Conversation
Signed-off-by: oliver könig <okoenig@nvidia.com>
|
Thanks for putting this together, @ko3n1g. Cutting out the self-hosted Claude job also removes a lot of attack surface. SummaryThis PR swaps the FindingsWarnings — Worth addressing
Suggestions — Take it or leave it
What Looks Good
Residual Risk
VerdictNeeds changes. Restore the This review was generated by an AI assistant. |
|
| echo "Checking PR author: ${USER}" | ||
| fi | ||
|
|
||
| PERMISSION=$(gh api "repos/${REPO}/collaborators/${USER}/permission" --jq '.permission') |
There was a problem hiding this comment.
Permission lookup fails the gate
When a non-collaborator opens a PR, this lookup can return 404. Without the previous fallback, the runner’s default bash -e stops the gate before it writes allowed=false. External contributors then get a failed workflow run instead of a clean skip.
| PERMISSION=$(gh api "repos/${REPO}/collaborators/${USER}/permission" --jq '.permission') | |
| PERMISSION=$(gh api "repos/${REPO}/collaborators/${USER}/permission" --jq '.permission' 2>/dev/null || echo "none") |
Prompt To Fix With AI
This is a comment left during a code review.
Path: .github/workflows/agentic-ci-pr-review.yml
Line: 71
Comment:
**Permission lookup fails the gate**
When a non-collaborator opens a PR, this lookup can return 404. Without the previous fallback, the runner’s default `bash -e` stops the gate before it writes `allowed=false`. External contributors then get a failed workflow run instead of a clean skip.
```suggestion
PERMISSION=$(gh api "repos/${REPO}/collaborators/${USER}/permission" --jq '.permission' 2>/dev/null || echo "none")
```
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
chtruong814
left a comment
There was a problem hiding this comment.
We should probably close this for now. I can start a conversation with the maintainer of this repo and you so we can share our thoughts but another team owns this.
Background
The legacy review workflow still runs Claude Code. Reviews are moving to an explicit
/reviewrequest handled by the central review capability.What changed
/reviewguidance comment.review-codeskill and document the local legacy recipe’s publication boundary..agents/skills/review-code/SKILL.md.Details
CI-Events registration and publisher wiring are tracked in CI-Events-Workflows #2450. New skill sources must reach protected
main, and their Ready Plugin snapshots must contain the configured rubric, before enabling the profile.flowchart LR A[PR event or manual dispatch] --> B[Existing authorization gate] B -->|Allowed| C[Post /review guidance] C --> D[Maintainer requests /review] D --> E[Central review capability]Tested
actionlint .github/workflows/agentic-ci-pr-review.yml— passed.ghand a multiline notice containing backticks and$()— exact arguments and stdin preserved; no shell expansion occurred.pre-commit run --files .agents/recipes/pr-review/recipe.md .github/workflows/agentic-ci-pr-review.yml— passed.git diff --check— passed.markupsafe==3.0.4has no compatible CPython 3.14 distribution. This PR does not change dependencies.