Skip to content

feat: implement issue #405 — Compliance: stub-surface-drift-pr-auto-review.yml-concurrency - #425

Merged
don-petry merged 2 commits into
mainfrom
dev-lead/issue-405-20260814-1329
Aug 18, 2026
Merged

don-petry merged 2 commits into
mainfrom
dev-lead/issue-405-20260814-1329

Conversation

@don-petry

@don-petry don-petry commented Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

User description

Closes #405

Implemented by dev-lead agent. Please review.


CodeAnt-AI Description

Remove repository-level cancellation rules from automated PR reviews

What Changed

  • Automated PR reviews now rely on the centrally managed workflow for run scheduling and cancellation
  • Removed repository and job-level concurrency settings that could conflict with the shared review workflow
  • Added checks to prevent future workflow edits from reintroducing local concurrency settings

Impact

✅ Consistent automated review scheduling
✅ Fewer conflicting or duplicated review runs
✅ Prevented configuration drift across repositories

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Summary by CodeRabbit

  • Bug Fixes

    • Updated pull request auto-review workflow behavior to avoid canceling in-progress runs.
    • Removed workflow and job-level concurrency requirements, allowing review runs to proceed independently.
  • Tests

    • Updated automated workflow validation to reflect the revised concurrency behavior.

@don-petry
don-petry requested a review from a team as a code owner August 14, 2026 13:34
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@codeant-ai

codeant-ai Bot commented Aug 14, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Incremental review completed 077d2dc Aug 18, 2026 · 15:15 15:15
✅ Reviewed your PR a008bef Aug 14, 2026 · 13:34 13:36

@codeant-ai

codeant-ai Bot commented Aug 14, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@coderabbitai

coderabbitai Bot commented Aug 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 6a627168-dd55-488f-b2a5-ec84fc1cb3f3

📥 Commits

Reviewing files that changed from the base of the PR and between 3952f24 and 077d2dc.

📒 Files selected for processing (2)
  • .github/workflows/pr-auto-review.yml
  • scripts/tests/pr-auto-review-workflow.bats
💤 Files with no reviewable changes (1)
  • .github/workflows/pr-auto-review.yml

Included review availability: Your plan includes up to 1 review per rolling hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The PR removes concurrency configuration from the pull request auto-review workflow stub. Its BATS test now requires concurrency to remain centrally managed and rejects workflow-level or job-level concurrency blocks.

Changes

Workflow concurrency ownership

Layer / File(s) Summary
Remove local concurrency and enforce the stub contract
.github/workflows/pr-auto-review.yml, scripts/tests/pr-auto-review-workflow.bats
The workflow stub no longer defines concurrency. The test documentation and assertions require centralized concurrency management and reject top-level or job-level concurrency blocks.

Estimated code review effort: 2 (Simple) | ~10 minutes

Merge Risk: ⚪ Minimal · up to 077d2

This localized change removes repository-level workflow cancellation settings while updating the alignment tests; no actionable merge-blocking risk remains after normal checks and review.

Suggested reviewers: donpetry-bot

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the concurrency compliance fix for issue #405.
Linked Issues check ✅ Passed The workflow and tests remove repository-owned concurrency settings and verify alignment with the centralized reusable workflow as required by issue #405.
Out of Scope Changes check ✅ Passed The changes are limited to the workflow concurrency removal and its corresponding test updates.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev-lead/issue-405-20260814-1329

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codeant-ai codeant-ai Bot added the size:S This PR changes 10-29 lines, ignoring generated files label Aug 14, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the pr-auto-review-workflow.bats test suite to ensure that the pr-auto-review.yml workflow does not declare a per-repo concurrency block, aligning with centralized workflow standards. The reviewer suggests adding an assertion to verify that the test script's output is exactly "ok" to maintain consistency with other workflow tests and prevent false positives.

Comment thread scripts/tests/pr-auto-review-workflow.bats
Comment thread scripts/tests/pr-auto-review-workflow.bats
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #425
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-08-14T14:07:42Z

@don-petry

Copy link
Copy Markdown
Contributor Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-08-14T14:07:42Z

@don-petry
don-petry enabled auto-merge (squash) August 14, 2026 13:37
@don-petry

Copy link
Copy Markdown
Contributor Author

No description provided.

@don-petry
don-petry disabled auto-merge August 14, 2026 13:44
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — review-changes (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) August 14, 2026 13:47
@don-petry
don-petry disabled auto-merge August 14, 2026 13:48
@don-petry
don-petry enabled auto-merge (squash) August 14, 2026 13:52
@don-petry
don-petry disabled auto-merge August 14, 2026 13:53
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
Issues addressed: 0
- No actionable issues found — quality gate passed with zero new issues
Files changed: N/A
Skipped (informational): 0 (quality gate report)
Status: ✓ No changes required
```
The PR is in a healthy state with all checks passing and no bot-identified issues to fix. No action needed.

@don-petry
don-petry enabled auto-merge (squash) August 14, 2026 13:53

@donpetry-bot donpetry-bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated review — APPROVED ✓

Risk: LOW
Reviewed commit: 7ad0d983843524676ad8fd7dea1f554b900ff1be
Review mode: triage-approved (single reviewer)

Summary

Removes the per-repo concurrency block from the pr-auto-review.yml thin caller stub (4 deleted lines) and rewrites the bats guard to assert its absence at both workflow and job level. Verified against the canonical standards/workflows/pr-auto-review.yml, which carries no concurrency block — this is exactly the remediation issue #405 requested. Confirms the triage-tier low-risk assessment.

Linked issue analysis

Issue #405 (compliance audit finding stub-surface-drift-pr-auto-review.yml-concurrency) requires re-syncing the concurrency: surface with the canonical stub. The canonical template was fetched and confirmed to declare no concurrency block; the PR removes the drifted block and adds a regression guard so it cannot be re-introduced. The linked issue is substantively addressed.

Findings

No blocking findings.

  • Workflow change is a pure 4-line deletion restoring the canonical Tier-1 stub surface; no changes to triggers, permissions, secrets, or the v1-stable channel pin.
  • Test rewrite inverts the old issue-#274 guard (which mandated the block) into an absence guard covering both workflow-level and job-level concurrency.
  • Both open bot review threads are substantively addressed at head 7ad0d98: gemini-code-assist's output-assertion suggestion (the test now asserts output == "ok") and codeant-ai's job-level-concurrency gap (the test now iterates all job mappings). Threads remain unmarked-resolved in the UI but require no further code changes.
  • Secret scan: run_secret_scanning MCP tool unavailable in this environment; gitleaks CI check passed and the diff contains no secret-like content.

CI status

All checks green: CI (Lint, Format, Test, gitleaks), CodeQL, AgentShield, SonarCloud quality gate (0 new issues, 0 hotspots), CodeRabbit, Graphite. Remaining checks skipped by design (dependency-audit ecosystems, dependabot, ci-relay). Mergeable; blocked only on review decision.


Reviewed automatically by the PR-review agent (single-reviewer mode: fable 5). Reply if you need a human review.

@don-petry
don-petry force-pushed the dev-lead/issue-405-20260814-1329 branch from 7ad0d98 to 077d2dc Compare August 18, 2026 15:14
@codeant-ai

codeant-ai Bot commented Aug 18, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@codeant-ai codeant-ai Bot added size:S This PR changes 10-29 lines, ignoring generated files and removed size:S This PR changes 10-29 lines, ignoring generated files labels Aug 18, 2026
@don-petry
don-petry disabled auto-merge August 18, 2026 15:16
@sonarqubecloud

Copy link
Copy Markdown

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — waiting on PR blockers (intent: review-changes)

PR: #425
No changes were committed, but the PR still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews). The retry cron will re-attempt automatically. Next attempt after: 2026-08-18T15:47:53Z

@don-petry

Copy link
Copy Markdown
Contributor Author

Note

@don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically.
Next attempt after: 2026-08-18T15:47:53Z

@don-petry
don-petry enabled auto-merge (squash) August 18, 2026 15:17
@don-petry
don-petry merged commit 32bab7a into main Aug 18, 2026
31 of 35 checks passed
@don-petry
don-petry deleted the dev-lead/issue-405-20260814-1329 branch August 18, 2026 15:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S This PR changes 10-29 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Compliance: stub-surface-drift-pr-auto-review.yml-concurrency

2 participants