Skip to content

chore(ci): run PR Hygiene's engine from master - #1528

Merged
shumkov merged 1 commit into
v1.8-devfrom
chore/pr-hygiene-engine-from-master
Oct 2, 2026
Merged

shumkov merged 1 commit into
v1.8-devfrom
chore/pr-hygiene-engine-from-master

Conversation

@shumkov

@shumkov shumkov commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

What

This repo's PR Hygiene caller now runs the shared engine from master of dashpay/stale_prs_are_bad instead of a pinned commit:

- uses: dashpay/stale_prs_are_bad/.github/workflows/pr-review-reusable.yml@3b987722c37e91755785c031abb3f98fb08ea763
+ uses: dashpay/stale_prs_are_bad/.github/workflows/pr-review-reusable.yml@master

Why

With a pinned commit, every engine fix needs a re-pin PR here before it takes effect. The engine fixes merged this week (review bots that open PRs, "your part" per area, branch patterns) haven't reached this repo yet. Meanwhile the review policy is already read live from that same master, so pinned engines and the live policy can drift apart.

Security trade-off (please review)

Naming a branch instead of a SHA means engine upgrades are reviewed in dashpay/stale_prs_are_bad, not here. The controls there:

  • protect-master: changes need a pull request with code-owner review and the required test/check CI. Force-push and deletion are blocked.
  • no-tag-shadows-master: a master tag is forbidden, with no bypass. GitHub would resolve a tag before the branch.
  • The reusable workflow's bootstrap still refuses any commit not merged to that master (feat: a caller may run the engine from master stale_prs_are_bad#73).

Verified in a real run: dashpay/grovedb run 36953611829, caller on @master, succeeded.

🤖 Generated with Claude Code

PR Hygiene · 9e31a15

  • Bots — thepastaclaw ✓
  • Self-review — post /self-reviewed
  • Within your 5 open PRs
  • Build green
  • Approvals
    • github (.github/workflows/pr-review-policy.yml) — ktechmidas

When every box is checked the PR Hygiene check passes and this can merge.

The caller pinned the shared engine to one commit, so every engine fix
needed a re-pin here before it took effect. The engine is now named by
`master` of dashpay/stale_prs_are_bad — the protected branch the review
policy is already read from — and the reusable workflow still requires
the commit it runs to be merged there (dashpay/stale_prs_are_bad#73).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: dashpay/tenderdash/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 8ae91139-fc3d-466d-b2f1-47c2e2c53956

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the waiting-bots Waiting for the review bots to report on this head label Oct 2, 2026
@thepastaclaw

thepastaclaw commented Oct 2, 2026 •

Copy link
Copy Markdown

✅ Final review complete — Phase 1 only — no blockers (commit 9e31a15) · triage: trivial

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Final review — Phase 1 only (trivial change)

The PR makes the intended one-line change, switching the reusable PR Hygiene workflow from a pinned commit to the master branch of dashpay/stale_prs_are_bad. The supplied evidence confirms the referenced workflow and upstream protections are in place, and the policy reconciliation check succeeded; no in-scope defects were found.

Review provenance

Source: reviewer 1: glm-5.3-flash (agent: phase1-reviewer, role: general); final verifier: gpt-6.1-sol (agent: sol-gate-verifier, role: final-verifier)

  • Triage: trivial by gpt-6.1-sol (effort low) — The diff changes a single GitHub Actions workflow reference from a pinned commit to the master branch, with no application behavior or critical runtime surface affected.
  • Phase 1 reviewers: glm-5.3-flash — general (completed, effort high); agent phase1-reviewer
  • Phase 1 model: glm-5.3-flash — zai quota: 5h 99% left, weekly 71% left; passed over gemini-3.8-flash-high (antigravity below 15% reserve: weekly 70% left, 5h 12% left)
  • Fresh verifier: gpt-6.1-sol — final-verifier; agent sol-gate-verifier
  • Phase 2 reviewers: not run (triage rated this change trivial); this review comments and never approves

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Bots are done — your move: post /self-reviewed.
Full checklist in the description.

@github-actions github-actions Bot added waiting-self-review Waiting for the author to post /self-reviewed and removed waiting-bots Waiting for the review bots to report on this head labels Oct 2, 2026
@shumkov
shumkov merged commit ccd860b into v1.8-dev Oct 2, 2026
23 of 24 checks passed
@shumkov
shumkov deleted the chore/pr-hygiene-engine-from-master branch October 2, 2026 09:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

waiting-self-review Waiting for the author to post /self-reviewed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants