Skip to content

fix(pr-review): checkout agent repo explicitly for consumer callers (#536) - #538

Merged
don-petry merged 1 commit into
mainfrom
fix/checkout-agent-repo-explicit
Jun 10, 2026
Merged

don-petry merged 1 commit into
mainfrom
fix/checkout-agent-repo-explicit

Conversation

@don-petry

@don-petry don-petry commented Jun 10, 2026 •

Copy link
Copy Markdown
Collaborator

Caught by ring-1 (markets). The reusable's 'Checkout agent repo' step had ref: agent_ref but no repository:, so it cloned the caller's repo — fine for self-host (caller is .github-private), but for a consumer (markets) it tried markets@pr-review/stable (no such ref) → checkout failure.

Fix: repository: petry-projects/.github-private (public → default token reads it) + ref: agent_ref || 'main'. Scripts always come from the agent repo; review-one-pr.sh uses the gh API, no target checkout needed. No self-host change.

After merge: cut pr-review/v1.5.0, move stable, re-validate markets#261. Part of #536 · #497 · epic #495.

Summary by CodeRabbit

  • Chores
    • Updated internal workflow configuration to improve default branch handling for agent scripts during pull request reviews.

)

The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it
cloned the CALLER's repo at agent_ref. That accidentally worked for self-host
(caller == .github-private) but fails for consumers: invoked from markets it tried
markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure.

Pin repository: petry-projects/.github-private (public → default token can read it)
and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of
which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no
target-repo checkout. No change for self-host (was already .github-private).

Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@don-petry
don-petry requested a review from a team as a code owner June 10, 2026 03:54
@don-petry don-petry added the initiative Epic / initiative tracking issue label Jun 10, 2026
Copilot AI review requested due to automatic review settings June 10, 2026 03:54
@don-petry don-petry added the initiative Epic / initiative tracking issue label Jun 10, 2026
@gemini-code-assist

Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@coderabbitai

coderabbitai Bot commented Jun 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The workflow's "Checkout agent repo" step is updated to explicitly default the .github-private repository checkout ref to the main branch when inputs.agent_ref is not provided, replacing a bare input reference with a fallback expression and adjusting the inline comments to document this behavior.

Changes

Agent checkout default branch

Layer / File(s) Summary
Agent ref defaulting to main
.github/workflows/pr-review.yml
The actions/checkout ref for .github-private is changed from ${{ inputs.agent_ref }} to ${{ inputs.agent_ref || 'main' }} to ensure the workflow defaults to the main branch when agent_ref is empty, with expanded inline comments documenting this fallback behavior.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related issues

  • petry-projects/.github-private#506: Both changes involve the same actions/checkout step and handling of inputs.agent_ref, with this PR applying an explicit fallback to main when the input is empty.

Possibly related PRs

  • petry-projects/.github-private#513: This PR directly extends the agent_ref input wiring introduced by PR #513 by adding a fallback default when the input is not provided.
  • petry-projects/.github-private#74: Both PRs modify the same .github/workflows/pr-review.yml "Checkout agent repo" step, this one changing the ref default behavior and PR #74 pinning the actions/checkout action version.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and specifically summarizes the main change: fixing the agent repo checkout to be explicit for consumer callers. It directly relates to the changeset which updates the checkout step behavior.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/checkout-agent-repo-explicit

