fix(dev-lead): visible no-changes comments, ACTOR for fix-reviews, bot login mismatch - #371
Conversation
|
Warning Review limit reached
Your plan currently allows 1 review/hour. Refill in 20 minutes and 8 seconds. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more review capacity refills, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than trial, open-source, and free plans. In all cases, review capacity refills continuously over time. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (5)
📝 WalkthroughWalkthroughThe PR enhances the dev-lead agent's session handling by persisting captured output through a shared file, redacting sensitive credentials, and including agent reasoning in terminal no-changes reports. It also hardens bot-author matching to handle GraphQL's inconsistent ChangesSession Output Persistence and Redaction
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related issues
Possibly related PRs
Suggested labels
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
No description provided. |
There was a problem hiding this comment.
Pull request overview
This PR fixes several dev-lead workflow/script issues observed in PR runs by ensuring “no-changes” outcomes produce a visible, informative PR comment; ensuring ACTOR is forwarded into fix-reviews; and correcting bot author matching where GitHub Actions includes a [bot] suffix but GraphQL omits it.
Changes:
- Add
read_session_summary+post_no_changesto always post a visible no-changes comment body (fallback text or session-log tail). - Persist writer session output to
/tmp/dev-lead-session-output.txtand (when available) append it toGITHUB_STEP_SUMMARY. - Forward
ACTORinto thefix-reviewsstep and update bot-thread matching to handle[bot]suffix differences.
Reviewed changes
Copilot reviewed 7 out of 7 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
scripts/dev-lead-fix-reviews.sh |
Adds helpers to include a visible summary (fallback or session tail) in no-changes terminal comments; exports ACTOR for fix-reviews. |
scripts/engine.sh |
Persists writer output to /tmp/dev-lead-session-output.txt and appends it to the step summary for visibility/debugging. |
.github/workflows/dev-lead.yml |
Passes ACTOR into the fix-reviews job step environment. |
prompts/dev-lead/fix-reviews.md |
Declares ACTOR as a prompt variable and documents [bot] suffix differences for thread ownership decisions. |
prompts/dev-lead/fix-bot-comment.md |
Updates jq filtering guidance to match bot logins with/without [bot] suffix. |
tests/dev-lead/unit/test_fix_reviews.bats |
Updates/adds tests to validate visible no-changes comment output (fallback + session log). |
tests/dev-lead/unit/test_engine_writer.bats |
Adds coverage for session-output persistence to /tmp/dev-lead-session-output.txt. |
Superseded by automated re-review at
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7ce85dc37c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
Code Review
This pull request enhances the dev-lead agent's handling of bot logins and improves transparency when no actionable items are found. Key changes include updating GraphQL queries to match bot logins with or without the '[bot]' suffix, persisting session logs to a temporary file, and including agent reasoning in the GitHub Step Summary and PR comments. Feedback was provided regarding the potential for raw agent output to break HTML rendering in the GitHub Step Summary, suggesting the use of code blocks for better isolation.
…njection Rebase + review feedback addressed on top of #371's original intent. Changes vs. main: - engine.sh now persists writer session output to /tmp/dev-lead-session-output.txt and to GITHUB_STEP_SUMMARY with HTML-escaped content inside a <pre> block, so literal </details> in agent output cannot break the wrapping <details> on the run summary page (Gemini medium finding). - dev-lead-fix-reviews.sh adds redact_secrets, read_session_summary, pick_fence, and post_no_changes. Secrets matching common token formats (GitHub PAT, Anthropic/OpenAI keys, AWS, Google OAuth, bearer tokens, PEM private keys) are scrubbed before the session tail is published to a PR comment (ChatGPT-Codex P1 finding). The wrapping ~~~~ fence is grown to outrun any tilde sequence in the content (review-agent INFO finding), and literal </details> in content is escaped so it cannot terminate the outer block. - All three remaining bare 'no-changes' call sites (fix-reviews, fix-bot-comment, rebase) now use post_no_changes — the bug that originally motivated #371. - TRIGGERING_REVIEWER is normalised by stripping any trailing [bot] suffix so it matches GraphQL's author.login form. Without this, the fix-reviews.md constraint 'author.login == ${TRIGGERING_REVIEWER}' never matched bot threads. - fix-bot-comment.md jq filter updated to match author.login against both the raw ACTOR and ACTOR with [bot] stripped. - 7 new bats tests: session output persistence, GITHUB_STEP_SUMMARY HTML escape, fallback comment body, agent-reasoning capture, GH token redaction, pick_fence tilde-overrun, </details> neutralisation. Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
7ce85dc to
74ecfa3
Compare
…njection Rebase + review feedback addressed on top of #371's original intent. Changes vs. main: - engine.sh now persists writer session output to /tmp/dev-lead-session-output.txt and to GITHUB_STEP_SUMMARY with HTML-escaped content inside a <pre> block, so literal </details> in agent output cannot break the wrapping <details> on the run summary page (Gemini medium finding). - dev-lead-fix-reviews.sh adds redact_secrets, read_session_summary, pick_fence, and post_no_changes. Secrets matching common token formats (GitHub PAT, Anthropic/OpenAI keys, AWS, Google OAuth, bearer tokens, PEM private keys) are scrubbed before the session tail is published to a PR comment (ChatGPT-Codex P1 finding). The wrapping ~~~~ fence is grown to outrun any tilde sequence in the content (review-agent INFO finding), and literal </details> in content is escaped so it cannot terminate the outer block. - All three remaining bare 'no-changes' call sites (fix-reviews, fix-bot-comment, rebase) now use post_no_changes — the bug that originally motivated #371. - TRIGGERING_REVIEWER is normalised by stripping any trailing [bot] suffix so it matches GraphQL's author.login form. Without this, the fix-reviews.md constraint 'author.login == ${TRIGGERING_REVIEWER}' never matched bot threads. - fix-bot-comment.md jq filter updated to match author.login against both the raw ACTOR and ACTOR with [bot] stripped. - 7 new bats tests: session output persistence, GITHUB_STEP_SUMMARY HTML escape, fallback comment body, agent-reasoning capture, GH token redaction, pick_fence tilde-overrun, </details> neutralisation. Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
74ecfa3 to
fbb7230
Compare
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: fbb723034f81078e82661026619984b117ccd2ac
Review mode: triage-approved (single reviewer)
Summary
Focused dev-lead bug fix PR that the triage tier already cleared as low-risk. The new head SHA addresses the prior review's findings: the merge conflict is resolved (mergeable=MERGEABLE), the tilde-fence overrun edge case is handled by the new pick_fence helper, and defense-in-depth credential redaction was added before session output is published to PR comments. HTML escaping of </details> and < in the GitHub step summary closes a related output-integrity issue raised by Gemini.
Linked issue analysis
No linked issues. PR body cleanly describes the three motivating bugs observed on PR #366 runs and the additional review-feedback items rolled in on rebase.
Findings
- No blocking issues found.
redact_secretsregex covers GitHub tokens (gh[opsu]/ghr/github_pat_), OpenAI/Anthropic (sk-/sk-ant-), AWS access keys (AKIA), Google (AIza/ya29.), bearer tokens, and PEM private-key headers — reasonable defense-in-depth before publishing session tails to PR comments.- HTML escaping in
engine.shuses correct ordering (&first, then</>) so the wrapping<details>on the run summary page cannot be broken by literal HTML in agent output. </details>neutralisation inpost_no_changes(replaces with<\/details>) will render the backslash literally to readers, but it is acceptable given that the alternative is a broken collapsible block.- Bot login suffix handling — both the jq filter in
fix-bot-comment.mdand theTRIGGERING_REVIEWERnormalisation indev-lead-fix-reviews.shcorrectly bridge the GitHub Actions actor form (with[bot]) to the GraphQLauthor.loginform (without). - Tests: 7 new bats cases exercise the new helpers (session persistence, GITHUB_STEP_SUMMARY HTML escape, fallback body, agent-reasoning body, GH token redaction,
pick_fenceoverrun,</details>neutralisation).
CI status
All 22 checks SUCCESS or SKIPPED — CodeQL, AgentShield, Agent Security Scan, gitleaks, ShellCheck, bats, unit-tests, SonarCloud (Quality Gate passed, 0 new issues), Lint, dependency-audit (skipped per ecosystem), Compile agentic workflows, validate-agent-profiles, gh-aw-compile. Dependabot check skipped as expected. No CI failures or security warnings.
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@scripts/dev-lead-fix-reviews.sh`:
- Around line 95-103: Current redaction only replaces the "-----BEGIN ...
PRIVATE KEY-----" line and leaves the PEM body and the "END" line exposed;
update the script's private-key redaction to remove the entire PEM block between
the BEGIN and END markers. Replace the single-line sed regex '-----BEGIN [A-Z
]*PRIVATE KEY-----' with a multiline-safe replacement (e.g., use perl -0777 -pe
or sed -z) that matches /-----BEGIN [A-Z ]*PRIVATE KEY-----.*?-----END [A-Z
]*PRIVATE KEY-----/s and substitutes the whole block with a single placeholder
like '***REDACTED-PRIVATE-KEY***' so both the header, body, and footer are
redacted (apply this change where the current sed invocation and the '-----BEGIN
[A-Z ]*PRIVATE KEY-----' pattern appear).
- Around line 111-137: The conditional tests using single-bracket [ ... ] in
helper functions should be converted to bash-style double-bracket tests [[ ...
]] to match repo standards: update read_session_summary (the line using [ -f
"$log" ] || return 0) to use [[ -f $log ]] || return 0 (preserve
quoting/word-safety as appropriate) and update post_no_changes (the if [ -n
"$_summary" ]; then) to if [[ -n $_summary ]]; then; also scan other helper
functions like pick_fence for any remaining [ ... ] usages and replace them with
[[ ... ]] while keeping the same test semantics and variable quoting where
necessary.
In `@scripts/engine.sh`:
- Around line 598-600: When the copy of "$_tmp" to
/tmp/dev-lead-session-output.txt fails the old target can persist and leak into
read_session_summary; change the failure branch for the cp command so it removes
or truncates /tmp/dev-lead-session-output.txt (e.g. rm -f
/tmp/dev-lead-session-output.txt or : > /tmp/dev-lead-session-output.txt)
instead of only emitting a warning, keeping the existing rm -f "$_tmp" behavior
afterward.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 3a21a6a3-0c5a-439e-9570-cf4e46735438
📒 Files selected for processing (5)
prompts/dev-lead/fix-bot-comment.mdscripts/dev-lead-fix-reviews.shscripts/engine.shtests/dev-lead/unit/test_engine_writer.batstests/dev-lead/unit/test_fix_reviews.bats
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fbb723034f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@coderabbitai resolve |
✅ Actions performedComments resolved and changes approved. |
Dev-Lead — rate-limited (intent: fix-reviews)PR: #371 |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f53d80fa8d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Dev-Lead — rate-limited (intent: fix-reviews)PR: #371 |
f53d80f to
f8677c0
Compare
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: f8677c012e44d5986efef34fece50a043b1dbcc3
Review mode: triage-approved (single reviewer)
Summary
Triage cleared this dev-lead bug-fix PR as low-risk; confirmation review agrees. The new head SHA addresses CodeRabbit's three findings on the prior commit (full PEM-block redaction via sed range c\, stale session-file guard with rm -f + cp-failure truncation, and [[ ]] conditionals). All 22 CI checks pass and the changes are well-tested with 7 new bats cases. No security, correctness, or maintainability concerns.
Linked issue analysis
No linked issues. PR body describes three motivating bugs observed on PR #366 runs (empty no-changes comments, missing ACTOR forwarding, bot [bot] suffix mismatch) plus the additional review-feedback items addressed during rebase.
Findings
- No blocking issues found.
- PEM-block redaction (Critical fix from CodeRabbit) —
redact_secretsnow uses sed range/-----BEGIN .../,/-----END .../c\so the entire multi-line PEM block is replaced, not just the BEGIN header. New bats test confirms body/footer lines no longer leak. (scripts/dev-lead-fix-reviews.sh:103) - Stale session-output guard (Major fix from CodeRabbit) —
engine.shnowrm -f /tmp/dev-lead-session-output.txtbeforecp, and truncates on cp failure, so a prior run's content cannot be read by the nextread_session_summarycall. New bats test pre-populates the file withSTALE_CONTENT_FROM_PRIOR_RUNand asserts replacement. (scripts/engine.sh:601-605) - Bash conventions (Minor fix from CodeRabbit) — new helpers
read_session_summaryandpost_no_changesuse[[ ]]per reposhell.instructions.md. (scripts/dev-lead-fix-reviews.sh:114, 130) - Bot login suffix handling — both the jq filter in
fix-bot-comment.mdandTRIGGERING_REVIEWERnormalisation indev-lead-fix-reviews.shcorrectly bridge the GitHub Actions actor form (with[bot]) to the GraphQLauthor.loginform (without). - HTML escaping —
engine.shuses correct ordering (&first, then</>) so literal HTML in agent output cannot break the wrapping<details>on the run summary page. - Tests — 7 new bats cases exercise session persistence, GITHUB_STEP_SUMMARY HTML escape, stale-file overwrite, fallback body, agent-reasoning body, GH-token redaction, full PEM-block redaction,
pick_fencetilde-overrun, and</details>neutralisation. Test fixtures correctly avoid literal secret/PEM patterns to dodge our own gitleaks check.
CI status
All 22 checks SUCCESS or SKIPPED — CodeQL (Actions + general), AgentShield, Agent Security Scan, gitleaks, ShellCheck, bats, unit-tests, SonarCloud (Quality Gate passed, 0 new issues), Lint, dependency-audit (skipped per ecosystem), Compile agentic workflows, validate-agent-profiles, gh-aw-compile. Dependabot and pr-review-mention skipped as expected. No CI failures or security warnings. mergeStateStatus=BLOCKED reflects pending approval, not a merge conflict (mergeable=MERGEABLE).
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.
|
Auto-rebase failed — merge conflict — this branch has conflicts with Claude will attempt to resolve this automatically. If it cannot, a follow-up comment will explain what needs manual attention. To resolve manually instead: |
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ession summary (#375) Two follow-ups from issue #374 that PR #371 didn't cover. Rebased onto current main (post-PR #371 merge) and folded in PR #375 review-comment fixes for jq injection, memory efficiency, ACTOR forwarding, and pagination cap. 1. `resolve_actor_outdated_threads` — script-level safety net. The no-changes path used to rely on the agent to call `resolveReviewThread`. When the agent decided "no code change needed because already fixed," it tended to skip the resolve step, leaving outdated threads stuck open (e.g. PR #366's Copilot and ChatGPT-Codex threads). New helper queries reviewThreads, filters for `isResolved=false AND isOutdated=true AND author matches ACTOR` (with the GitHub Actions `[bot]` suffix optionally stripped to match GraphQL's `author.login`), and resolves each. Best-effort: failures emit warnings but don't fail the script. Wired into the no-changes branches of `fix-reviews`, `fix-bot-comment`, and `review-changes`. - ACTOR is passed via jq's `--arg` (gh's --jq does not accept --arg, so we pipe gh's output into jq directly) so a hostile actor value cannot escape the filter (gemini security-medium). - `reviewThreads(first:100)` — bumped from 50 to the GraphQL single-page max (copilot finding). Full cursor pagination is overkill for a safety net. - Workflow's review-changes step now sets `ACTOR: env.INTENT_ACTOR` so the helper can scrub outdated threads in the no-changes branch (was missing). - fix-reviews handler derives ACTOR from TRIGGERING_REVIEWER when not explicitly set, so the helper works without further workflow changes. 