pr-review: dogfood ring-0 on @pr-review/next (self-host canary) - #833
Conversation
Repin .github-private's own pr-review trigger from @pr-review/stable to @pr-review/next so this repo becomes the ring-0 canary per the agentic release strategy (docs/initiatives/agentic-release-strategy.md §5): new pr-review releases are exercised on .github-private's own PRs via the next channel before promotion to stable (the fleet). This is the ring-0 step for enabling the downstream-impact pass (#748/#815): once pr-review/next points at v1.7.0 (which carries DOWNSTREAM_IMPACT_ENABLED), .github-private reviews run it first to prove it out, then stable is promoted. MERGE ORDERING: requires the pr-review/next tag to exist first, or self-host reviews can't resolve the reusable. Cut it before merging: scripts/cut-release.sh pr-review 1.7.0 --ref origin/main --push git tag -f pr-review/next pr-review/v1.7.0 && git push -f origin pr-review/next (these are OrgAdmin/automation-gated tag ops). https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
|
Warning Review limit reached
More reviews will be available in 1 hour. Learn how PR review limits work. Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file). ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits. 🚦 How do rate limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
Superseded by automated re-review at
|
The trigger header still described the old @pr-review/stable behavior and claimed 'This file never changes', contradicting the repin to @pr-review/next. Update the header to describe the ring-0 dogfooding rationale (self-host tracks next; promotion to stable is a central tag move), and trim the now-redundant inline job comment. Addresses the pr-review agent's maintainability finding. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
|
Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-06-20T17:58:05Z. |
|
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
|
Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-06-20T19:11:07Z. |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: MEDIUM
Reviewed commit: a42e92cc504e1fa8b0d9b6ebfe0b9928acf88ca9
Review mode: triage-approved (single reviewer)
Summary
Repins the self-host ring-0 trigger stub (.github/workflows/pr-review-trigger.yml) from @pr-review/stable to @pr-review/next for both the reusable 'uses:' ref and the 'agent_ref' input, plus header-comment updates. 1 file, +15/-9 (mostly comments). This makes .github-private the ring-0 canary that dogfoods the 'next' channel before fleet promotion, per docs/initiatives/agentic-release-strategy.md §5.
Linked issue analysis
No formal closing issue (closingIssuesReferences empty). This is a rollout/enablement step referencing #748/#815 (downstream-impact pass) and #497/#506 (self-hosting circular-dependency break). The PR's intent — establish a canary channel before fleet rollout — is consistent with the referenced initiative and is fully addressed by the single-line repin.
Findings
No blocking findings.
- Allowed-input scope: pr-review-trigger.yml is a thin trigger stub; changing the channel-tag pin is the documented promotion mechanism (the header itself states the file changes only when the ring-0 channel changes). Within allowed scope. ✓
- Security: no new permissions, secrets, or untrusted code paths. Moving between two same-repo channel tags preserves the existing pinning model (stable was already a mutable channel tag), so no new GitHub Actions security smell.
- Operational caveat (non-blocking, author-owned): per the PR body, the pr-review/next tag must be cut/advanced BEFORE this merges or self-host reviews 403/fail to resolve. These tag ops are OrgAdmin/automation-gated and explicitly owned by the author; nothing in this diff can enforce that ordering, so it is flagged for awareness only.
CI status
All required checks green; remaining are expected SKIPs (dependency-audit ecosystems, dependabot-automerge, dev-lead/ci-relay). Notable passes: shellcheck, ShellCheck, Lint, CodeQL (actions+python), Agent Security Scan, AgentShield, Secret scan (gitleaks), gh-aw-compile, Compile agentic workflows, validate-agent-profiles, unit-tests, bats, SonarCloud. mergeStateStatus=BLOCKED only due to REVIEW_REQUIRED (this review).
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>
…xt (#850) Ring-0 dogfood for the downstream-impact pass (#748/#815), now live on the @pr-review/next channel after #833. This comment-only edit to a shared surface (scripts/lib/ci-status.sh, a surface_source of .github/workflows/pr-review.yml) should make the self-host pr-review agent emit a 'Downstream impact' annotation naming the consumer repos that pin that reusable. No functional change; revert once the annotation is verified. https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L Co-authored-by: Claude <noreply@anthropic.com>



Why
Enabling the downstream-impact pass (#748 / #815) should roll out ring-by-ring, not fleet-wide at once. Per
docs/initiatives/agentic-release-strategy.md§5, Ring 0 =.github-privateself-host runs@pr-review/next; a release only reaches@pr-review/stable(the fleet) after the ring-0 soak proves healthy.Today the self-host trigger pins
@pr-review/stable, so there is no canary — there's no way to dogfood a new pr-review version on this repo before everyone gets it.What
Repin
pr-review-trigger.yml(this repo's own review caller) from@pr-review/stable→@pr-review/next(workflow +agent_ref). That makes.github-privatethe ring-0 canary: its own PR reviews runnextfirst.This is the code half of enabling downstream-impact via the ring approach; the tag operations are the other half (below).
nexttag must exist first)@pr-review/nextmust resolve, or self-host reviews break. These tag ops are OrgAdmin/automation-gated (an agent onGITHUB_TOKENis 403-blocked by thepr-review/**ruleset), so they're yours:Live test (after this lands on
next)Open a PR here touching a mapped shared surface (e.g. a comment-only edit to
scripts/lib/ci-status.sh, whichpr-review.yml'ssurface_sourceslists). The verdict should then carry a Downstream impact section naming consumer repos. I'll drive and verify that oncenextis cut.🤖 Generated with Claude Code
https://claude.ai/code/session_014djuNDBa3GASVDLQPXXg9L
Generated by Claude Code