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@sonarqubecloud

Copy link
Copy Markdown

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
Files changed: none
Skipped (informational): 1 — Gemini reported it cannot review this PR
  due to unsupported file types (YAML/shell workflows); no actionable
  findings were raised and no open review threads exist from this bot.
```

@don-petry
don-petry enabled auto-merge (squash) June 10, 2026 03:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a failure mode when .github/workflows/pr-review.yml is invoked as a reusable workflow from consumer repositories: the workflow now explicitly checks out the agent scripts repository (petry-projects/.github-private) instead of implicitly checking out the caller repo (which can’t satisfy refs like pr-review/stable).

Changes:

  • Update the “Checkout agent repo” step to set repository: petry-projects/.github-private.
  • Adjust the checkout ref selection logic for agent_ref (with a default fallback) and expand inline documentation explaining the consumer-repo failure scenario.

Comment thread .github/workflows/pr-review.yml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/pr-review.yml (1)

6-16: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Update the input description to reflect the new default behavior.

The comment at lines 11-12 states that empty agent_ref "preserves the historical behaviour exactly: actions/checkout treats an empty ref as 'default'", but the implementation at line 184 now explicitly defaults to 'main' when agent_ref is empty (${{ inputs.agent_ref || 'main' }}). This is a behavior change from letting actions/checkout choose its default branch.

📝 Suggested fix to align the input description with the implementation
       # The .github-private ref to check out for the agent's own scripts
       # (engine.sh, review-one-pr.sh, …). A trigger-stub caller passes its
       # pinned channel (e.g. pr-review/stable) so the SCRIPTS run at the
       # pinned version, not the caller's branch — closing the reusable
-      # self-ref gap (`#506`). Empty (the default) preserves the historical
-      # behaviour exactly: actions/checkout treats an empty ref as "default".
+      # self-ref gap (`#506`). Empty (the default) uses 'main' to ensure
+      # a consistent baseline when no specific ref is pinned (`#506/`#536).
       description: "Ref of petry-projects/.github-private to check out for agent scripts"
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/pr-review.yml around lines 6 - 16, The input description
for agent_ref is out of sync with the implementation: the workflow uses the
expression `${{ inputs.agent_ref || 'main' }}` so an empty agent_ref no longer
defers to actions/checkout's default but explicitly falls back to 'main'; update
the description for the agent_ref input to state that an empty value will
default to 'main' (reference the agent_ref input and the `${{ inputs.agent_ref
|| 'main' }}` fallback) so docs match the actual behavior.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/pr-review.yml:
- Around line 6-16: The input description for agent_ref is out of sync with the
implementation: the workflow uses the expression `${{ inputs.agent_ref || 'main'
}}` so an empty agent_ref no longer defers to actions/checkout's default but
explicitly falls back to 'main'; update the description for the agent_ref input
to state that an empty value will default to 'main' (reference the agent_ref
input and the `${{ inputs.agent_ref || 'main' }}` fallback) so docs match the
actual behavior.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 5c379bad-55b3-4ea8-b95d-d6ea1aa58cf6

📥 Commits

Reviewing files that changed from the base of the PR and between 38448af and 7256075.

📒 Files selected for processing (1)
  • .github/workflows/pr-review.yml

@don-petry
don-petry disabled auto-merge June 10, 2026 03:58
@don-petry
don-petry merged commit 790e68b into main Jun 10, 2026
35 checks passed
@don-petry
don-petry deleted the fix/checkout-agent-repo-explicit branch June 10, 2026 03:59
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-reviews (applied)

Changes committed and pushed.

don-petry added a commit that referenced this pull request Jun 12, 2026
) (#538)

The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it
cloned the CALLER's repo at agent_ref. That accidentally worked for self-host
(caller == .github-private) but fails for consumers: invoked from markets it tried
markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure.

Pin repository: petry-projects/.github-private (public → default token can read it)
and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of
which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no
target-repo checkout. No change for self-host (was already .github-private).

Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable.

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 14, 2026
) (#538)

The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it
cloned the CALLER's repo at agent_ref. That accidentally worked for self-host
(caller == .github-private) but fails for consumers: invoked from markets it tried
markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure.

Pin repository: petry-projects/.github-private (public → default token can read it)
and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of
which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no
target-repo checkout. No change for self-host (was already .github-private).

Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable.

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 18, 2026
) (#538)

The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it
cloned the CALLER's repo at agent_ref. That accidentally worked for self-host
(caller == .github-private) but fails for consumers: invoked from markets it tried
markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure.

Pin repository: petry-projects/.github-private (public → default token can read it)
and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of
which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no
target-repo checkout. No change for self-host (was already .github-private).

Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable.

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
) (#538)

The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it
cloned the CALLER's repo at agent_ref. That accidentally worked for self-host
(caller == .github-private) but fails for consumers: invoked from markets it tried
markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure.

Pin repository: petry-projects/.github-private (public → default token can read it)
and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of
which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no
target-repo checkout. No change for self-host (was already .github-private).

Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable.

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
) (#538)

The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it
cloned the CALLER's repo at agent_ref. That accidentally worked for self-host
(caller == .github-private) but fails for consumers: invoked from markets it tried
markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure.

Pin repository: petry-projects/.github-private (public → default token can read it)
and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of
which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no
target-repo checkout. No change for self-host (was already .github-private).

Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable.

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

initiative Epic / initiative tracking issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants