Skip to content

fix(dev-lead): visible no-changes comments, ACTOR for fix-reviews, bot login mismatch - #371

Merged
don-petry merged 1 commit into
mainfrom
fix/dev-lead-empty-comments-and-resolve
May 23, 2026
Merged

don-petry merged 1 commit into
mainfrom
fix/dev-lead-empty-comments-and-resolve

Conversation

@don-petry

@don-petry don-petry commented May 23, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Three bugs diagnosed from observing PR #366 runs:

  • Empty no-changes comments — all intent handlers called post_reviews_terminal "X" "no-changes" with no summary arg, producing an invisible HTML-only marker body. Added read_session_summary + post_no_changes helpers that attach the agent's session tail (or a plain fallback) to every no-changes comment. Also backports the engine.sh session-output persistence from feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments #366 (copy _tmp → /tmp/dev-lead-session-output.txt + GITHUB_STEP_SUMMARY).

  • ACTOR not forwarded to fix-reviews — the workflow step and the script's fix-reviews handler both lacked ACTOR, making the "only resolve threads from the triggering reviewer" constraint unenforceable. Added ACTOR: ${{ env.INTENT_ACTOR }} to the step env and export ACTOR in the handler.

  • Bot [bot] suffix mismatch in fix-bot-comment — GitHub Actions sets ACTOR with the [bot] suffix (e.g. chatgpt-codex-connector[bot]) while GraphQL's author.login omits it. The jq filter used a strict == comparison, so threads from bots like chatgpt-codex and coderabbitai were never found and never resolved. Updated the filter in fix-bot-comment.md to match both the raw and [bot]-stripped form.

Test plan

  • bats tests/dev-lead/unit/test_fix_reviews.bats — all 23 tests pass (2 updated, 2 new)
  • bats tests/dev-lead/unit/test_engine_writer.bats — all 28 tests pass (1 new: session file persistence)
  • Observe next fix-bot-comment no-changes run on a PR — comment should show "No actionable items found." or agent reasoning instead of blank
  • Observe next bot thread after a code fix — thread should be resolved by the agent

🤖 Generated with Claude Code

Summary by CodeRabbit

Release Notes

  • New Features

    • Added credential redaction for sensitive token patterns in agent output
    • Implemented session output persistence and enhanced "no changes" reporting with agent reasoning details
  • Bug Fixes

    • Fixed bot review thread resolution to handle GitHub Actions bot author variations
  • Tests

    • Added comprehensive test coverage for session output persistence, credential redaction, and HTML escaping

Review Change Stack

Copilot AI review requested due to automatic review settings May 23, 2026 02:48
@coderabbitai

coderabbitai Bot commented May 23, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@don-petry, we couldn't start this review because you've used your available PR reviews for now.

Your plan currently allows 1 review/hour. Refill in 20 minutes and 8 seconds.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more review capacity refills, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than trial, open-source, and free plans. In all cases, review capacity refills continuously over time.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 50bd8d14-daca-4ec8-ab5a-51364b8a2cda

📥 Commits

Reviewing files that changed from the base of the PR and between 74ecfa3 and 0da801c.

📒 Files selected for processing (5)
  • prompts/dev-lead/fix-bot-comment.md
  • scripts/dev-lead-fix-reviews.sh
  • scripts/engine.sh
  • tests/dev-lead/unit/test_engine_writer.bats
  • tests/dev-lead/unit/test_fix_reviews.bats
📝 Walkthrough

Walkthrough

The PR enhances the dev-lead agent's session handling by persisting captured output through a shared file, redacting sensitive credentials, and including agent reasoning in terminal no-changes reports. It also hardens bot-author matching to handle GraphQL's inconsistent [bot] suffix inclusion.

Changes

Session Output Persistence and Redaction

Layer / File(s) Summary
Engine session output persistence
scripts/engine.sh, tests/dev-lead/unit/test_engine_writer.bats
run_writer() now appends an HTML-escaped expandable session log to GITHUB_STEP_SUMMARY and persists captured output to /tmp/dev-lead-session-output.txt. Tests verify persistence and HTML escaping of </details> literals.
Bot-author GraphQL matching robustness
prompts/dev-lead/fix-bot-comment.md
The thread-resolution jq filter now matches review threads from the bot regardless of whether author.login includes the [bot] suffix by checking both the provided ${ACTOR} value and ${ACTOR} with any trailing [bot] removed.
Session redaction and reporting helpers
scripts/dev-lead-fix-reviews.sh
Four new functions: redact_secrets() masks token patterns, read_session_summary() sanitizes agent reasoning lines from the session file, pick_fence() generates a safe tilde fence, and post_no_changes() posts a no-changes marker with optional redacted agent context inside a <details> block.
Bot-author normalization and wiring
scripts/dev-lead-fix-reviews.sh
TRIGGERING_REVIEWER is normalized by stripping a trailing [bot] suffix for fix-reviews; the fix-reviews, fix-bot-comment, and rebase intents replace post_reviews_terminal no-changes calls with post_no_changes to include redacted agent reasoning in terminal output.
Session redaction and reporting test coverage
tests/dev-lead/unit/test_fix_reviews.bats
Five new tests validate post_no_changes behavior: fallback heading and "No actionable items found" when session log is missing, inclusion of agent reasoning when log exists, token redaction correctness, markdown fence selection for embedded tildes, and HTML escaping of literal </details> tags.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related issues

Possibly related PRs

Suggested labels

needs-human-review

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the three main fixes: visible no-changes comments, ACTOR variable forwarding for fix-reviews, and bot login suffix mismatch resolution.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/dev-lead-empty-comments-and-resolve

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@don-petry

Copy link
Copy Markdown
Collaborator Author

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes several dev-lead workflow/script issues observed in PR runs by ensuring “no-changes” outcomes produce a visible, informative PR comment; ensuring ACTOR is forwarded into fix-reviews; and correcting bot author matching where GitHub Actions includes a [bot] suffix but GraphQL omits it.

Changes:

  • Add read_session_summary + post_no_changes to always post a visible no-changes comment body (fallback text or session-log tail).
  • Persist writer session output to /tmp/dev-lead-session-output.txt and (when available) append it to GITHUB_STEP_SUMMARY.
  • Forward ACTOR into the fix-reviews step and update bot-thread matching to handle [bot] suffix differences.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated no comments.

Show a summary per file
File Description
scripts/dev-lead-fix-reviews.sh Adds helpers to include a visible summary (fallback or session tail) in no-changes terminal comments; exports ACTOR for fix-reviews.
scripts/engine.sh Persists writer output to /tmp/dev-lead-session-output.txt and appends it to the step summary for visibility/debugging.
.github/workflows/dev-lead.yml Passes ACTOR into the fix-reviews job step environment.
prompts/dev-lead/fix-reviews.md Declares ACTOR as a prompt variable and documents [bot] suffix differences for thread ownership decisions.
prompts/dev-lead/fix-bot-comment.md Updates jq filtering guidance to match bot logins with/without [bot] suffix.
tests/dev-lead/unit/test_fix_reviews.bats Updates/adds tests to validate visible no-changes comment output (fallback + session log).
tests/dev-lead/unit/test_engine_writer.bats Adds coverage for session-output persistence to /tmp/dev-lead-session-output.txt.

@donpetry-bot

donpetry-bot commented May 23, 2026 •

Copy link
Copy Markdown
Contributor
Superseded by automated re-review at fbb723034f81078e82661026619984b117ccd2ac — click to expand prior review.

Review — fix requested (cycle 1/3)

The automated review identified the following issues. Please address each one:

Findings to fix

Automated review — NEEDS HUMAN REVIEW

Risk: LOW
Reviewed commit: 7ce85dc37cba202ce131214e6a22a05010e69415
Cascade: triage → deep (triage: haiku 4.5 → deep: sonnet 4.6 + duck: o4-mini → audit: opus 4.7)

Summary

PR #371 fixes three real dev-lead bugs (empty no-changes comments, missing ACTOR forwarding, bot login suffix mismatch) with comprehensive tests and passing CodeQL. The sole blocking gate failure is the unresolved merge conflict (mergeStateStatus=DIRTY); no security concerns were found in the changes themselves.

