feat: implement issue #822 — Live idea:approved canary + Fleet Monitor coverage - #849
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Review limit reached
More reviews will be available in 39 minutes and 39 seconds. Learn how PR review limits work. Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file). ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits. 🚦 How do rate limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (9)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
|
Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-06-20T23:02:38Z. |
There was a problem hiding this comment.
Code Review
This pull request introduces initiative-planner stub coverage and drift detection to the Actions Fleet Monitor, along with a post-merge canary script (initiative_canary.sh) to smoke-test the live trigger path. It also adds comprehensive unit tests for both features. The reviewer feedback highlights a potential race condition due to clock drift when polling for the dispatched workflow run, and suggests falling back to the documented INITIATIVE_CANARY_DISCUSSION environment variable if CANARY_DISCUSSION is not provided.
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
|
Dev-Lead — waiting on PR blockers (intent: review-changes)PR: #849 |
|
Note @don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically. |
|
@donpetry-bot please review — code-owner approval needed to merge. CI is green on the current head. |
|
@don-petry I'm on it — starting a fresh review now. Results will appear in a few minutes. |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: MEDIUM
Reviewed commit: 6b522bfb3a73f2e7beaf703335251d15bdffc97c
Review mode: triage-approved (single reviewer)
Summary
Implements #822: extends the Actions Fleet Monitor with initiative-planner stub coverage/drift detection and adds a daily post-merge canary for the idea:approved -> planner dispatch path. All three ACs are met (canary + dry-run alerting, fleet-monitor stub coverage, SHA drift alert). Pure helpers are well unit-tested (bats), network I/O is isolated, and the canary runs dry-run only so it creates nothing.
Linked issue analysis
Closes #822. AC#1 (scheduled dry-run canary that alerts on failure or the 'Unsupported event type: discussion' regression fingerprint) -> initiative-planner-canary.yml + scripts/initiative_canary.sh. AC#2 (Fleet Monitor extended to the new stub) -> scripts/fleet_stub_drift.sh sourced into fleet_monitor.sh, reusing the existing repo discovery rather than a parallel monitor. AC#3 (alert on per-repo stub SHA drift) -> stub_drift_alert_json + the 'Track initiative-planner stub drift' / 'Dispatch dev-lead' workflow steps. Substantively addressed.
Findings
No blocking issues.
- Security: command-injection surfaces are guarded — CANARY_DISCUSSION is validated against ^[1-9][0-9]*$ before reaching the gh command line; GITHUB_REF is checked to be a refs/heads or refs/tags value before use as --ref. No hardcoded secrets (only secrets.GH_PAT_WORKFLOWS / github.token references). github-script steps interpolate org repo names only into Markdown issue bodies (no shell), so no injection.
- Actions hygiene: actions/github-script (3a2844b7, v9.0.0) and actions/checkout (df4cb1c0, v6.0.3) are SHA-pinned consistent with the rest of the repo; checkout uses persist-credentials: false. PAT (GH_PAT_WORKFLOWS) use is documented and justified (github.token does not start a dispatched run / trigger downstream issue workflows).
- AGENTS.md is updated to document initiative-planner-canary.yml as a repo-specific Workflow Files exception, with a remove-if-template-gains-equivalent note — matches the existing exception pattern.
- Tests are pure-function focused with a mocked gh CLI for main(); they assert the dispatch is dry-run and that the regression fingerprint is detected even on a 'success' conclusion.
- Note: MCP run_secret_scanning was not runnable in this CI context (permission not granted); relied on the gitleaks CI check, which passed.
CI status
All required checks green: shellcheck/ShellCheck, bats/unit-tests, CodeQL (actions+python), gitleaks secret scan, agent-shield/AgentShield, Agent Security Scan, validate-agent-profiles, gh-aw-compile, SonarCloud (Quality Gate passed, 0 new issues). The single CANCELLED 'review / review' run is superseded by a SUCCESS run of the same check. Advisory bots Codex and CodeRabbit reported usage/rate limits (no substantive findings); SonarCloud and CodeRabbit's check state are green.
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.
|
Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-06-20T23:16:00Z. |



Closes #822
Implemented by dev-lead agent. Please review.