Skip to content

feat: implement issue #404 — Compliance: stub-surface-drift-pr-review-mention.yml-concurrency - #424

Merged
don-petry merged 3 commits into
mainfrom
dev-lead/issue-404-20260814-1329
Aug 18, 2026
Merged

don-petry merged 3 commits into
mainfrom
dev-lead/issue-404-20260814-1329

Conversation

@don-petry

@don-petry don-petry commented Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

User description

Closes #404

Implemented by dev-lead agent. Please review.

Summary by CodeRabbit

  • Chores
    • Simplified pull request review automation by centralizing run concurrency management.
    • Preserved existing triggers, permissions, workflow execution, and secret handling.
    • Updated workflow validation to reflect the centralized concurrency configuration.

CodeAnt-AI Description

Centralize pull request review mention concurrency management

What Changed

  • Removes the workflow’s local concurrency settings so review mention runs follow the shared central configuration
  • Keeps pull request, review comment, and issue comment triggers unchanged
  • Updates workflow checks to prevent local concurrency settings from being reintroduced

Impact

✅ Consistent review-run concurrency across repositories
✅ Fewer workflow configuration conflicts
✅ Preserved review mention triggers

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

@don-petry
don-petry requested a review from a team as a code owner August 14, 2026 13:34
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@codeant-ai

codeant-ai Bot commented Aug 14, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Incremental review completed 8f9ace0 Aug 18, 2026 · 15:15 15:16
✅ Reviewed your PR c897945 Aug 14, 2026 · 13:34 13:36

@codeant-ai

codeant-ai Bot commented Aug 14, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@codeant-ai codeant-ai Bot added the size:S This PR changes 10-29 lines, ignoring generated files label Aug 14, 2026
@coderabbitai

coderabbitai Bot commented Aug 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@don-petry, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 41 minutes

Limit details: You’ve used all 1 included review currently available under your plan.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: f7e29242-cd67-4a56-8fe7-73cc484d19e5

📥 Commits

Reviewing files that changed from the base of the PR and between c897945 and 36bd421.

📒 Files selected for processing (2)
  • scripts/tests/dev-lead-workflow.bats
  • scripts/tests/pr-review-mention-workflow.bats

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 5ea65dd8-aa7a-44de-8e14-058332532cf8

📥 Commits

Reviewing files that changed from the base of the PR and between 3952f24 and c897945.

📒 Files selected for processing (2)
  • .github/workflows/pr-review-mention.yml
  • scripts/tests/pr-review-mention-workflow.bats
💤 Files with no reviewable changes (1)
  • .github/workflows/pr-review-mention.yml

📝 Walkthrough

Walkthrough

The pull request removes workflow-level concurrency from the review mention caller. It updates the Bats test to document centralized ownership and assert that the stub has no local concurrency block.

Changes

Review workflow concurrency

Layer / File(s) Summary
Remove local concurrency and update validation
.github/workflows/pr-review-mention.yml, scripts/tests/pr-review-mention-workflow.bats
The caller workflow retains its triggers, permissions, reusable workflow reference, and secrets. The test documentation and assertion now require the stub to omit concurrency.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to c8979

This PR makes a localized workflow and test update, and no actionable merge-blocking risk remains after normal checks and review.

Suggested reviewers: donpetry-bot

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning The pull request removes the local concurrency block instead of re-syncing the required canonical concurrency configuration from the standard workflow [#404]. Restore the canonical concurrency block in .github/workflows/pr-review-mention.yml and update the test to verify the required configuration.
✅ Passed checks (4 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed The workflow and test changes remain within the linked issue scope, although the implementation does not satisfy the required concurrency configuration [#404].
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the compliance fix for concurrency drift in the pr-review-mention workflow stub.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev-lead/issue-404-20260814-1329

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the pr-review-mention-workflow.bats test script to reflect that the concurrency block is now centrally managed rather than defined locally in the workflow stub. It removes tests asserting local concurrency behavior and adds a new test to ensure no local concurrency block is declared. The review feedback suggests assigning the concurrency expression to a local variable in the Python inline script to avoid complex nested quote escaping and improve readability.

Comment thread scripts/tests/pr-review-mention-workflow.bats
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #424
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-08-14T14:06:01Z

@don-petry

Copy link
Copy Markdown
Contributor Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-08-14T14:06:01Z

@don-petry
don-petry enabled auto-merge (squash) August 14, 2026 13:36
Comment thread scripts/tests/pr-review-mention-workflow.bats
@don-petry

Copy link
Copy Markdown
Contributor Author

No description provided.

@don-petry
don-petry disabled auto-merge August 14, 2026 13:44
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — review-changes (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) August 14, 2026 13:46
@don-petry
don-petry disabled auto-merge August 14, 2026 13:47
@don-petry
don-petry enabled auto-merge (squash) August 14, 2026 13:50
@don-petry
don-petry disabled auto-merge August 14, 2026 13:51
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
Files changed: None
Skipped (informational): 0
```
**No actionable issues found.** The SonarCloud Quality Gate passed with zero new issues, zero security hotspots, and all CI checks passed. The PR is in a clean state with no blocking feedback.

@don-petry
don-petry enabled auto-merge (squash) August 14, 2026 13:51

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: 63f310398aff29f7b94bdf338d143e3720b8874e
Review mode: triage-approved (single reviewer)

Summary

Deletion-only re-sync of the pr-review-mention.yml thin caller stub to the canonical org template, removing a drifted local concurrency: block, plus test updates that now guard against the block re-appearing. Verified the stub at the reviewed head matches standards/workflows/pr-review-mention.yml exactly on all centrally-owned surfaces (triggers, permissions, jobs — and no top-level concurrency block). The triage tier's low-risk assessment is confirmed.

Linked issue analysis

Closes #404 (compliance finding stub-surface-drift-pr-review-mention.yml-concurrency). The finding required re-syncing the concurrency: surface from the canonical template. Verified directly: the canonical standards/workflows/pr-review-mention.yml carries no top-level concurrency: block, and after this PR the repo stub matches it field-for-field (triggers, permissions: {}, job-level permissions, pinned uses: ref all unchanged). The issue is substantively and completely addressed.

Findings

No blocking findings.

  • Bot review threads (addressed): gemini-code-assist's quote-escaping nit and codeant-ai's stale-comment mismatch in dev-lead-workflow.bats were both fixed in commits present at the reviewed head (local concurrency variable extracted in the bats one-liner; sibling comment updated to note pr-review-mention no longer carries a concurrency block). Threads remain unmarked-resolved but are substantively resolved.
  • Non-blocking observation: removing the local concurrency block also removes the #333 comment-burst protection at the stub level. The updated test header correctly documents that if this protection is still wanted it belongs in the org reusable (pr-review-mention-reusable.yml), never in the caller stub — consistent with ci-standards.md centralization tiers.
  • Secret scan: run_secret_scanning MCP tool not available in this environment; gitleaks CI check passed and the diff contains no secret material.

CI status

All checks green: Lint, Format, Test, CodeQL, Secret scan (gitleaks), SonarCloud Quality Gate, AgentShield, CodeRabbit, Graphite AI Reviews all SUCCESS. Skipped jobs (dependency-audit ecosystem jobs, dependabot-automerge, dev-lead ci-relay) are conditional and expected to skip.


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

@don-petry
don-petry force-pushed the dev-lead/issue-404-20260814-1329 branch from 63f3103 to 8f9ace0 Compare August 18, 2026 15:15
@codeant-ai

codeant-ai Bot commented Aug 18, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@codeant-ai codeant-ai Bot added size:S This PR changes 10-29 lines, ignoring generated files and removed size:S This PR changes 10-29 lines, ignoring generated files labels Aug 18, 2026
@don-petry
don-petry disabled auto-merge August 18, 2026 15:15
@don-petry
don-petry enabled auto-merge (squash) August 18, 2026 15:18
@don-petry
don-petry disabled auto-merge August 18, 2026 15:26
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0 (Quality Gate passed)
- 0 new issues detected
- 0 security hotspots
- All CI checks green
Files changed: None
Skipped (informational): 0
```
✅ **No action needed** — the PR is clean and ready for merge.

@don-petry
don-petry enabled auto-merge (squash) August 18, 2026 15:26
@sonarqubecloud

Copy link
Copy Markdown

@don-petry
don-petry merged commit f8b5979 into main Aug 18, 2026
22 checks passed
@don-petry
don-petry deleted the dev-lead/issue-404-20260814-1329 branch August 18, 2026 15:37
@donpetry-bot

Copy link
Copy Markdown
Contributor

Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-08-18T16:40:27Z.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S This PR changes 10-29 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Compliance: stub-surface-drift-pr-review-mention.yml-concurrency

2 participants