Findings

  • MAJOR: PR is in CONFLICTING/DIRTY state and cannot be merged to main. Author must rebase or merge main into the branch to resolve conflicts before approval.
  • MINOR: fix-reviews.md softens the thread-resolution constraint from 'Only resolve threads from the triggering reviewer' to 'Prioritize... leave open unless you also address their concern.' This is intentional but widens agent authority — could lead to resolving threads from unrelated reviewers in edge cases. (prompts/dev-lead/fix-reviews.md:31)
  • INFO: /tmp/dev-lead-session-output.txt is a fixed path written by engine.sh and read by dev-lead-fix-reviews.sh. Concurrent CI jobs on the same runner host could race, though in practice each GitHub Actions job runs in an isolated VM. (scripts/engine.sh:590)
  • INFO: If the session output itself contains '~~~~', the tilde-fenced code block in post_no_changes will be broken in the rendered GitHub comment. Low probability but worth noting. (scripts/dev-lead-fix-reviews.sh:106)
  • INFO: CodeQL (Actions) and CodeRabbit status checks passed. Dependabot check skipped as expected. No CI failures.

Reviewed by the PR-review cascade (triage: haiku 4.5 → deep: sonnet 4.6 + duck: o4-mini → audit: opus 4.7). Reply if you need a human review.

Additional tasks

  1. Resolve all unresolved review thread comments from other reviewers
  2. Ensure all CI checks pass after your changes
  3. Rebase on the target branch if behind
  4. Do NOT modify files unrelated to the findings above

The review cascade will automatically re-review after new commits are pushed.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7ce85dc37c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/dev-lead-fix-reviews.sh Outdated

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request enhances the dev-lead agent's handling of bot logins and improves transparency when no actionable items are found. Key changes include updating GraphQL queries to match bot logins with or without the '[bot]' suffix, persisting session logs to a temporary file, and including agent reasoning in the GitHub Step Summary and PR comments. Feedback was provided regarding the potential for raw agent output to break HTML rendering in the GitHub Step Summary, suggesting the use of code blocks for better isolation.

Comment thread scripts/engine.sh
don-petry added a commit that referenced this pull request May 23, 2026
…njection

Rebase + review feedback addressed on top of #371's original intent.

Changes vs. main:
- engine.sh now persists writer session output to /tmp/dev-lead-session-output.txt
  and to GITHUB_STEP_SUMMARY with HTML-escaped content inside a <pre> block,
  so literal </details> in agent output cannot break the wrapping <details>
  on the run summary page (Gemini medium finding).
- dev-lead-fix-reviews.sh adds redact_secrets, read_session_summary, pick_fence,
  and post_no_changes.  Secrets matching common token formats (GitHub PAT,
  Anthropic/OpenAI keys, AWS, Google OAuth, bearer tokens, PEM private keys)
  are scrubbed before the session tail is published to a PR comment
  (ChatGPT-Codex P1 finding).  The wrapping ~~~~ fence is grown to outrun any
  tilde sequence in the content (review-agent INFO finding), and literal
  </details> in content is escaped so it cannot terminate the outer block.
- All three remaining bare 'no-changes' call sites (fix-reviews, fix-bot-comment,
  rebase) now use post_no_changes — the bug that originally motivated #371.
- TRIGGERING_REVIEWER is normalised by stripping any trailing [bot] suffix so
  it matches GraphQL's author.login form.  Without this, the fix-reviews.md
  constraint 'author.login == ${TRIGGERING_REVIEWER}' never matched bot
  threads.
- fix-bot-comment.md jq filter updated to match author.login against both the
  raw ACTOR and ACTOR with [bot] stripped.
- 7 new bats tests: session output persistence, GITHUB_STEP_SUMMARY HTML
  escape, fallback comment body, agent-reasoning capture, GH token redaction,
  pick_fence tilde-overrun, </details> neutralisation.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
@don-petry
don-petry force-pushed the fix/dev-lead-empty-comments-and-resolve branch from 7ce85dc to 74ecfa3 Compare May 23, 2026 12:39
don-petry added a commit that referenced this pull request May 23, 2026
…njection

Rebase + review feedback addressed on top of #371's original intent.

