Repository navigation
fix(pr-review): checkout agent repo explicitly for consumer callers (#536) - #538
Conversation
) The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it cloned the CALLER's repo at agent_ref. That accidentally worked for self-host (caller == .github-private) but fails for consumers: invoked from markets it tried markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure. Pin repository: petry-projects/.github-private (public → default token can read it) and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no target-repo checkout. No change for self-host (was already .github-private). Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
📝 WalkthroughWalkthroughThe workflow's "Checkout agent repo" step is updated to explicitly default the ChangesAgent checkout default branch
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Possibly related issues
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
There was a problem hiding this comment.
Pull request overview
This PR fixes a failure mode when .github/workflows/pr-review.yml is invoked as a reusable workflow from consumer repositories: the workflow now explicitly checks out the agent scripts repository (petry-projects/.github-private) instead of implicitly checking out the caller repo (which can’t satisfy refs like pr-review/stable).
Changes:
- Update the “Checkout agent repo” step to set
repository: petry-projects/.github-private. - Adjust the checkout
refselection logic foragent_ref(with a default fallback) and expand inline documentation explaining the consumer-repo failure scenario.
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.github/workflows/pr-review.yml (1)
6-16:⚠️ Potential issue | 🟡 Minor | ⚡ Quick winUpdate the input description to reflect the new default behavior.
The comment at lines 11-12 states that empty
agent_ref"preserves the historical behaviour exactly: actions/checkout treats an empty ref as 'default'", but the implementation at line 184 now explicitly defaults to'main'whenagent_refis empty (${{ inputs.agent_ref || 'main' }}). This is a behavior change from letting actions/checkout choose its default branch.📝 Suggested fix to align the input description with the implementation
# The .github-private ref to check out for the agent's own scripts # (engine.sh, review-one-pr.sh, …). A trigger-stub caller passes its # pinned channel (e.g. pr-review/stable) so the SCRIPTS run at the # pinned version, not the caller's branch — closing the reusable - # self-ref gap (`#506`). Empty (the default) preserves the historical - # behaviour exactly: actions/checkout treats an empty ref as "default". + # self-ref gap (`#506`). Empty (the default) uses 'main' to ensure + # a consistent baseline when no specific ref is pinned (`#506/`#536). description: "Ref of petry-projects/.github-private to check out for agent scripts"🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/pr-review.yml around lines 6 - 16, The input description for agent_ref is out of sync with the implementation: the workflow uses the expression `${{ inputs.agent_ref || 'main' }}` so an empty agent_ref no longer defers to actions/checkout's default but explicitly falls back to 'main'; update the description for the agent_ref input to state that an empty value will default to 'main' (reference the agent_ref input and the `${{ inputs.agent_ref || 'main' }}` fallback) so docs match the actual behavior.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In @.github/workflows/pr-review.yml:
- Around line 6-16: The input description for agent_ref is out of sync with the
implementation: the workflow uses the expression `${{ inputs.agent_ref || 'main'
}}` so an empty agent_ref no longer defers to actions/checkout's default but
explicitly falls back to 'main'; update the description for the agent_ref input
to state that an empty value will default to 'main' (reference the agent_ref
input and the `${{ inputs.agent_ref || 'main' }}` fallback) so docs match the
actual behavior.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 5c379bad-55b3-4ea8-b95d-d6ea1aa58cf6
📒 Files selected for processing (1)
.github/workflows/pr-review.yml
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
) (#538) The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it cloned the CALLER's repo at agent_ref. That accidentally worked for self-host (caller == .github-private) but fails for consumers: invoked from markets it tried markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure. Pin repository: petry-projects/.github-private (public → default token can read it) and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no target-repo checkout. No change for self-host (was already .github-private). Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable. Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
) (#538) The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it cloned the CALLER's repo at agent_ref. That accidentally worked for self-host (caller == .github-private) but fails for consumers: invoked from markets it tried markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure. Pin repository: petry-projects/.github-private (public → default token can read it) and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no target-repo checkout. No change for self-host (was already .github-private). Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable. Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
) (#538) The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it cloned the CALLER's repo at agent_ref. That accidentally worked for self-host (caller == .github-private) but fails for consumers: invoked from markets it tried markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure. Pin repository: petry-projects/.github-private (public → default token can read it) and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no target-repo checkout. No change for self-host (was already .github-private). Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable. Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
) (#538) The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it cloned the CALLER's repo at agent_ref. That accidentally worked for self-host (caller == .github-private) but fails for consumers: invoked from markets it tried markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure. Pin repository: petry-projects/.github-private (public → default token can read it) and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no target-repo checkout. No change for self-host (was already .github-private). Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable. Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
) (#538) The 'Checkout agent repo' step set ref: inputs.agent_ref but no repository, so it cloned the CALLER's repo at agent_ref. That accidentally worked for self-host (caller == .github-private) but fails for consumers: invoked from markets it tried markets@pr-review/stable (no such ref) → 'Checkout agent repo' failure. Pin repository: petry-projects/.github-private (public → default token can read it) and ref: agent_ref || 'main'. Scripts always come from the agent repo regardless of which repo's PRs are reviewed; review-one-pr.sh operates via the gh API and needs no target-repo checkout. No change for self-host (was already .github-private). Surfaced by ring-1 consumer validation (markets). Promote via pr-review/stable. Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>



Caught by ring-1 (markets). The reusable's 'Checkout agent repo' step had
ref: agent_refbut norepository:, so it cloned the caller's repo — fine for self-host (caller is .github-private), but for a consumer (markets) it triedmarkets@pr-review/stable(no such ref) → checkout failure.Fix:
repository: petry-projects/.github-private(public → default token reads it) +ref: agent_ref || 'main'. Scripts always come from the agent repo; review-one-pr.sh uses the gh API, no target checkout needed. No self-host change.After merge: cut
pr-review/v1.5.0, movestable, re-validate markets#261. Part of #536 · #497 · epic #495.Summary by CodeRabbit