Skip to content

feat: implement issue #540 — Compliance: ruleset-drift-pr-quality-require_code_owner_review - #542

Merged
don-petry merged 6 commits into
mainfrom
dev-lead/issue-540-20260904-1652
Sep 14, 2026
Merged

don-petry merged 6 commits into
mainfrom
dev-lead/issue-540-20260904-1652

Conversation

@don-petry

@don-petry don-petry commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

User description

Closes #540

Implemented by dev-lead agent. Please review.


CodeAnt-AI Description

Lock pull request review rules to the organization’s required standard

What Changed

  • Tests now verify the complete pr-quality pull request rule configuration against the organization standard
  • Checks fail when required approvals, code-owner review, stale-review dismissal, last-push approval, thread resolution, or any configuration key changes
  • Failures show the expected and actual settings to make ruleset drift easier to diagnose

Impact

✅ Code-owner review requirements stay enabled
✅ Fewer undetected pull request rule changes
✅ Clearer compliance test failures

💡 Usage Guide

Checking Your Pull Request

Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.

Talking to CodeAnt AI

Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:

@codeant-ai ask: Your question here

This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.

Example

@codeant-ai ask: Can you suggest a safer alternative to storing this secret?

Preserve Org Learnings with CodeAnt

You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:

@codeant-ai: Your feedback here

This helps CodeAnt AI learn and adapt to your team's coding style and standards.

Example

@codeant-ai: Do not flag unused imports.

Retrigger review

Ask CodeAnt AI to review the PR again, by typing:

@codeant-ai: review

Check Your Repository Health

To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.

Summary by CodeRabbit

  • Tests
    • Added coverage to verify that pull-request quality parameters match the expected values exactly.
    • Tests now fail when parameter parsing fails or when any parameter differs from the expected configuration.

@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@codeant-ai

codeant-ai Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

🤖 CodeAnt AI — Review Status

Status Commit Started (UTC) Finished (UTC)
✅ Incremental review completed f8161d8 Sep 14, 2026 · 23:37 23:37
✅ Incremental review completed bccfe0b Sep 07, 2026 · 23:39 23:40
✅ Reviewed your PR dceae2d Sep 04, 2026 · 16:59 17:00

@codeant-ai

codeant-ai Bot commented Sep 4, 2026

Copy link
Copy Markdown

Thanks for using CodeAnt! 🎉

We're free for open-source projects. if you're enjoying it, help us grow by sharing.

Share on X ·
Reddit ·
LinkedIn

@coderabbitai

coderabbitai Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Warning

.coderabbit.yaml has a parsing error

The CodeRabbit configuration file in this repository has a parsing error and default settings were used instead. Please fix the error(s) in the configuration file. You can initialize chat with CodeRabbit to get help with the configuration file.

Parsing errors (1)
Validation error: Invalid input: expected string, received object at "reviews.path_filters[3]"
⚙️ Configuration instructions
  • Please see the configuration documentation for more information.
  • You can also validate your configuration using the online YAML validator.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 13b976e3-26c5-4945-bd23-a7cbb13bcaf1

📥 Commits

Reviewing files that changed from the base of the PR and between 83e2807 and f8161d8.

📒 Files selected for processing (1)
  • tests/scripts/apply-rulesets.test.sh

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request adds an exact JSON snapshot assertion for the pr-quality parameters. The test now fails when parsing fails or when any expected key or value differs.

Changes

Ruleset validation

Layer / File(s) Summary
Canonical parameter snapshot
tests/scripts/apply-rulesets.test.sh
The test compares sorted pr-quality parameters with five expected settings and values. It reports parsing errors and parameter differences as failures.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to 9b5dc

The ruleset validation enforces the required code-owner review setting and detects configuration drift. No actionable merge risk remains.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the implementation of issue #540 and the specific pr-quality ruleset compliance change.
Linked Issues check ✅ Passed Issue #540 requires pr-quality.require_code_owner_review to be true and requires the repository ruleset configuration to match the standard. The reviewed scripts/apply-rulesets.sh payload sets t…
Out of Scope Changes check ✅ Passed The changed test supports issue #540 by locking the complete pr-quality parameter set to the organization standard. The checks for related review parameters and --repo argument handling support th…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev-lead/issue-540-20260904-1652

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codeant-ai codeant-ai Bot added the size:M This PR changes 30-99 lines, ignoring generated files label Sep 4, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a canonical snapshot lock check in tests/scripts/apply-rulesets.test.sh to ensure that the entire .parameters object of the pr-quality pull request rule matches the expected organization standard. The review feedback suggests improving the Bash script by using a here-string instead of piping printf to pass variable contents to jq, and safely capturing potential non-zero exit codes under set -e to prevent premature script termination.

Comment thread tests/scripts/apply-rulesets.test.sh Outdated
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — review-changes (applied)

Changes committed and pushed.

@don-petry
don-petry enabled auto-merge (squash) September 4, 2026 17:04
@don-petry
don-petry disabled auto-merge September 4, 2026 17:08
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
- The PR only modifies test scripts and workflow comments, not `go.mod`, `package.json`, or dependency files
- These appear to be flaky CI environment issues unrelated to the code change
**No action required** — the SonarCloud quality gate passed and code-level issues are zero.
---
## Output
**Bot:** SonarCloud  
**Issues addressed:** 0  
**Skipped (informational):** 1 — SonarCloud Quality Gate passed with no defects  
**Tier 1 blockers noted:** 2 CI failures (govulncheck, pnpm audit) are environmental/infrastructure issues outside code-fix scope  
**Files changed:** `tests/scripts/apply-rulesets.test.sh`, `.github/workflows/ci.yml`

@don-petry
don-petry disabled auto-merge September 7, 2026 23:44
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
**PR Scope:** This PR only modifies `tests/scripts/apply-rulesets.test.sh` (adding a canonical snapshot lock check for issue #540). No dependency files (pnpm-lock.yaml, package.json, go.mod) were changed by this PR.
## Analysis
Since the dependency audit failures:
- Are **not** introduced by this PR's code changes
- Would require a separate dependency update effort
- Cannot be fixed without modifying files outside this PR's scope
And the SonarCloud bot reports **no issues**, there are **no actionable SonarCloud findings to address** in this PR.
## Recommendation
The PR itself is clean regarding code quality (SonarCloud: Quality Gate Passed). The dependency vulnerabilities are environmental issues that should be addressed in a separate dependency-update PR, independent of this change.
This PR can proceed with approval—the SonarCloud analysis confirms it introduces no code quality regressions.

@don-petry
don-petry enabled auto-merge (squash) September 7, 2026 23:46
@don-petry
don-petry disabled auto-merge September 7, 2026 23:54
@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — fix-bot-comment (no-changes)

Agent reasoning
  - Panic: `unexpected expr: *ast.KeyValueExpr` in SSA builder
  - Not caused by this PR: PR only modifies bash test script, no Go code changes
  - Related to commit 54ccbda which modified dependency-audit.yml
**PR Changes Review:**
- ✅ Bash script additions (lines 154-186) implement canonical snapshot lock check correctly
- ✅ Uses proper here-document syntax with jq
- ✅ Error handling with exit code capture is correct
- ✅ No new issues introduced
**Conclusion:**
The SonarCloud bot passed cleanly. The govulncheck failure is a pre-existing tool compatibility issue on the main branch (not introduced by this PR). The PR's bash test script changes are correct and follow best practices. No fixes are needed in this PR.

@don-petry
don-petry disabled auto-merge September 14, 2026 23:43
@sonarqubecloud

Copy link
Copy Markdown

@donpetry-bot

Copy link
Copy Markdown
Contributor

Automated review paused — review engines are unavailable.

Every configured review engine (Claude → Copilot → Gemini) reported a usage/rate limit or was otherwise unavailable, so no review could be generated for this run. This is a single, deduplicated notice: the agent will re-review automatically on its next scheduled run once capacity recovers, and will not post repeat notices in the meantime.

@don-petry

Copy link
Copy Markdown
Contributor Author

Dev-Lead — rate-limited (intent: fix-reviews)

PR: #542
The retry cron will re-attempt automatically.

@don-petry
don-petry merged commit e4fec4a into main Sep 14, 2026
21 of 27 checks passed
@don-petry
don-petry deleted the dev-lead/issue-540-20260904-1652 branch September 14, 2026 23:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M This PR changes 30-99 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Compliance: ruleset-drift-pr-quality-require_code_owner_review

2 participants