feat: implement issue #555 — Compliance: ruleset-drift-pr-quality-dismiss_stale_reviews_on_push - #576
Conversation
…miss_stale_reviews_on_push
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
🤖 CodeAnt AI — Review Status
|
|
ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing |
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
There was a problem hiding this comment.
Code Review
This pull request adds explanatory comments to both scripts/setup-pr-quality-ruleset.sh and scripts/tests/setup-pr-quality-ruleset.test.js to document compliance-pinned parameters (dismiss_stale_reviews_on_push and require_last_push_approval) and reference their corresponding issues (#539 and #555). There are no review comments, and I have no feedback to provide.
|
Note @don-petry I reviewed this PR and no code changes were needed, but it still has blocking checks or reviews (failing or cancelled checks, or changes-requested reviews), so I cannot mark it done yet. I'll re-check automatically. |
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Repository: petry-projects/google-app-scripts/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe change adds comments that document compliance-pinned ruleset parameters, their enforcement sources, and related configuration-drift issues. No executable logic or public declarations change. ChangesRuleset compliance documentation
Estimated code review effort: 1 (Trivial) | ~2 minutes Suggested reviewers: Merge Risk: ⚪ Minimal · up to This change documents compliance-pinned ruleset settings and related drift issues without altering runtime or repository configuration behavior. No merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
No description provided. |
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
Superseded by automated re-review at
|
Superseded by automated re-review at
|
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
|
No description provided. |
Dev-Lead — waiting on PR blockers (intent: review-changes)PR: #576 |
…lity Upgraded js-yaml from 4.3.1 to 4.3.2 to fix high-severity vulnerability where maxTotalMergeKeys does not limit CPU use for empty merge sources. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Dev-Lead — fix-bot-comment (applied)Changes committed and pushed. |
|
|
Advisory bots were rate-limited; auto-approval is withheld until they recover. pr-review-sweep will re-review this PR after 2026-09-20T19:36:03Z. |
Superseded by automated re-review at
|
Dev-Lead — fix-bot-comment (no-changes)Agent reasoning |
donpetry-bot
left a comment
There was a problem hiding this comment.
Automated review — APPROVED ✓
Risk: LOW
Reviewed commit: 8c84860a9ed4ed7deb95f723ace8ecd3229b4985
Cascade: triage → deep (triage: haiku 4.5 [sonnet 5] → deep: opus 4.8 [sonnet 5] + duck: o4-mini → audit: fable 5)
Summary
Comment-only change to setup-pr-quality-ruleset.sh and its test that documents two compliance-pinned ruleset parameters (dismiss_stale_reviews_on_push #555, require_last_push_approval #539), plus a dev-only js-yaml 4.3.1->4.3.2 patch bump in package-lock.json. Verified the new comments are factually accurate against the head payload (both keys present and set true) and the test (both assertions present); the change is behavior-preserving. CI is fully green, SonarCloud passed, advisory bots raised no substantive findings, and no downstream consumers are impacted.
Findings
- info: An unrelated dev-dependency bump (js-yaml 4.3.1->4.3.2) is bundled into an otherwise documentation-only PR. Patch-level, dev:true, integrity-pinned, and npm audit passed, so it is low risk, but mixing an unrelated lockfile bump into a docs change slightly muddies the PR's scope. Non-blocking.
- info: PR description is missing the structured risk/test-plan/rollback sections (DESCRIPTION_MISSING: 3). Acceptable here given a linked closing issue (#555) and a clear change description, but the maintainer should fill the standard sections for consistency.
- info: Added comments explain WHY the parameters must not be relaxed and cross-reference the enforcing test and audit — accurate and useful. Verified against head: script payload has dismiss_stale_reviews_on_push:true and require_last_push_approval:true, and the test asserts both. Behavior-preserving.
Reviewed by the PR-review cascade (triage: haiku 4.5 [sonnet 5] → deep: opus 4.8 [sonnet 5] + duck: o4-mini → audit: fable 5). Reply if you need a human review.



User description
Closes #555
Implemented by dev-lead agent. Please review.
CodeAnt-AI Description
Enforce approval refreshes when pull requests change
What Changed
pr-qualityruleset now requires stale reviews to be dismissed when new commits are pushedImpact
✅ Stale approvals cannot remain valid after new pushes✅ Latest changes require fresh approval✅ Fewer ruleset compliance regressions💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.
Summary by CodeRabbit
Documentation
Tests