Repository navigation
feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments - #366
Conversation
|
Warning Review limit reached
Your plan currently allows 1 review/hour. Refill in 37 minutes and 10 seconds. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more review capacity refills, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than trial, open-source, and free plans. In all cases, review capacity refills continuously over time. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (4)
📝 WalkthroughWalkthroughThis PR implements persistent session output capture and enriched no-changes comments. The engine now saves agent output to GitHub Actions logs and a temp file; dev-lead-fix-reviews reads this output and embeds it as a collapsible "Agent reasoning" block in no-changes PR comments across all intent handlers. ChangesSession Output Persistence and No-Changes Enrichment
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes Possibly related issues
Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — human-pr (no-changes)Agent reasoningPR: #366 - |
|
No description provided. |
There was a problem hiding this comment.
Code Review
This pull request implements a mechanism to capture and display agent session summaries when no code changes are applied. It updates the engine to persist session logs to a temporary file and the GitHub Step Summary, and modifies the review script to include these logs as 'Agent reasoning' in PR comments. Feedback suggests refining the regex used for summary extraction to handle whitespace-only lines and wrapping the GitHub Step Summary output in a collapsible block for better readability.
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
There was a problem hiding this comment.
Pull request overview
This PR addresses issue #365 by preserving dev-lead agent session output in GitHub Actions (step summary + a known temp file) and re-surfacing that output as collapsed “Agent reasoning” context in no-changes PR comments, while adding unit tests to cover the new behavior.
Changes:
- Persist
run_writersession output by appending it toGITHUB_STEP_SUMMARYand copying it to/tmp/dev-lead-session-output.txt. - Add
read_session_summary+post_no_changeshelper to include a collapsed reasoning block inno-changesmarkers across intents. - Add/extend Bats tests to validate session persistence and
no-changescomment rendering behavior.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| tests/dev-lead/unit/test_fix_reviews.bats | Adds coverage for no-changes dry-run output including/excluding the “Agent reasoning” details block. |
| tests/dev-lead/unit/test_engine_writer.bats | Adds coverage for session output persistence to /tmp/... and GITHUB_STEP_SUMMARY, including rate-limit/dry-run cases. |
| scripts/engine.sh | Persists writer session output to step summary and a stable temp file. |
| scripts/dev-lead-fix-reviews.sh | Adds helpers to read persisted session output and embed it in no-changes PR comments. |
| read_session_summary() { | ||
| local log="/tmp/dev-lead-session-output.txt" | ||
| [ -f "$log" ] || return | ||
| # The agent output format is always at the end; grab last non-empty paragraph | ||
| tail -30 "$log" | sed '/^[[:space:]]*$/d' | tail -10 | ||
| } | ||
|
|
||
| post_no_changes() { | ||
| local intent="$1" | ||
| local _summary | ||
| _summary=$(read_session_summary) | ||
| if [ -n "$_summary" ]; then | ||
| post_reviews_terminal "$intent" "no-changes" \ | ||
| "<details><summary>Agent reasoning</summary> | ||
|
|
Dev-Lead — human-pr (applied)Changes committed and pushed. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: bad4e7f8be
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| read_session_summary() { | ||
| local log="/tmp/dev-lead-session-output.txt" | ||
| [ -f "$log" ] || return |
There was a problem hiding this comment.
Return success when session log is missing
Make this guard return 0 instead of inheriting a failing status: post_no_changes captures read_session_summary via command substitution, and under set -e a non-zero return here aborts the whole script before posting the no-changes terminal marker. In practice, when /tmp/dev-lead-session-output.txt is absent (e.g., dry-run paths or any run where writer output was not persisted), the intent exits with status 1 instead of completing normally.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@scripts/dev-lead-fix-reviews.sh`:
- Around line 102-107: The rendered reasoning block risk breaks when _summary
contains triple backticks; before interpolating _summary into the
"<details><summary>Agent reasoning</summary>```...```</details>" string,
sanitize/escape triple-backtick sequences (or HTML-escape the whole summary and
wrap it in a <pre><code> block) so fences cannot be injected; implement this in
the code that builds the string (e.g., add a sanitizeSummary function used where
_summary is inserted) to replace or neutralize "```" (and optionally escape
HTML) prior to interpolation.
- Around line 91-100: The helper read_session_summary currently exits non-zero
when the log file is absent which causes _summary=$(read_session_summary) in
post_no_changes to fail under set -e; update read_session_summary so it returns
an empty string and a zero exit status when the target log file is missing (do
not use a non-zero return/path), or alternatively change the caller
post_no_changes to invoke read_session_summary in a safe way (e.g., capture its
output with a fallback like _summary=$(read_session_summary || true)),
referencing the read_session_summary function and the post_no_changes function
to locate where to apply the change.
In `@scripts/engine.sh`:
- Around line 582-588: The session output persistence currently runs commands
(cat "$_tmp" >> "$GITHUB_STEP_SUMMARY", cp "$_tmp"
/tmp/dev-lead-session-output.txt) that can trigger set -e and turn a successful
writer run into a hard failure; make these persistence steps best-effort by
guarding them so failures don't abort the script—wrap the GITHUB_STEP_SUMMARY
append and the cp into conditional checks or append "|| true" to the commands
that reference $_tmp and GITHUB_STEP_SUMMARY, or perform explicit if-checks
around cat and cp to ignore non-zero exits while still attempting to write the
file and summary (references: $_tmp, GITHUB_STEP_SUMMARY, and
/tmp/dev-lead-session-output.txt).
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 949bb94c-084d-4945-ad61-fada4ed530b4
📒 Files selected for processing (4)
scripts/dev-lead-fix-reviews.shscripts/engine.shtests/dev-lead/unit/test_engine_writer.batstests/dev-lead/unit/test_fix_reviews.bats
|
@coderabbitai resolve |
Dev-Lead — human-pr (no-changes)Agent reasoningPR: #366 -
|
✅ Actions performedComments resolved and changes approved. |
|
No description provided. |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: d3e417cd66569e419018dd2d50f9e68febff5ff9
Review mode: triage-approved (single reviewer)
Summary
Small, well-scoped implementation of issue #365. scripts/engine.sh run_writer now (a) appends the writer transcript to $GITHUB_STEP_SUMMARY inside a collapsible block when running under Actions, and (b) copies it to /tmp/dev-lead-session-output.txt before deletion. scripts/dev-lead-fix-reviews.sh adds read_session_summary + post_no_changes helpers and routes all five no-changes call-sites (fix-reviews, fix-bot-comment, human, human-pr, rebase) through the new helper so reasoning shows up as a collapsed <details> block. Bats coverage is added for both engine-side persistence (success, rate-limit, dry-run, GITHUB_STEP_SUMMARY set/unset) and the fix-reviews rendering paths.
Linked issue analysis
Issue #365 is substantively addressed and the implementation closely tracks the proposed approach (same file path, same helper shape, same five call-sites). Issue will auto-close on merge.
Findings
read_session_summaryset -esafety: addressed —[ -f "$log" ] || return 0returns success with empty output when the log is absent, so_summary=$(read_session_summary)doesn't triperrexit.- Minor (not blocking) — triple-backtick injection in rendered block:
${_summary}is interpolated between literal triple-backtick fences inpost_no_changes. If the agent's structured output ever contains```, the rendered markdown will break out of the code fence. Today's agent output formats don't emit fences, so the risk is theoretical; consider sanitizing or using an indented code block /<pre>if you want belt-and-suspenders. - Minor (not blocking) — best-effort persistence in
run_writer: underset -euo pipefail, the newcat $_tmp >> $GITHUB_STEP_SUMMARYandcp $_tmp /tmp/...will abort a successful writer run on the (very unlikely) event they fail in CI. A trailing|| truewould make the persistence strictly best-effort. - Tests: new bats cases cover the success path, GITHUB_STEP_SUMMARY presence/absence, rate-limit, and dry-run; teardown cleans
/tmp/dev-lead-session-output.txtin both test files so cases don't bleed.
CI status
All required checks green: CodeQL, SonarCloud, ShellCheck/shellcheck, bats, unit-tests, Agent Security Scan, Secret scan (gitleaks), AgentShield, validate-agent-profiles, gh-aw-compile, Compile agentic workflows. CodeRabbit's latest review is APPROVED.
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: 56d19b575bf661bdcfedc212b199c192094b48e2
Review mode: triage-approved (single reviewer)
Summary
Confirming triage assessment. The PR implements issue #365 exactly as specified — preserving dev-lead writer session output and surfacing structured agent reasoning in no-changes PR comments. Scope is limited to internal dev-lead automation; tests are thorough.
Linked issue analysis
Closes #365. The two-part spec in the issue is faithfully implemented:
scripts/engine.sh—run_writerpersistence. After the rate-limit check, output is appended to$GITHUB_STEP_SUMMARY(wrapped in a<details>block for cleanliness — a small UX improvement over the spec) and copied to/tmp/dev-lead-session-output.txtbefore the temp file is removed. Crucially the persistence sits after the rate-limit branch, so rate-limited runs do not leak the rate-limit banner into the next run's reasoning (verified by the new bats testrun_writer does not write session file when rate-limited).scripts/dev-lead-fix-reviews.sh— surface reasoning. Newread_session_summary(tail -30 → strip blank lines → tail -10) andpost_no_changeshelpers wrap the agent's structured output in a collapsed<details><summary>Agent reasoning</summary>block. All 5no-changescall-sites (fix-reviews,fix-bot-comment,human,human-pr,rebase) are updated. Behavior gracefully degrades when the session file is absent.
Findings
No blocking issues.
Minor (non-blocking) observation: the agent's session output is embedded inside a triple-backtick code fence in the PR comment. If the agent ever emits a line containing ``` in its last ~10 lines, that could break out of the fence and cause cosmetic markdown rendering issues in the comment. Since the agent's Output Format is structured (Bot/Issues/Files lines), this is unlikely in practice — flagging only for awareness. Not worth blocking on.
CI status
All required checks green:
- AgentShield ✓
- Agent Security Scan ✓
- CodeQL (actions) ✓
- SonarCloud / SonarCloud Code Analysis ✓
- Secret scan (gitleaks) ✓
- ShellCheck + shellcheck ✓
- bats, unit-tests ✓
- validate-agent-profiles, gh-aw-compile, Compile agentic workflows ✓
- review (PR Review Agent), CodeRabbit, dependency-audit ✓ / SKIPPED (no matching ecosystems)
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.
|
Auto-rebase failed — merge conflict — this branch has conflicts with Claude will attempt to resolve this automatically. If it cannot, a follow-up comment will explain what needs manual attention. To resolve manually instead: |
Superseded by automated re-review at 56d19b5.
…ions logs and surface agent reasoning in no-changes comments
66faa2e
56d19b5 to
66faa2e
Compare
|
No description provided. |
|
|
No description provided. |
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ession summary (#375) Two follow-ups from issue #374 that PR #371 didn't cover. Rebased onto current main (post-PR #371 merge) and folded in PR #375 review-comment fixes for jq injection, memory efficiency, ACTOR forwarding, and pagination cap. 1. `resolve_actor_outdated_threads` — script-level safety net. The no-changes path used to rely on the agent to call `resolveReviewThread`. When the agent decided "no code change needed because already fixed," it tended to skip the resolve step, leaving outdated threads stuck open (e.g. PR #366's Copilot and ChatGPT-Codex threads). New helper queries reviewThreads, filters for `isResolved=false AND isOutdated=true AND author matches ACTOR` (with the GitHub Actions `[bot]` suffix optionally stripped to match GraphQL's `author.login`), and resolves each. Best-effort: failures emit warnings but don't fail the script. Wired into the no-changes branches of `fix-reviews`, `fix-bot-comment`, and `review-changes`. - ACTOR is passed via jq's `--arg` (gh's --jq does not accept --arg, so we pipe gh's output into jq directly) so a hostile actor value cannot escape the filter (gemini security-medium). - `reviewThreads(first:100)` — bumped from 50 to the GraphQL single-page max (copilot finding). Full cursor pagination is overkill for a safety net. - Workflow's review-changes step now sets `ACTOR: env.INTENT_ACTOR` so the helper can scrub outdated threads in the no-changes branch (was missing). - fix-reviews handler derives ACTOR from TRIGGERING_REVIEWER when not explicitly set, so the helper works without further workflow changes. 2. `read_session_summary` — marker-based extraction. The prior `tail -30 | sed | tail -10` assumed the agent's structured summary landed in the last 30 lines. When the agent ran many tool calls and emitted long trailing output, the summary was off-window and the helper returned empty, leaving the no-changes comment with only the fallback message instead of the agent's actual reasoning. Rewritten with `grep -nE` to find the last known output header (`Bot:`, `PR: #`, `Addressed N threads:`, `Human review threads addressed:`, `Issues addressed:`) and `sed -n "${mark},\$p"` to emit from there to EOF, capped at 30 non-blank lines. Falls back to the prior tail-window behaviour when no marker is present. Uses grep/sed rather than awk to avoid loading the full log into a memory array (gemini medium finding); redundant `head -30` removed. Redaction runs before the marker search, so PEM blocks straddling the kept window are still fully scrubbed (no header/body leakage across the boundary). Tests: 33 fix-reviews tests (5 new — buried summary extraction, tail fallback, dry-run announce, [bot]-stripped match, ACTOR-unset skip). 33 engine writer tests unchanged. shellcheck clean. Closes #374 Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ession summary (#375) Two follow-ups from issue #374 that PR #371 didn't cover. Rebased onto current main (post-PR #371 merge) and folded in PR #375 review-comment fixes for jq injection, memory efficiency, ACTOR forwarding, and pagination cap. 1. `resolve_actor_outdated_threads` — script-level safety net. The no-changes path used to rely on the agent to call `resolveReviewThread`. When the agent decided "no code change needed because already fixed," it tended to skip the resolve step, leaving outdated threads stuck open (e.g. PR #366's Copilot and ChatGPT-Codex threads). New helper queries reviewThreads, filters for `isResolved=false AND isOutdated=true AND author matches ACTOR` (with the GitHub Actions `[bot]` suffix optionally stripped to match GraphQL's `author.login`), and resolves each. Best-effort: failures emit warnings but don't fail the script. Wired into the no-changes branches of `fix-reviews`, `fix-bot-comment`, and `review-changes`. - ACTOR is passed via jq's `--arg` (gh's --jq does not accept --arg, so we pipe gh's output into jq directly) so a hostile actor value cannot escape the filter (gemini security-medium). - `reviewThreads(first:100)` — bumped from 50 to the GraphQL single-page max (copilot finding). Full cursor pagination is overkill for a safety net. - Workflow's review-changes step now sets `ACTOR: env.INTENT_ACTOR` so the helper can scrub outdated threads in the no-changes branch (was missing). - fix-reviews handler derives ACTOR from TRIGGERING_REVIEWER when not explicitly set, so the helper works without further workflow changes. 2. `read_session_summary` — marker-based extraction. The prior `tail -30 | sed | tail -10` assumed the agent's structured summary landed in the last 30 lines. When the agent ran many tool calls and emitted long trailing output, the summary was off-window and the helper returned empty, leaving the no-changes comment with only the fallback message instead of the agent's actual reasoning. Rewritten with `grep -nE` to find the last known output header (`Bot:`, `PR: #`, `Addressed N threads:`, `Human review threads addressed:`, `Issues addressed:`) and `sed -n "${mark},\$p"` to emit from there to EOF, capped at 30 non-blank lines. Falls back to the prior tail-window behaviour when no marker is present. Uses grep/sed rather than awk to avoid loading the full log into a memory array (gemini medium finding); redundant `head -30` removed. Redaction runs before the marker search, so PEM blocks straddling the kept window are still fully scrubbed (no header/body leakage across the boundary). Tests: 33 fix-reviews tests (5 new — buried summary extraction, tail fallback, dry-run announce, [bot]-stripped match, ACTOR-unset skip). 33 engine writer tests unchanged. shellcheck clean. Closes #374 Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ession summary (#375) Two follow-ups from issue #374 that PR #371 didn't cover. Rebased onto current main (post-PR #371 merge) and folded in PR #375 review-comment fixes for jq injection, memory efficiency, ACTOR forwarding, and pagination cap. 1. `resolve_actor_outdated_threads` — script-level safety net. The no-changes path used to rely on the agent to call `resolveReviewThread`. When the agent decided "no code change needed because already fixed," it tended to skip the resolve step, leaving outdated threads stuck open (e.g. PR #366's Copilot and ChatGPT-Codex threads). New helper queries reviewThreads, filters for `isResolved=false AND isOutdated=true AND author matches ACTOR` (with the GitHub Actions `[bot]` suffix optionally stripped to match GraphQL's `author.login`), and resolves each. Best-effort: failures emit warnings but don't fail the script. Wired into the no-changes branches of `fix-reviews`, `fix-bot-comment`, and `review-changes`. - ACTOR is passed via jq's `--arg` (gh's --jq does not accept --arg, so we pipe gh's output into jq directly) so a hostile actor value cannot escape the filter (gemini security-medium). - `reviewThreads(first:100)` — bumped from 50 to the GraphQL single-page max (copilot finding). Full cursor pagination is overkill for a safety net. - Workflow's review-changes step now sets `ACTOR: env.INTENT_ACTOR` so the helper can scrub outdated threads in the no-changes branch (was missing). - fix-reviews handler derives ACTOR from TRIGGERING_REVIEWER when not explicitly set, so the helper works without further workflow changes. 2. `read_session_summary` — marker-based extraction. The prior `tail -30 | sed | tail -10` assumed the agent's structured summary landed in the last 30 lines. When the agent ran many tool calls and emitted long trailing output, the summary was off-window and the helper returned empty, leaving the no-changes comment with only the fallback message instead of the agent's actual reasoning. Rewritten with `grep -nE` to find the last known output header (`Bot:`, `PR: #`, `Addressed N threads:`, `Human review threads addressed:`, `Issues addressed:`) and `sed -n "${mark},\$p"` to emit from there to EOF, capped at 30 non-blank lines. Falls back to the prior tail-window behaviour when no marker is present. Uses grep/sed rather than awk to avoid loading the full log into a memory array (gemini medium finding); redundant `head -30` removed. Redaction runs before the marker search, so PEM blocks straddling the kept window are still fully scrubbed (no header/body leakage across the boundary). Tests: 33 fix-reviews tests (5 new — buried summary extraction, tail fallback, dry-run announce, [bot]-stripped match, ACTOR-unset skip). 33 engine writer tests unchanged. shellcheck clean. Closes #374 Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ions logs and surface agent reasoning in no-changes comments (#366) * feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments * fix(reviews): address review comments [skip ci-relay] * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com> Co-authored-by: donpetry-bot <donpetry-bot@users.noreply.github.com>



Closes #365
Implemented by dev-lead agent. Please review.
Summary by CodeRabbit