2. `read_session_summary` — marker-based extraction. The prior `tail -30 | sed | tail -10` assumed the agent's structured summary landed in the last 30 lines. When the agent ran many tool calls and emitted long trailing output, the summary was off-window and the helper returned empty, leaving the no-changes comment with only the fallback message instead of the agent's actual reasoning. Rewritten with `grep -nE` to find the last known output header (`Bot:`, `PR: #`, `Addressed N threads:`, `Human review threads addressed:`, `Issues addressed:`) and `sed -n "${mark},\$p"` to emit from there to EOF, capped at 30 non-blank lines. Falls back to the prior tail-window behaviour when no marker is present. Uses grep/sed rather than awk to avoid loading the full log into a memory array (gemini medium finding); redundant `head -30` removed. Redaction runs before the marker search, so PEM blocks straddling the kept window are still fully scrubbed (no header/body leakage across the boundary). Tests: 33 fix-reviews tests (5 new — buried summary extraction, tail fallback, dry-run announce, [bot]-stripped match, ACTOR-unset skip). 33 engine writer tests unchanged. shellcheck clean. Closes #374 Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…ession summary (#375) Two follow-ups from issue #374 that PR #371 didn't cover. Rebased onto current main (post-PR #371 merge) and folded in PR #375 review-comment fixes for jq injection, memory efficiency, ACTOR forwarding, and pagination cap. 1. `resolve_actor_outdated_threads` — script-level safety net. The no-changes path used to rely on the agent to call `resolveReviewThread`. When the agent decided "no code change needed because already fixed," it tended to skip the resolve step, leaving outdated threads stuck open (e.g. PR #366's Copilot and ChatGPT-Codex threads). New helper queries reviewThreads, filters for `isResolved=false AND isOutdated=true AND author matches ACTOR` (with the GitHub Actions `[bot]` suffix optionally stripped to match GraphQL's `author.login`), and resolves each. Best-effort: failures emit warnings but don't fail the script. Wired into the no-changes branches of `fix-reviews`, `fix-bot-comment`, and `review-changes`. - ACTOR is passed via jq's `--arg` (gh's --jq does not accept --arg, so we pipe gh's output into jq directly) so a hostile actor value cannot escape the filter (gemini security-medium). - `reviewThreads(first:100)` — bumped from 50 to the GraphQL single-page max (copilot finding). Full cursor pagination is overkill for a safety net. - Workflow's review-changes step now sets `ACTOR: env.INTENT_ACTOR` so the helper can scrub outdated threads in the no-changes branch (was missing). - fix-reviews handler derives ACTOR from TRIGGERING_REVIEWER when not explicitly set, so the helper works without further workflow changes. 2. `read_session_summary` — marker-based extraction. The prior `tail -30 | sed | tail -10` assumed the agent's structured summary landed in the last 30 lines. When the agent ran many tool calls and emitted long trailing output, the summary was off-window and the helper returned empty, leaving the no-changes comment with only the fallback message instead of the agent's actual reasoning. Rewritten with `grep -nE` to find the last known output header (`Bot:`, `PR: #`, `Addressed N threads:`, `Human review threads addressed:`, `Issues addressed:`) and `sed -n "${mark},\$p"` to emit from there to EOF, capped at 30 non-blank lines. Falls back to the prior tail-window behaviour when no marker is present. Uses grep/sed rather than awk to avoid loading the full log into a memory array (gemini medium finding); redundant `head -30` removed. Redaction runs before the marker search, so PEM blocks straddling the kept window are still fully scrubbed (no header/body leakage across the boundary). Tests: 33 fix-reviews tests (5 new — buried summary extraction, tail fallback, dry-run announce, [bot]-stripped match, ACTOR-unset skip). 33 engine writer tests unchanged. shellcheck clean. Closes #374 Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
…redaction (#371) Rebases PR #371 onto current main (post-PR #366 merge) and folds in review-comment fixes for credential redaction. Changes vs. main: - scripts/dev-lead-fix-reviews.sh: - Adds redact_secrets covering GitHub PAT/token, OpenAI/Anthropic, AWS, Google API/OAuth, generic Bearer, and full PEM private-key blocks (range-replacement with sed c\, not just the header line). - read_session_summary now redacts *before* tailing so PEM blocks that straddle the tail-30 boundary cannot leak body or footer lines. - post_no_changes adds pick_fence and escapes literal </details> so untrusted agent output cannot break the wrapping <details> block. - Strips a trailing "[bot]" suffix from TRIGGERING_REVIEWER so the prompt's `author.login == ${TRIGGERING_REVIEWER}` match works for coderabbitai / chatgpt-codex / etc. (GraphQL omits the suffix). - scripts/engine.sh: - Redacts session output once at write time, persists the scrubbed copy to /tmp/dev-lead-session-output.txt, and feeds the same redacted file (HTML-escaped) into GITHUB_STEP_SUMMARY. No raw credentials survive in either location. - Clears any stale /tmp file from a prior run before writing, and truncates if the redact/persist pipeline fails — read_session_summary cannot pick up the previous run's content. - prompts/dev-lead/fix-bot-comment.md: jq filter matches both the raw ACTOR string and the [bot]-stripped form so threads from coderabbitai/chatgpt-codex/copilot get resolved. Test coverage: 33 engine tests (5 new — token redact, API-key step summary, full PEM persistence, stale overwrite, HTML escape) and 28 fix-reviews tests (5 new — straddle-PEM redaction, fence growth, </details> escape, agent reasoning embed, GH-token redact). shellcheck clean. Co-authored-by: Gemini CLI <gemini-cli@example.com> Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Summary
Three bugs diagnosed from observing PR #366 runs:
Empty no-changes comments — all intent handlers called
post_reviews_terminal "X" "no-changes"with no summary arg, producing an invisible HTML-only marker body. Addedread_session_summary+post_no_changeshelpers that attach the agent's session tail (or a plain fallback) to every no-changes comment. Also backports the engine.sh session-output persistence from feat: implement issue #365 — dev-lead: preserve session output in Actions logs and surface agent reasoning in no-changes comments #366 (copy_tmp→/tmp/dev-lead-session-output.txt+GITHUB_STEP_SUMMARY).ACTOR not forwarded to
fix-reviews— the workflow step and the script'sfix-reviewshandler both lackedACTOR, making the "only resolve threads from the triggering reviewer" constraint unenforceable. AddedACTOR: ${{ env.INTENT_ACTOR }}to the step env andexport ACTORin the handler.Bot
[bot]suffix mismatch infix-bot-comment— GitHub Actions setsACTORwith the[bot]suffix (e.g.chatgpt-codex-connector[bot]) while GraphQL'sauthor.loginomits it. The jq filter used a strict==comparison, so threads from bots like chatgpt-codex and coderabbitai were never found and never resolved. Updated the filter infix-bot-comment.mdto match both the raw and[bot]-stripped form.Test plan
bats tests/dev-lead/unit/test_fix_reviews.bats— all 23 tests pass (2 updated, 2 new)bats tests/dev-lead/unit/test_engine_writer.bats— all 28 tests pass (1 new: session file persistence)fix-bot-commentno-changes run on a PR — comment should show "No actionable items found." or agent reasoning instead of blank🤖 Generated with Claude Code
Summary by CodeRabbit
Release Notes
New Features
Bug Fixes
Tests