fix(dev-lead): self-host pin to @dev-lead/stable + agent_ref (#535) - #554
Conversation
…ent_ref (#535) .github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a broken change to dev-lead on main instantly gated its own fix (the self-host circular dependency). Pin the caller to the dev-lead/stable channel and thread agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned version too (#506). Promotion is now a central tag move; this caller is never edited on release — mirrors the validated pr-review self-host pattern. dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does not regress ring-0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
|
Warning Review limit reached
More reviews will be available in 55 minutes and 16 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe workflow pins the reusable ChangesWorkflow reference pinning to dev-lead/stable
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Possibly related issues
Possibly related PRs
Suggested labels
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
This PR updates .github-private’s ring-0 dev-lead caller stub to run the reusable workflow from the pinned dev-lead/stable channel (instead of @main) and passes agent_ref: dev-lead/stable so the reusable’s internal checkout of .github-private scripts/prompts is pinned to the same ref, eliminating the self-hosting circular-dependency risk described in #506/#535.
Changes:
- Pin
.github/workflows/dev-lead.ymltodev-lead-reusable.yml@dev-lead/stable. - Thread
with: agent_ref: dev-lead/stableso dev-lead scripts/prompts checkout runs at the same pinned channel.
Dev-Lead — review-changes (applied)Changes committed and pushed. |
|
Dev-Lead — waiting on PR blockers (intent: review-changes)PR: #554 |
|
Note @don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically. |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: 532b4153aad81defa028900076e1a8c2feb76f3e
Review mode: triage-approved (single reviewer)
Summary
Pins .github-private's own dev-lead.yml thin caller stub from dev-lead-reusable.yml@main to @dev-lead/stable, and threads agent_ref: dev-lead/stable so the scripts/prompts checkout inside the reusable runs at the same channel. Closes the ring-0 self-host circular dependency (#535/#506). The integration test tests/dev-lead/integration/test_dev_lead_stub.sh is correctly updated to accept any dev-lead-reusable.yml@<ref> (not just @main), preserving the thin-caller-stub structural assertion.
Linked issue analysis
No closingIssuesReferences (PR description names #535 / #506 as motivation rather than via "Closes" syntax). Title and body describe the intent precisely; the diff matches that intent (workflow pin + test update — no scope creep, no inline logic regression).
Findings
No blocking findings.
.github/workflows/dev-lead.yml— switchesuses:from@mainto@dev-lead/stableand addswith: agent_ref: dev-lead/stable. This is explicitly the sanctioned mutable-ref exception documented in AGENTS.md §"Release channel tags & the mutable-ref exception" — first-party channel tags are the documented version-selection mechanism for in-repo reusable workflows, protected by therelease-channel-tagsruleset. Compliance audits must NOT flag this as an unpinned action.- Stub remains thin (no inline
run:blocks introduced). Permissions block,secrets: inherit, and the same-repoif:guard are untouched. - Pattern mirrors the validated pr-review self-host pin (#497/#523).
tests/dev-lead/integration/test_dev_lead_stub.sh— the regexdev-lead-reusable\.yml@\S+correctly accepts both@mainand channel tags like@dev-lead/stable. The fail message is updated to reflect the broader acceptance criterion. The "no inline run steps" assertion (step 3) is preserved.- PR body claim that
dev-lead/stablewas first advanced to v1.2.0 (= current main) before this pin is not directly verifiable from the diff, but is the necessary precondition for non-regression and is documented in the description.
Nit (non-blocking): none.
CI status
All checks green. 27 successful (CI/Lint/ShellCheck/bats, CodeQL actions+python, Agent Security Scan, gitleaks, AgentShield, SonarCloud, Dev-Lead dispatch, PR Review trigger, Test Dev-Lead Agent suite including stub-structure/caller-permissions/toplevel-permissions/concurrency-config, validate-agent-profiles, gh-aw-compile, etc.) and 6 cleanly skipped (dependabot, dependency-audit ecosystem matrix legs, dev-lead ci-relay). mergeable: MERGEABLE; mergeStateStatus: BLOCKED is purely from REVIEW_REQUIRED.
Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.
…554) * fix(dev-lead): pin .github-private self-host to @dev-lead/stable + agent_ref (#535) .github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a broken change to dev-lead on main instantly gated its own fix (the self-host circular dependency). Pin the caller to the dev-lead/stable channel and thread agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned version too (#506). Promotion is now a central tag move; this caller is never edited on release — mirrors the validated pr-review self-host pattern. dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does not regress ring-0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
…554) * fix(dev-lead): pin .github-private self-host to @dev-lead/stable + agent_ref (#535) .github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a broken change to dev-lead on main instantly gated its own fix (the self-host circular dependency). Pin the caller to the dev-lead/stable channel and thread agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned version too (#506). Promotion is now a central tag move; this caller is never edited on release — mirrors the validated pr-review self-host pattern. dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does not regress ring-0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
…554) * fix(dev-lead): pin .github-private self-host to @dev-lead/stable + agent_ref (#535) .github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a broken change to dev-lead on main instantly gated its own fix (the self-host circular dependency). Pin the caller to the dev-lead/stable channel and thread agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned version too (#506). Promotion is now a central tag move; this caller is never edited on release — mirrors the validated pr-review self-host pattern. dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does not regress ring-0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
…554) * fix(dev-lead): pin .github-private self-host to @dev-lead/stable + agent_ref (#535) .github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a broken change to dev-lead on main instantly gated its own fix (the self-host circular dependency). Pin the caller to the dev-lead/stable channel and thread agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned version too (#506). Promotion is now a central tag move; this caller is never edited on release — mirrors the validated pr-review self-host pattern. dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does not regress ring-0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
…554) * fix(dev-lead): pin .github-private self-host to @dev-lead/stable + agent_ref (#535) .github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a broken change to dev-lead on main instantly gated its own fix (the self-host circular dependency). Pin the caller to the dev-lead/stable channel and thread agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned version too (#506). Promotion is now a central tag move; this caller is never edited on release — mirrors the validated pr-review self-host pattern. dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does not regress ring-0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * chore: apply manual instructions [skip ci-relay] --------- Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>



What
Pin
.github-private's owndev-lead.ymltrigger stub fromdev-lead-reusable.yml@main→@dev-lead/stable, and threadagent_ref: dev-lead/stableso the dev-lead scripts/prompts checkout runs at the pinned version too (#506).Why
Closes dev-lead's ring-0 self-hosting circular dependency: previously a broken change to dev-lead on
mainwas instantly live for .github-private's own dev-lead duty, so it could gate the fix for its own breakage. Now ring-0 runs the known-gooddev-lead/stablechannel; promotion = moving the tag centrally, never editing this caller. Mirrors the validated pr-review self-host pattern (#497/#523).Safe-by-construction
dev-lead/stablewas first advanced v1.1.0 → v1.2.0 (= current main) so this pin does not regress ring-0 — v1.1.0 was 84 lines behind, missing #488's ci-relaycommits-to-pullsfallback and exit-code-2 soft-skip handling. v1.2.0 includes them.Audit note
No inline→stub reconciliation was needed:
dev-lead.ymlis already a thin trigger stub anddev-lead-reusable.ymlholds the logic. The split pre-existed; this PR is purely the version pin.Part of #535 (ring-0). Consumer fan-out to
@dev-lead/stableis a separate follow-up.🤖 Generated with Claude Code
Summary by CodeRabbit