressed:`,
   `Issues addressed:`) and `sed -n "${mark},\$p"` to emit from there to EOF,
   capped at 30 non-blank lines. Falls back to the prior tail-window behaviour
   when no marker is present. Uses grep/sed rather than awk to avoid loading
   the full log into a memory array (gemini medium finding); redundant
   `head -30` removed.

   Redaction runs before the marker search, so PEM blocks straddling the kept
   window are still fully scrubbed (no header/body leakage across the
   boundary).

Tests: 33 fix-reviews tests (5 new — buried summary extraction, tail fallback,
dry-run announce, [bot]-stripped match, ACTOR-unset skip). 33 engine writer
tests unchanged. shellcheck clean.

Closes #374

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…ession summary (#375)

Two follow-ups from issue #374 that PR #371 didn't cover. Rebased onto current main
(post-PR #371 merge) and folded in PR #375 review-comment fixes for jq injection,
memory efficiency, ACTOR forwarding, and pagination cap.

1. `resolve_actor_outdated_threads` — script-level safety net.
   The no-changes path used to rely on the agent to call `resolveReviewThread`.
   When the agent decided "no code change needed because already fixed," it tended
   to skip the resolve step, leaving outdated threads stuck open (e.g. PR #366's
   Copilot and ChatGPT-Codex threads). New helper queries reviewThreads,
   filters for `isResolved=false AND isOutdated=true AND author matches ACTOR`
   (with the GitHub Actions `[bot]` suffix optionally stripped to match
   GraphQL's `author.login`), and resolves each. Best-effort: failures emit
   warnings but don't fail the script. Wired into the no-changes branches of
   `fix-reviews`, `fix-bot-comment`, and `review-changes`.

   - ACTOR is passed via jq's `--arg` (gh's --jq does not accept --arg, so we
     pipe gh's output into jq directly) so a hostile actor value cannot escape
     the filter (gemini security-medium).
   - `reviewThreads(first:100)` — bumped from 50 to the GraphQL single-page max
     (copilot finding). Full cursor pagination is overkill for a safety net.
   - Workflow's review-changes step now sets `ACTOR: env.INTENT_ACTOR` so the
     helper can scrub outdated threads in the no-changes branch (was missing).
   - fix-reviews handler derives ACTOR from TRIGGERING_REVIEWER when not
     explicitly set, so the helper works without further workflow changes.

2. `read_session_summary` — marker-based extraction.
   The prior `tail -30 | sed | tail -10` assumed the agent's structured summary
   landed in the last 30 lines. When the agent ran many tool calls and emitted
   long trailing output, the summary was off-window and the helper returned
   empty, leaving the no-changes comment with only the fallback message
   instead of the agent's actual reasoning.

   Rewritten with `grep -nE` to find the last known output header
   (`Bot:`, `PR: #`, `Addressed N threads:`, `Human review threads addressed:`,
   `Issues addressed:`) and `sed -n "${mark},\$p"` to emit from there to EOF,
   capped at 30 non-blank lines. Falls back to the prior tail-window behaviour
   when no marker is present. Uses grep/sed rather than awk to avoid loading
   the full log into a memory array (gemini medium finding); redundant
   `head -30` removed.

   Redaction runs before the marker search, so PEM blocks straddling the kept
   window are still fully scrubbed (no header/body leakage across the
   boundary).

Tests: 33 fix-reviews tests (5 new — buried summary extraction, tail fallback,
dry-run announce, [bot]-stripped match, ACTOR-unset skip). 33 engine writer
tests unchanged. shellcheck clean.

Closes #374

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 2, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 2, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…ions logs and surface agent reasoning in no-changes comments (#366)

* feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

* fix(reviews): address review comments [skip ci-relay]

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments

3 participants