Changes vs. main:
- engine.sh now persists writer session output to /tmp/dev-lead-session-output.txt
  and to GITHUB_STEP_SUMMARY with HTML-escaped content inside a <pre> block,
  so literal </details> in agent output cannot break the wrapping <details>
  on the run summary page (Gemini medium finding).
- dev-lead-fix-reviews.sh adds redact_secrets, read_session_summary, pick_fence,
  and post_no_changes.  Secrets matching common token formats (GitHub PAT,
  Anthropic/OpenAI keys, AWS, Google OAuth, bearer tokens, PEM private keys)
  are scrubbed before the session tail is published to a PR comment
  (ChatGPT-Codex P1 finding).  The wrapping ~~~~ fence is grown to outrun any
  tilde sequence in the content (review-agent INFO finding), and literal
  </details> in content is escaped so it cannot terminate the outer block.
- All three remaining bare 'no-changes' call sites (fix-reviews, fix-bot-comment,
  rebase) now use post_no_changes — the bug that originally motivated #371.
- TRIGGERING_REVIEWER is normalised by stripping any trailing [bot] suffix so
  it matches GraphQL's author.login form.  Without this, the fix-reviews.md
  constraint 'author.login == ${TRIGGERING_REVIEWER}' never matched bot
  threads.
- fix-bot-comment.md jq filter updated to match author.login against both the
  raw ACTOR and ACTOR with [bot] stripped.
- 7 new bats tests: session output persistence, GITHUB_STEP_SUMMARY HTML
  escape, fallback comment body, agent-reasoning capture, GH token redaction,
  pick_fence tilde-overrun, </details> neutralisation.

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
@don-petry
don-petry force-pushed the fix/dev-lead-empty-comments-and-resolve branch from 74ecfa3 to fbb7230 Compare May 23, 2026 12:40
donpetry-bot
donpetry-bot previously approved these changes May 23, 2026

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: fbb723034f81078e82661026619984b117ccd2ac
Review mode: triage-approved (single reviewer)

Summary

Focused dev-lead bug fix PR that the triage tier already cleared as low-risk. The new head SHA addresses the prior review's findings: the merge conflict is resolved (mergeable=MERGEABLE), the tilde-fence overrun edge case is handled by the new pick_fence helper, and defense-in-depth credential redaction was added before session output is published to PR comments. HTML escaping of </details> and < in the GitHub step summary closes a related output-integrity issue raised by Gemini.

Linked issue analysis

No linked issues. PR body cleanly describes the three motivating bugs observed on PR #366 runs and the additional review-feedback items rolled in on rebase.

Findings

  • No blocking issues found.
  • redact_secrets regex covers GitHub tokens (gh[opsu]/ghr/github_pat_), OpenAI/Anthropic (sk-/sk-ant-), AWS access keys (AKIA), Google (AIza/ya29.), bearer tokens, and PEM private-key headers — reasonable defense-in-depth before publishing session tails to PR comments.
  • HTML escaping in engine.sh uses correct ordering (& first, then </>) so the wrapping <details> on the run summary page cannot be broken by literal HTML in agent output.
  • </details> neutralisation in post_no_changes (replaces with <\/details>) will render the backslash literally to readers, but it is acceptable given that the alternative is a broken collapsible block.
  • Bot login suffix handling — both the jq filter in fix-bot-comment.md and the TRIGGERING_REVIEWER normalisation in dev-lead-fix-reviews.sh correctly bridge the GitHub Actions actor form (with [bot]) to the GraphQL author.login form (without).
  • Tests: 7 new bats cases exercise the new helpers (session persistence, GITHUB_STEP_SUMMARY HTML escape, fallback body, agent-reasoning body, GH token redaction, pick_fence overrun, </details> neutralisation).

CI status

All 22 checks SUCCESS or SKIPPED — CodeQL, AgentShield, Agent Security Scan, gitleaks, ShellCheck, bats, unit-tests, SonarCloud (Quality Gate passed, 0 new issues), Lint, dependency-audit (skipped per ecosystem), Compile agentic workflows, validate-agent-profiles, gh-aw-compile. Dependabot check skipped as expected. No CI failures or security warnings.


Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/dev-lead-fix-reviews.sh`:
- Around line 95-103: Current redaction only replaces the "-----BEGIN ...
PRIVATE KEY-----" line and leaves the PEM body and the "END" line exposed;
update the script's private-key redaction to remove the entire PEM block between
the BEGIN and END markers. Replace the single-line sed regex '-----BEGIN [A-Z
]*PRIVATE KEY-----' with a multiline-safe replacement (e.g., use perl -0777 -pe
or sed -z) that matches /-----BEGIN [A-Z ]*PRIVATE KEY-----.*?-----END [A-Z
]*PRIVATE KEY-----/s and substitutes the whole block with a single placeholder
like '***REDACTED-PRIVATE-KEY***' so both the header, body, and footer are
redacted (apply this change where the current sed invocation and the '-----BEGIN
[A-Z ]*PRIVATE KEY-----' pattern appear).
- Around line 111-137: The conditional tests using single-bracket [ ... ] in
helper functions should be converted to bash-style double-bracket tests [[ ...
]] to match repo standards: update read_session_summary (the line using [ -f
"$log" ] || return 0) to use [[ -f $log ]] || return 0 (preserve
quoting/word-safety as appropriate) and update post_no_changes (the if [ -n
"$_summary" ]; then) to if [[ -n $_summary ]]; then; also scan other helper
functions like pick_fence for any remaining [ ... ] usages and replace them with
[[ ... ]] while keeping the same test semantics and variable quoting where
necessary.

In `@scripts/engine.sh`:
- Around line 598-600: When the copy of "$_tmp" to
/tmp/dev-lead-session-output.txt fails the old target can persist and leak into
read_session_summary; change the failure branch for the cp command so it removes
or truncates /tmp/dev-lead-session-output.txt (e.g. rm -f
/tmp/dev-lead-session-output.txt or : > /tmp/dev-lead-session-output.txt)
instead of only emitting a warning, keeping the existing rm -f "$_tmp" behavior
afterward.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 3a21a6a3-0c5a-439e-9570-cf4e46735438

📥 Commits

Reviewing files that changed from the base of the PR and between 52b84f5 and 74ecfa3.

📒 Files selected for processing (5)
  • prompts/dev-lead/fix-bot-comment.md
  • scripts/dev-lead-fix-reviews.sh
  • scripts/engine.sh
  • tests/dev-lead/unit/test_engine_writer.bats
  • tests/dev-lead/unit/test_fix_reviews.bats

Comment thread scripts/dev-lead-fix-reviews.sh Outdated
Comment thread scripts/dev-lead-fix-reviews.sh Outdated
Comment thread scripts/engine.sh Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fbb723034f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/dev-lead-fix-reviews.sh Outdated
@don-petry

Copy link
Copy Markdown
Collaborator Author

@coderabbitai resolve

coderabbitai[bot]
coderabbitai Bot previously approved these changes May 23, 2026
@coderabbitai

coderabbitai Bot commented May 23, 2026

Copy link
Copy Markdown
✅ Actions performed

Comments resolved and changes approved.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — rate-limited (intent: fix-reviews)

PR: #371
The retry cron will re-attempt automatically.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f53d80fa8d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/engine.sh Outdated
Comment thread scripts/engine.sh Outdated
Comment thread scripts/dev-lead-fix-reviews.sh Outdated
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — rate-limited (intent: fix-reviews)

PR: #371
The retry cron will re-attempt automatically.

donpetry-bot
donpetry-bot previously approved these changes May 23, 2026

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: f8677c012e44d5986efef34fece50a043b1dbcc3
Review mode: triage-approved (single reviewer)

Summary

Triage cleared this dev-lead bug-fix PR as low-risk; confirmation review agrees. The new head SHA addresses CodeRabbit's three findings on the prior commit (full PEM-block redaction via sed range c\, stale session-file guard with rm -f + cp-failure truncation, and [[ ]] conditionals). All 22 CI checks pass and the changes are well-tested with 7 new bats cases. No security, correctness, or maintainability concerns.

Linked issue analysis

No linked issues. PR body describes three motivating bugs observed on PR #366 runs (empty no-changes comments, missing ACTOR forwarding, bot [bot] suffix mismatch) plus the additional review-feedback items addressed during rebase.

Findings

  • No blocking issues found.
  • PEM-block redaction (Critical fix from CodeRabbit) — redact_secrets now uses sed range /-----BEGIN .../,/-----END .../c\ so the entire multi-line PEM block is replaced, not just the BEGIN header. New bats test confirms body/footer lines no longer leak. (scripts/dev-lead-fix-reviews.sh:103)
  • Stale session-output guard (Major fix from CodeRabbit) — engine.sh now rm -f /tmp/dev-lead-session-output.txt before cp, and truncates on cp failure, so a prior run's content cannot be read by the next read_session_summary call. New bats test pre-populates the file with STALE_CONTENT_FROM_PRIOR_RUN and asserts replacement. (scripts/engine.sh:601-605)
  • Bash conventions (Minor fix from CodeRabbit) — new helpers read_session_summary and post_no_changes use [[ ]] per repo shell.instructions.md. (scripts/dev-lead-fix-reviews.sh:114, 130)
  • Bot login suffix handling — both the jq filter in fix-bot-comment.md and TRIGGERING_REVIEWER normalisation in dev-lead-fix-reviews.sh correctly bridge the GitHub Actions actor form (with [bot]) to the GraphQL author.login form (without).
  • HTML escaping — engine.sh uses correct ordering (& first, then </>) so literal HTML in agent output cannot break the wrapping <details> on the run summary page.
  • Tests — 7 new bats cases exercise session persistence, GITHUB_STEP_SUMMARY HTML escape, stale-file overwrite, fallback body, agent-reasoning body, GH-token redaction, full PEM-block redaction, pick_fence tilde-overrun, and </details> neutralisation. Test fixtures correctly avoid literal secret/PEM patterns to dodge our own gitleaks check.

CI status

All 22 checks SUCCESS or SKIPPED — CodeQL (Actions + general), AgentShield, Agent Security Scan, gitleaks, ShellCheck, bats, unit-tests, SonarCloud (Quality Gate passed, 0 new issues), Lint, dependency-audit (skipped per ecosystem), Compile agentic workflows, validate-agent-profiles, gh-aw-compile. Dependabot and pr-review-mention skipped as expected. No CI failures or security warnings. mergeStateStatus=BLOCKED reflects pending approval, not a merge conflict (mergeable=MERGEABLE).


Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Auto-rebase failed — merge conflict — this branch has conflicts with main that must be resolved.

Claude will attempt to resolve this automatically. If it cannot, a follow-up comment will explain what needs manual attention.

To resolve manually instead:

git fetch origin
git merge origin/main
# resolve conflicts, then:
git add .
git commit
git push

don-petry added a commit that referenced this pull request Jun 25, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…ession summary (#375)

Two follow-ups from issue #374 that PR #371 didn't cover. Rebased onto current main
(post-PR #371 merge) and folded in PR #375 review-comment fixes for jq injection,
memory efficiency, ACTOR forwarding, and pagination cap.

1. `resolve_actor_outdated_threads` — script-level safety net.
   The no-changes path used to rely on the agent to call `resolveReviewThread`.
   When the agent decided "no code change needed because already fixed," it tended
   to skip the resolve step, leaving outdated threads stuck open (e.g. PR #366's
   Copilot and ChatGPT-Codex threads). New helper queries reviewThreads,
   filters for `isResolved=false AND isOutdated=true AND author matches ACTOR`
   (with the GitHub Actions `[bot]` suffix optionally stripped to match
   GraphQL's `author.login`), and resolves each. Best-effort: failures emit
   warnings but don't fail the script. Wired into the no-changes branches of
   `fix-reviews`, `fix-bot-comment`, and `review-changes`.

   - ACTOR is passed via jq's `--arg` (gh's --jq does not accept --arg, so we
     pipe gh's output into jq directly) so a hostile actor value cannot escape
     the filter (gemini security-medium).
   - `reviewThreads(first:100)` — bumped from 50 to the GraphQL single-page max
     (copilot finding). Full cursor pagination is overkill for a safety net.
   - Workflow's review-changes step now sets `ACTOR: env.INTENT_ACTOR` so the
     helper can scrub outdated threads in the no-changes branch (was missing).
   - fix-reviews handler derives ACTOR from TRIGGERING_REVIEWER when not
     explicitly set, so the helper works without further workflow changes.

2. `read_session_summary` — marker-based extraction.
   The prior `tail -30 | sed | tail -10` assumed the agent's structured summary
   landed in the last 30 lines. When the agent ran many tool calls and emitted
   long trailing output, the summary was off-window and the helper returned
   empty, leaving the no-changes comment with only the fallback message
   instead of the agent's actual reasoning.

   Rewritten with `grep -nE` to find the last known output header
   (`Bot:`, `PR: #`, `Addressed N threads:`, `Human review threads addressed:`,
   `Issues addressed:`) and `sed -n "${mark},\$p"` to emit from there to EOF,
   capped at 30 non-blank lines. Falls back to the prior tail-window behaviour
   when no marker is present. Uses grep/sed rather than awk to avoid loading
   the full log into a memory array (gemini medium finding); redundant
   `head -30` removed.

   Redaction runs before the marker search, so PEM blocks straddling the kept
   window are still fully scrubbed (no header/body leakage across the
   boundary).

Tests: 33 fix-reviews tests (5 new — buried summary extraction, tail fallback,
dry-run announce, [bot]-stripped match, ACTOR-unset skip). 33 engine writer
tests unchanged. shellcheck clean.

Closes #374

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…ession summary (#375)

Two follow-ups from issue #374 that PR #371 didn't cover. Rebased onto current main
(post-PR #371 merge) and folded in PR #375 review-comment fixes for jq injection,
memory efficiency, ACTOR forwarding, and pagination cap.

1. `resolve_actor_outdated_threads` — script-level safety net.
   The no-changes path used to rely on the agent to call `resolveReviewThread`.
   When the agent decided "no code change needed because already fixed," it tended
   to skip the resolve step, leaving outdated threads stuck open (e.g. PR #366's
   Copilot and ChatGPT-Codex threads). New helper queries reviewThreads,
   filters for `isResolved=false AND isOutdated=true AND author matches ACTOR`
   (with the GitHub Actions `[bot]` suffix optionally stripped to match
   GraphQL's `author.login`), and resolves each. Best-effort: failures emit
   warnings but don't fail the script. Wired into the no-changes branches of
   `fix-reviews`, `fix-bot-comment`, and `review-changes`.

   - ACTOR is passed via jq's `--arg` (gh's --jq does not accept --arg, so we
     pipe gh's output into jq directly) so a hostile actor value cannot escape
     the filter (gemini security-medium).
   - `reviewThreads(first:100)` — bumped from 50 to the GraphQL single-page max
     (copilot finding). Full cursor pagination is overkill for a safety net.
   - Workflow's review-changes step now sets `ACTOR: env.INTENT_ACTOR` so the
     helper can scrub outdated threads in the no-changes branch (was missing).
   - fix-reviews handler derives ACTOR from TRIGGERING_REVIEWER when not
     explicitly set, so the helper works without further workflow changes.

2. `read_session_summary` — marker-based extraction.
   The prior `tail -30 | sed | tail -10` assumed the agent's structured summary
   landed in the last 30 lines. When the agent ran many tool calls and emitted
   long trailing output, the summary was off-window and the helper returned
   empty, leaving the no-changes comment with only the fallback message
   instead of the agent's actual reasoning.

   Rewritten with `grep -nE` to find the last known output header
   (`Bot:`, `PR: #`, `Addressed N threads:`, `Human review threads addressed:`,
   `Issues addressed:`) and `sed -n "${mark},\$p"` to emit from there to EOF,
   capped at 30 non-blank lines. Falls back to the prior tail-window behaviour
   when no marker is present. Uses grep/sed rather than awk to avoid loading
   the full log into a memory array (gemini medium finding); redundant
   `head -30` removed.

   Redaction runs before the marker search, so PEM blocks straddling the kept
   window are still fully scrubbed (no header/body leakage across the
   boundary).

Tests: 33 fix-reviews tests (5 new — buried summary extraction, tail fallback,
dry-run announce, [bot]-stripped match, ACTOR-unset skip). 33 engine writer
tests unchanged. shellcheck clean.

Closes #374

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 2, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 3, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 7, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Aug 8, 2026
…redaction (#371)

Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction.

Changes vs. main:
- scripts/dev-lead-fix-reviews.sh:
  - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS,
    Google API/OAuth, generic Bearer, and full PEM private-key blocks
    (range-replacement with sed c\, not just the header line).
  - read_session_summary now redacts *before* tailing so PEM blocks that
    straddle the tail-30 boundary cannot leak body or footer lines.
  - post_no_changes adds pick_fence and escapes literal </details> so
    untrusted agent output cannot break the wrapping <details> block.
  - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the
    prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for
    coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix).

- scripts/engine.sh:
  - Redacts session output once at write time, persists the scrubbed
    copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted
    file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials
    survive in either location.
  - Clears any stale /tmp file from a prior run before writing, and
    truncates if the redact/persist pipeline fails — read_session_summary
    cannot pick up the previous run's content.

- prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw
  ACTOR string and the [bot]-stripped form so threads from
  coderabbitai/chatgpt-codex/copilot get resolved.

Test coverage: 33 engine tests (5 new — token redact, API-key step
summary, full PEM persistence, stale overwrite, HTML escape) and 28
fix-reviews tests (5 new — straddle-PEM redaction, fence growth,
</details> escape, agent reasoning embed, GH-token redact). shellcheck
clean.

Co-authored-by: Gemini CLI <gemini-cli@example.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants