Skip to content

fix(dev-lead): self-host pin to @dev-lead/stable + agent_ref (#535) - #554

Merged
don-petry merged 2 commits into
mainfrom
fix/dev-lead-pin-stable
Jun 10, 2026
Merged

don-petry merged 2 commits into
mainfrom
fix/dev-lead-pin-stable

Conversation

@don-petry

@don-petry don-petry commented Jun 10, 2026 •

Copy link
Copy Markdown
Collaborator

What

Pin .github-private's own dev-lead.yml trigger stub from dev-lead-reusable.yml@main → @dev-lead/stable, and thread agent_ref: dev-lead/stable so the dev-lead scripts/prompts checkout runs at the pinned version too (#506).

Why

Closes dev-lead's ring-0 self-hosting circular dependency: previously a broken change to dev-lead on main was instantly live for .github-private's own dev-lead duty, so it could gate the fix for its own breakage. Now ring-0 runs the known-good dev-lead/stable channel; promotion = moving the tag centrally, never editing this caller. Mirrors the validated pr-review self-host pattern (#497/#523).

Safe-by-construction

dev-lead/stable was first advanced v1.1.0 → v1.2.0 (= current main) so this pin does not regress ring-0 — v1.1.0 was 84 lines behind, missing #488's ci-relay commits-to-pulls fallback and exit-code-2 soft-skip handling. v1.2.0 includes them.

Audit note

No inline→stub reconciliation was needed: dev-lead.yml is already a thin trigger stub and dev-lead-reusable.yml holds the logic. The split pre-existed; this PR is purely the version pin.

Part of #535 (ring-0). Consumer fan-out to @dev-lead/stable is a separate follow-up.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated development workflow configuration to use a stable reference channel for consistency.

…ent_ref (#535)

.github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a
broken change to dev-lead on main instantly gated its own fix (the self-host
circular dependency). Pin the caller to the dev-lead/stable channel and thread
agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned
version too (#506). Promotion is now a central tag move; this caller is never
edited on release — mirrors the validated pr-review self-host pattern.

dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's
ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does
not regress ring-0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 10, 2026 21:10
@don-petry
don-petry requested a review from a team as a code owner June 10, 2026 21:10
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@gemini-code-assist

Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@coderabbitai

coderabbitai Bot commented Jun 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@don-petry, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 55 minutes and 16 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: a5a85f5d-e393-4287-9792-2146aa08f63f

📥 Commits

Reviewing files that changed from the base of the PR and between 4191977 and 532b415.

📒 Files selected for processing (1)
  • tests/dev-lead/integration/test_dev_lead_stub.sh
📝 Walkthrough

Walkthrough

The workflow pins the reusable dev-lead-reusable invocation and agent scripts to the dev-lead/stable ref instead of @main, with updated inline comments explaining the stable-channel behavior and anti-circular-dependency logic.

Changes

Workflow reference pinning to dev-lead/stable

Layer / File(s) Summary
Stable channel pinning for dev-lead workflow
.github/workflows/dev-lead.yml
The reusable workflow reference is updated from @main to @dev-lead/stable and agent_ref: dev-lead/stable is passed to ensure consistent stable-channel checkout. Inline comments document the anti-circular-dependency behavior when dev-lead changes on main.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Possibly related issues

  • petry-projects/.github-private#535: The stable-channel pin and agent_ref threading directly implement the trigger-stub + reusable@dev-lead/stable + agent_ref architecture described in the issue.

Possibly related PRs

  • petry-projects/.github-private#538: Both PRs update workflow logic around agent_ref being used to check out the agent scripts; this PR pins the reusable workflow and passes agent_ref: dev-lead/stable while PR #538 fixes the checkout step to use ref: ${{ inputs.agent_ref || 'main' }}.
  • petry-projects/.github-private#513: Introduces the agent_ref input and wires it to actions/checkout via ref: ${{ inputs.agent_ref }}; this PR threads that parameter from the trigger workflow.
  • petry-projects/.github-private#509: Documents and protects dev-lead/** channel tags as the sanctioned mutable-ref exception; this PR operationalizes that pattern by pinning to dev-lead/stable.

Suggested labels

initiative

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main change: pinning dev-lead to @dev-lead/stable and adding agent_ref parameter, which directly matches the workflow modification.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/dev-lead-pin-stable

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates .github-private’s ring-0 dev-lead caller stub to run the reusable workflow from the pinned dev-lead/stable channel (instead of @main) and passes agent_ref: dev-lead/stable so the reusable’s internal checkout of .github-private scripts/prompts is pinned to the same ref, eliminating the self-hosting circular-dependency risk described in #506/#535.

Changes:

  • Pin .github/workflows/dev-lead.yml to dev-lead-reusable.yml@dev-lead/stable.
  • Thread with: agent_ref: dev-lead/stable so dev-lead scripts/prompts checkout runs at the same pinned channel.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — review-changes (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) June 10, 2026 21:13
@sonarqubecloud

Copy link
Copy Markdown

@don-petry
don-petry disabled auto-merge June 10, 2026 21:14
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #554
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-06-10T21:45:33Z

@don-petry

Copy link
Copy Markdown
Collaborator Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-06-10T21:45:33Z

@don-petry
don-petry enabled auto-merge (squash) June 10, 2026 21:15

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: 532b4153aad81defa028900076e1a8c2feb76f3e
Review mode: triage-approved (single reviewer)

Summary

Pins .github-private's own dev-lead.yml thin caller stub from dev-lead-reusable.yml@main to @dev-lead/stable, and threads agent_ref: dev-lead/stable so the scripts/prompts checkout inside the reusable runs at the same channel. Closes the ring-0 self-host circular dependency (#535/#506). The integration test tests/dev-lead/integration/test_dev_lead_stub.sh is correctly updated to accept any dev-lead-reusable.yml@<ref> (not just @main), preserving the thin-caller-stub structural assertion.

Linked issue analysis

No closingIssuesReferences (PR description names #535 / #506 as motivation rather than via "Closes" syntax). Title and body describe the intent precisely; the diff matches that intent (workflow pin + test update — no scope creep, no inline logic regression).

Findings

No blocking findings.

  • .github/workflows/dev-lead.yml — switches uses: from @main to @dev-lead/stable and adds with: agent_ref: dev-lead/stable. This is explicitly the sanctioned mutable-ref exception documented in AGENTS.md §"Release channel tags & the mutable-ref exception" — first-party channel tags are the documented version-selection mechanism for in-repo reusable workflows, protected by the release-channel-tags ruleset. Compliance audits must NOT flag this as an unpinned action.
  • Stub remains thin (no inline run: blocks introduced). Permissions block, secrets: inherit, and the same-repo if: guard are untouched.
  • Pattern mirrors the validated pr-review self-host pin (#497/#523).
  • tests/dev-lead/integration/test_dev_lead_stub.sh — the regex dev-lead-reusable\.yml@\S+ correctly accepts both @main and channel tags like @dev-lead/stable. The fail message is updated to reflect the broader acceptance criterion. The "no inline run steps" assertion (step 3) is preserved.
  • PR body claim that dev-lead/stable was first advanced to v1.2.0 (= current main) before this pin is not directly verifiable from the diff, but is the necessary precondition for non-regression and is documented in the description.

Nit (non-blocking): none.

CI status

All checks green. 27 successful (CI/Lint/ShellCheck/bats, CodeQL actions+python, Agent Security Scan, gitleaks, AgentShield, SonarCloud, Dev-Lead dispatch, PR Review trigger, Test Dev-Lead Agent suite including stub-structure/caller-permissions/toplevel-permissions/concurrency-config, validate-agent-profiles, gh-aw-compile, etc.) and 6 cleanly skipped (dependabot, dependency-audit ecosystem matrix legs, dev-lead ci-relay). mergeable: MERGEABLE; mergeStateStatus: BLOCKED is purely from REVIEW_REQUIRED.


Reviewed automatically by the PR-review agent (single-reviewer mode: opus 4.7). Reply if you need a human review.

@don-petry
don-petry merged commit 58389d5 into main Jun 10, 2026
35 checks passed
@don-petry
don-petry deleted the fix/dev-lead-pin-stable branch June 10, 2026 21:18
don-petry added a commit that referenced this pull request Jun 12, 2026
…554)

* fix(dev-lead): pin .github-private self-host to @dev-lead/stable + agent_ref (#535)

.github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a
broken change to dev-lead on main instantly gated its own fix (the self-host
circular dependency). Pin the caller to the dev-lead/stable channel and thread
agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned
version too (#506). Promotion is now a central tag move; this caller is never
edited on release — mirrors the validated pr-review self-host pattern.

dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's
ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does
not regress ring-0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 14, 2026
…554)

* fix(dev-lead): pin .github-private self-host to @dev-lead/stable + agent_ref (#535)

.github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a
broken change to dev-lead on main instantly gated its own fix (the self-host
circular dependency). Pin the caller to the dev-lead/stable channel and thread
agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned
version too (#506). Promotion is now a central tag move; this caller is never
edited on release — mirrors the validated pr-review self-host pattern.

dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's
ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does
not regress ring-0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 18, 2026
…554)

* fix(dev-lead): pin .github-private self-host to @dev-lead/stable + agent_ref (#535)

.github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a
broken change to dev-lead on main instantly gated its own fix (the self-host
circular dependency). Pin the caller to the dev-lead/stable channel and thread
agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned
version too (#506). Promotion is now a central tag move; this caller is never
edited on release — mirrors the validated pr-review self-host pattern.

dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's
ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does
not regress ring-0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…554)

* fix(dev-lead): pin .github-private self-host to @dev-lead/stable + agent_ref (#535)

.github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a
broken change to dev-lead on main instantly gated its own fix (the self-host
circular dependency). Pin the caller to the dev-lead/stable channel and thread
agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned
version too (#506). Promotion is now a central tag move; this caller is never
edited on release — mirrors the validated pr-review self-host pattern.

dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's
ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does
not regress ring-0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
don-petry added a commit that referenced this pull request Jun 25, 2026
…554)

* fix(dev-lead): pin .github-private self-host to @dev-lead/stable + agent_ref (#535)

.github-private's own dev-lead duty called dev-lead-reusable.yml@main, so a
broken change to dev-lead on main instantly gated its own fix (the self-host
circular dependency). Pin the caller to the dev-lead/stable channel and thread
agent_ref: dev-lead/stable so the scripts/prompts checkout runs at the pinned
version too (#506). Promotion is now a central tag move; this caller is never
edited on release — mirrors the validated pr-review self-host pattern.

dev-lead/stable was first advanced to v1.2.0 (= current main, incl. #488's
ci-relay commits-to-pulls fallback + exit-2 soft-skip handling) so pinning does
not regress ring-0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore: apply manual instructions [skip ci-relay]

---------

Co-authored-by: donpetry-bot <{}+donpetry-bot@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: donpetry-bot <281750570+donpetry-bot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants