Skip to content

feat: implement issue #274 — [Fleet Monitor] petry-projects/ContentTwin — .github/workflows/pr-auto-review.yml - #275

Merged
don-petry merged 3 commits into
mainfrom
dev-lead/issue-274-20260618-1048
Jun 18, 2026
Merged

don-petry merged 3 commits into
mainfrom
dev-lead/issue-274-20260618-1048

Conversation

@don-petry

@don-petry don-petry commented Jun 18, 2026 •

Copy link
Copy Markdown
Contributor

Closes #274

Implemented by dev-lead agent. Please review.

Summary by CodeRabbit

  • Chores

    • Enhanced continuous integration workflow to intelligently manage concurrent runs, automatically canceling outdated checks when multiple pull request updates are rapidly processed, improving review cycle efficiency.
  • Tests

    • Added comprehensive validation suite for workflow configuration integrity and job execution verification.

…in — .github/workflows/pr-auto-review.yml
@don-petry
don-petry requested a review from a team as a code owner June 18, 2026 10:52
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Jun 18, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@don-petry, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 54 minutes and 51 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 82b45ea3-84f5-4dbb-b74d-c0cce411ac4c

📥 Commits

Reviewing files that changed from the base of the PR and between acf49dc and 5974372.

📒 Files selected for processing (1)
  • scripts/tests/pr-auto-review-workflow.bats
📝 Walkthrough

Walkthrough

Adds a concurrency block to .github/workflows/pr-auto-review.yml that groups runs by workflow and ref and cancels in-progress runs on new triggers. Introduces a new Bats test suite in scripts/tests/pr-auto-review-workflow.bats that validates the workflow file's presence, YAML validity, concurrency configuration, and reusable workflow delegation.

Changes

pr-auto-review Concurrency Policy and Validation Tests

Layer / File(s) Summary
Concurrency policy
.github/workflows/pr-auto-review.yml
Adds a top-level concurrency block using ${{ github.workflow }}-${{ github.ref }} as the group key and sets cancel-in-progress: true to cancel older runs when a newer run starts for the same ref.
Bats test suite
scripts/tests/pr-auto-review-workflow.bats
New 74-line Bats file with a setup() hook that checks PyYAML availability, then asserts the workflow file exists, parses as valid YAML, has a concurrency mapping with a group key, sets cancel-in-progress: true, includes github.ref in the group string, and delegates the pr-auto-review job to pr-auto-review-reusable.yml.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Possibly related issues

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title references issue #274 and the specific workflow file being modified, clearly summarizing the main change.
Linked Issues check ✅ Passed The PR implements concurrency controls to address workflow failures. Issue #274 reports a 26.3% failure rate; adding concurrency with cancel-in-progress directly mitigates rapid automated PR updates causing inflated failures.
Out of Scope Changes check ✅ Passed All changes are scoped to the pr-auto-review workflow and its test file, directly addressing the degraded workflow issue identified in #274.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev-lead/issue-274-20260618-1048

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #275
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-06-18T11:23:16Z

@don-petry

Copy link
Copy Markdown
Contributor Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-06-18T11:23:16Z

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a new BATS test suite, scripts/tests/pr-auto-review-workflow.bats, to validate the .github/workflows/pr-auto-review.yml workflow, ensuring its YAML validity, concurrency configuration, and proper delegation. The feedback suggests improving consistency and safety in the YAML validation test by passing the workflow path as an argument to Python instead of using direct string interpolation.

Comment thread scripts/tests/pr-auto-review-workflow.bats Outdated
@don-petry
don-petry enabled auto-merge (squash) June 18, 2026 10:53
@don-petry
don-petry disabled auto-merge June 18, 2026 10:54

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
scripts/tests/pr-auto-review-workflow.bats (1)

63-70: ⚡ Quick win

Tighten reusable-workflow assertion to the expected repository path.

Current check can pass for unintended uses values as long as they contain pr-auto-review-reusable.yml. Assert the full trusted path (or at least expected repo/path prefix) to enforce the contract this test describes.

Suggested diff
-assert 'pr-auto-review-reusable.yml' in uses, f'job must call the org reusable, got: {uses!r}'
+expected = 'petry-projects/.github/.github/workflows/pr-auto-review-reusable.yml@'
+assert uses.startswith(expected), f'job must call the org reusable workflow, got: {uses!r}'
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/tests/pr-auto-review-workflow.bats` around lines 63 - 70, The
assertion in the test checking the pr-auto-review job's uses value is too
permissive. Currently it only verifies that 'pr-auto-review-reusable.yml'
appears somewhere in the uses string, which could pass for unintended paths.
Replace the loose substring check in the assert statement with a more specific
validation that checks for the full trusted repository path or at least the
expected repo/path prefix to ensure the workflow is calling the correct org
reusable workflow.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@scripts/tests/pr-auto-review-workflow.bats`:
- Around line 63-70: The assertion in the test checking the pr-auto-review job's
uses value is too permissive. Currently it only verifies that
'pr-auto-review-reusable.yml' appears somewhere in the uses string, which could
pass for unintended paths. Replace the loose substring check in the assert
statement with a more specific validation that checks for the full trusted
repository path or at least the expected repo/path prefix to ensure the workflow
is calling the correct org reusable workflow.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 3d0bd6d5-2412-45c4-9547-94c7acdb2b2a

📥 Commits

Reviewing files that changed from the base of the PR and between 3068700 and acf49dc.

📒 Files selected for processing (2)
  • .github/workflows/pr-auto-review.yml
  • scripts/tests/pr-auto-review-workflow.bats

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-reviews (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) June 18, 2026 10:55
@don-petry
don-petry disabled auto-merge June 18, 2026 10:56
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — review-changes (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) June 18, 2026 10:57
@don-petry
don-petry disabled auto-merge June 18, 2026 10:58
@sonarqubecloud

Copy link
Copy Markdown

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — review-changes (no-changes)

No changes were needed for this PR.

@don-petry
don-petry enabled auto-merge (squash) June 18, 2026 10:59

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: 59743729a75e4edd6d2286f9598834a7d94360c4
Review mode: triage-approved (single reviewer)

Summary

Adds a top-level concurrency block to the pr-auto-review.yml caller workflow (group keyed by workflow+ref, cancel-in-progress: true) plus a 75-line Bats suite validating the workflow's YAML, concurrency config, and reusable-workflow delegation. Scope is tight (2 files, +83/-0), changes are low-risk CI configuration, and all checks are green.

Linked issue analysis

Closes #274 (Fleet Monitor: 26.3% failure rate on pr-auto-review.yml). Rapid bot-authored pushes spawned redundant readiness-check runs that piled up in action_required state and inflated the failure rate. The concurrency block cancels superseded same-ref runs, directly addressing the reported cause. Mirrors the prior sonarcloud.yml fix (#263). The new Bats tests guard the fix against regression.

Findings

No blocking findings.

  • permissions: {} on the workflow is preserved; no permission or secret changes.
  • Prior bot-review feedback is already resolved in the current head:
    • CodeRabbit nitpick (loose reusable-workflow assertion) -> test now uses uses.startswith('petry-projects/.github/.github/workflows/pr-auto-review-reusable.yml@').
    • Gemini suggestion (avoid string interpolation in YAML-validation test) -> tests pass the path via sys.argv[1].
  • Bats suite has a sensible PyYAML availability guard in setup().

CI status

All checks green or skipped: CI (Lint/Format/Test/Secret scan), CodeQL, SonarCloud (Quality Gate passed), AgentShield, dependency-audit, pr-auto-review readiness, PR Review Agent — all SUCCESS. No failing or cancelled checks. mergeStateStatus is BLOCKED only because the org-leads team review is still required (human approval gate).


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

@don-petry
don-petry merged commit 3f34cd5 into main Jun 18, 2026
22 checks passed
@don-petry
don-petry deleted the dev-lead/issue-274-20260618-1048 branch June 18, 2026 13:48
@github-actions

Copy link
Copy Markdown
Contributor

CI Failure: SonarCloud Code Analysis

Step: Quality Gate evaluation
Root cause: Lint/style

SonarCloud detected 14 new Security Hotspots introduced by this PR, causing the Quality Gate to fail. Security Hotspots are security-sensitive code patterns that require manual review — they are not necessarily confirmed vulnerabilities, but SonarCloud flags them until a reviewer marks each one as Safe or Acknowledged. The new BATS test file (scripts/tests/pr-auto-review-workflow.bats) likely triggered these flags due to inline python3 -c "..." shell invocations, which static analyzers commonly flag as potential injection risks.

Suggested fix: Open the SonarCloud Security Hotspots page for this branch, review each of the 14 flagged hotspots, and mark them as Safe (or fix any that are genuine risks) so the Quality Gate passes.

View run logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Fleet Monitor] petry-projects/ContentTwin — .github/workflows/pr-auto-review.yml

2 participants