Skip to content

feat: implement issue #822 — Live idea:approved canary + Fleet Monitor coverage - #849

Merged
don-petry merged 2 commits into
mainfrom
dev-lead/issue-822-20260620-2146
Jun 20, 2026
Merged

don-petry merged 2 commits into
mainfrom
dev-lead/issue-822-20260620-2146

Conversation

@don-petry

Copy link
Copy Markdown
Collaborator

Closes #822

Implemented by dev-lead agent. Please review.

@don-petry
don-petry requested a review from a team as a code owner June 20, 2026 22:01
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Jun 20, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@don-petry, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 39 minutes and 39 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 71d5c835-8136-46a5-850c-dd309ee90bf4

📥 Commits

Reviewing files that changed from the base of the PR and between 1ff137e and 6b522bf.

📒 Files selected for processing (9)
  • .github/workflows/actions-fleet-monitor.yml
  • .github/workflows/initiative-planner-canary.yml
  • .github/workflows/lint.yml
  • AGENTS.md
  • scripts/fleet_monitor.sh
  • scripts/fleet_stub_drift.sh
  • scripts/initiative_canary.sh
  • tests/fleet_stub_drift.bats
  • tests/test_initiative_canary.bats
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev-lead/issue-822-20260620-2146

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — review-changes (no-changes)

No changes were needed for this PR.

@don-petry
don-petry enabled auto-merge (squash) June 20, 2026 22:02
@donpetry-bot

Copy link
Copy Markdown
Contributor

Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-06-20T23:02:38Z.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces initiative-planner stub coverage and drift detection to the Actions Fleet Monitor, along with a post-merge canary script (initiative_canary.sh) to smoke-test the live trigger path. It also adds comprehensive unit tests for both features. The reviewer feedback highlights a potential race condition due to clock drift when polling for the dispatched workflow run, and suggests falling back to the documented INITIATIVE_CANARY_DISCUSSION environment variable if CANARY_DISCUSSION is not provided.

Comment thread scripts/initiative_canary.sh Outdated
Comment thread scripts/initiative_canary.sh Outdated
@don-petry
don-petry disabled auto-merge June 20, 2026 22:03
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jun 20, 2026
@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — fix-reviews (applied)

Changes committed and pushed.

@sonarqubecloud

Copy link
Copy Markdown

@don-petry

Copy link
Copy Markdown
Collaborator Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #849
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-06-20T22:38:29Z

@don-petry

Copy link
Copy Markdown
Collaborator Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-06-20T22:38:29Z

@don-petry
don-petry enabled auto-merge (squash) June 20, 2026 22:08
@don-petry

Copy link
Copy Markdown
Collaborator Author

@donpetry-bot please review — code-owner approval needed to merge. CI is green on the current head.

@donpetry-bot

Copy link
Copy Markdown
Contributor

@don-petry I'm on it — starting a fresh review now. Results will appear in a few minutes.

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: MEDIUM
Reviewed commit: 6b522bfb3a73f2e7beaf703335251d15bdffc97c
Review mode: triage-approved (single reviewer)

Summary

Implements #822: extends the Actions Fleet Monitor with initiative-planner stub coverage/drift detection and adds a daily post-merge canary for the idea:approved -> planner dispatch path. All three ACs are met (canary + dry-run alerting, fleet-monitor stub coverage, SHA drift alert). Pure helpers are well unit-tested (bats), network I/O is isolated, and the canary runs dry-run only so it creates nothing.

Linked issue analysis

Closes #822. AC#1 (scheduled dry-run canary that alerts on failure or the 'Unsupported event type: discussion' regression fingerprint) -> initiative-planner-canary.yml + scripts/initiative_canary.sh. AC#2 (Fleet Monitor extended to the new stub) -> scripts/fleet_stub_drift.sh sourced into fleet_monitor.sh, reusing the existing repo discovery rather than a parallel monitor. AC#3 (alert on per-repo stub SHA drift) -> stub_drift_alert_json + the 'Track initiative-planner stub drift' / 'Dispatch dev-lead' workflow steps. Substantively addressed.

Findings

No blocking issues.

  • Security: command-injection surfaces are guarded — CANARY_DISCUSSION is validated against ^[1-9][0-9]*$ before reaching the gh command line; GITHUB_REF is checked to be a refs/heads or refs/tags value before use as --ref. No hardcoded secrets (only secrets.GH_PAT_WORKFLOWS / github.token references). github-script steps interpolate org repo names only into Markdown issue bodies (no shell), so no injection.
  • Actions hygiene: actions/github-script (3a2844b7, v9.0.0) and actions/checkout (df4cb1c0, v6.0.3) are SHA-pinned consistent with the rest of the repo; checkout uses persist-credentials: false. PAT (GH_PAT_WORKFLOWS) use is documented and justified (github.token does not start a dispatched run / trigger downstream issue workflows).
  • AGENTS.md is updated to document initiative-planner-canary.yml as a repo-specific Workflow Files exception, with a remove-if-template-gains-equivalent note — matches the existing exception pattern.
  • Tests are pure-function focused with a mocked gh CLI for main(); they assert the dispatch is dry-run and that the regression fingerprint is detected even on a 'success' conclusion.
  • Note: MCP run_secret_scanning was not runnable in this CI context (permission not granted); relied on the gitleaks CI check, which passed.

CI status

All required checks green: shellcheck/ShellCheck, bats/unit-tests, CodeQL (actions+python), gitleaks secret scan, agent-shield/AgentShield, Agent Security Scan, validate-agent-profiles, gh-aw-compile, SonarCloud (Quality Gate passed, 0 new issues). The single CANCELLED 'review / review' run is superseded by a SUCCESS run of the same check. Advisory bots Codex and CodeRabbit reported usage/rate limits (no substantive findings); SonarCloud and CodeRabbit's check state are green.


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

@don-petry
don-petry merged commit 761541f into main Jun 20, 2026
28 of 29 checks passed
@don-petry
don-petry deleted the dev-lead/issue-822-20260620-2146 branch June 20, 2026 22:15
@donpetry-bot

Copy link
Copy Markdown
Contributor

Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-06-20T23:16:00Z.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Live idea:approved canary + Fleet Monitor coverage

2 participants