chore(ci): run PR Hygiene's engine from master - #1099
Conversation
The caller pinned the shared engine to one commit, so every engine fix needed a re-pin here before it took effect. The engine is now named by `master` of dashpay/stale_prs_are_bad — the protected branch the review policy is already read from — and the reusable workflow still requires the commit it runs to be merged there (dashpay/stale_prs_are_bad#73). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: dashpay/rust-dashcore/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe PR review policy workflow now references the reusable workflow from the ChangesPR review policy workflow
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Other Merge Risk: ⚪ Minimal · up to No actionable issue was established with the workflow change; it is mergeable after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change permits automatic upstream engine updates without changing this repository’s declared permissions. No exploit is confirmed, but the upstream branch and tag protections that now govern workflow selection have not been independently verified. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Bots are done — your move: post |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## dev #1099 +/- ##
==========================================
- Coverage 77.39% 77.38% -0.01%
==========================================
Files 320 320
Lines 81343 81343
==========================================
- Hits 62956 62949 -7
- Misses 18387 18394 +7
|
What
This repo's PR Hygiene caller now runs the shared engine from
masterofdashpay/stale_prs_are_badinstead of a pinned commit:Why
With a pinned commit, every engine fix needs a re-pin PR here before it takes effect. The engine fixes merged this week (review bots that open PRs, "your part" per area, branch patterns) haven't reached this repo yet. Meanwhile the review policy is already read live from that same
master, so pinned engines and the live policy can drift apart.Security trade-off (please review)
Naming a branch instead of a SHA means engine upgrades are reviewed in
dashpay/stale_prs_are_bad, not here. The controls there:protect-master: changes need a pull request with code-owner review and the requiredtest/checkCI. Force-push and deletion are blocked.no-tag-shadows-master: amastertag is forbidden, with no bypass. GitHub would resolve a tag before the branch.master(feat: a caller may run the engine from master stale_prs_are_bad#73).Verified in a real run: dashpay/grovedb run 36953611829, caller on
@master, succeeded.🤖 Generated with Claude Code
Summary by CodeRabbit
PR Hygiene ·
80bf2d2/self-reviewedgithub(.github/workflows/pr-review-policy.yml) — ktechmidasWhen every box is checked the
PR Hygienecheck passes and this can merge.