feat: implement issue #274 — [Fleet Monitor] petry-projects/ContentTwin — .github/workflows/pr-auto-review.yml - #275
Conversation
…in — .github/workflows/pr-auto-review.yml
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Review limit reached
More reviews will be available in 54 minutes and 51 seconds. Learn how PR review limits work. Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file). ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits. 🚦 How do rate limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughAdds a Changespr-auto-review Concurrency Policy and Validation Tests
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related issues
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Dev-Lead — waiting on PR blockers (intent: review-changes)PR: #275 |
|
Note @don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically. |
There was a problem hiding this comment.
Code Review
This pull request introduces a new BATS test suite, scripts/tests/pr-auto-review-workflow.bats, to validate the .github/workflows/pr-auto-review.yml workflow, ensuring its YAML validity, concurrency configuration, and proper delegation. The feedback suggests improving consistency and safety in the YAML validation test by passing the workflow path as an argument to Python instead of using direct string interpolation.
There was a problem hiding this comment.
🧹 Nitpick comments (1)
scripts/tests/pr-auto-review-workflow.bats (1)
63-70: ⚡ Quick winTighten reusable-workflow assertion to the expected repository path.
Current check can pass for unintended
usesvalues as long as they containpr-auto-review-reusable.yml. Assert the full trusted path (or at least expected repo/path prefix) to enforce the contract this test describes.Suggested diff
-assert 'pr-auto-review-reusable.yml' in uses, f'job must call the org reusable, got: {uses!r}' +expected = 'petry-projects/.github/.github/workflows/pr-auto-review-reusable.yml@' +assert uses.startswith(expected), f'job must call the org reusable workflow, got: {uses!r}'🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/tests/pr-auto-review-workflow.bats` around lines 63 - 70, The assertion in the test checking the pr-auto-review job's uses value is too permissive. Currently it only verifies that 'pr-auto-review-reusable.yml' appears somewhere in the uses string, which could pass for unintended paths. Replace the loose substring check in the assert statement with a more specific validation that checks for the full trusted repository path or at least the expected repo/path prefix to ensure the workflow is calling the correct org reusable workflow.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@scripts/tests/pr-auto-review-workflow.bats`:
- Around line 63-70: The assertion in the test checking the pr-auto-review job's
uses value is too permissive. Currently it only verifies that
'pr-auto-review-reusable.yml' appears somewhere in the uses string, which could
pass for unintended paths. Replace the loose substring check in the assert
statement with a more specific validation that checks for the full trusted
repository path or at least the expected repo/path prefix to ensure the workflow
is calling the correct org reusable workflow.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 3d0bd6d5-2412-45c4-9547-94c7acdb2b2a
📒 Files selected for processing (2)
.github/workflows/pr-auto-review.ymlscripts/tests/pr-auto-review-workflow.bats
Dev-Lead — fix-reviews (applied)Changes committed and pushed. |
Dev-Lead — review-changes (applied)Changes committed and pushed. |
|
Dev-Lead — review-changes (no-changes)No changes were needed for this PR. |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: 59743729a75e4edd6d2286f9598834a7d94360c4
Review mode: triage-approved (single reviewer)
Summary
Adds a top-level concurrency block to the pr-auto-review.yml caller workflow (group keyed by workflow+ref, cancel-in-progress: true) plus a 75-line Bats suite validating the workflow's YAML, concurrency config, and reusable-workflow delegation. Scope is tight (2 files, +83/-0), changes are low-risk CI configuration, and all checks are green.
Linked issue analysis
Closes #274 (Fleet Monitor: 26.3% failure rate on pr-auto-review.yml). Rapid bot-authored pushes spawned redundant readiness-check runs that piled up in action_required state and inflated the failure rate. The concurrency block cancels superseded same-ref runs, directly addressing the reported cause. Mirrors the prior sonarcloud.yml fix (#263). The new Bats tests guard the fix against regression.
Findings
No blocking findings.
- permissions: {} on the workflow is preserved; no permission or secret changes.
- Prior bot-review feedback is already resolved in the current head:
- CodeRabbit nitpick (loose reusable-workflow assertion) -> test now uses uses.startswith('petry-projects/.github/.github/workflows/pr-auto-review-reusable.yml@').
- Gemini suggestion (avoid string interpolation in YAML-validation test) -> tests pass the path via sys.argv[1].
- Bats suite has a sensible PyYAML availability guard in setup().
CI status
All checks green or skipped: CI (Lint/Format/Test/Secret scan), CodeQL, SonarCloud (Quality Gate passed), AgentShield, dependency-audit, pr-auto-review readiness, PR Review Agent — all SUCCESS. No failing or cancelled checks. mergeStateStatus is BLOCKED only because the org-leads team review is still required (human approval gate).
Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.
CI Failure: SonarCloud Code AnalysisStep: Quality Gate evaluation SonarCloud detected 14 new Security Hotspots introduced by this PR, causing the Quality Gate to fail. Security Hotspots are security-sensitive code patterns that require manual review — they are not necessarily confirmed vulnerabilities, but SonarCloud flags them until a reviewer marks each one as Safe or Acknowledged. The new BATS test file ( Suggested fix: Open the SonarCloud Security Hotspots page for this branch, review each of the 14 flagged hotspots, and mark them as Safe (or fix any that are genuine risks) so the Quality Gate passes. |



Closes #274
Implemented by dev-lead agent. Please review.
Summary by CodeRabbit
Chores
Tests