Skip to content

🤖 ci: Sync Docs With LibreChat dev Weekly - #796

Open
berry-13 wants to merge 2 commits into
mainfrom
berry-13/docs-sync-automation
Open

berry-13 wants to merge 2 commits into
mainfrom
berry-13/docs-sync-automation

Conversation

@berry-13

@berry-13 berry-13 commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

Adds a weekly workflow that keeps the docs in step with LibreChat dev. It lists the commits merged since the last synced commit, has Claude triage them, verify each change against the app source and write the missing English docs, then opens or refreshes a single draft PR with a report of what changed, what needed no docs, and what needs a human. Nothing merges on its own.

The sync marker in .github/docs-sync/state.json advances only when that PR merges, so an unmerged run is regenerated with the wider range next time. It starts after the commit #795 was audited against. The instructions in .github/docs-sync/prompt.md encode the conventions from #795 and assume the versioned docs from #770, so merge #770 first.

Because the agent reads untrusted text, it may only edit content/docs and its report, run read-only git commands, and never sees a stored token; the job fails if git config or hooks change, and rejects locale files, other paths, and dashes used as punctuation.

Before it can run, a maintainer needs to add the ANTHROPIC_API_KEY secret and, so CI runs on the sync PR, an optional DOCS_SYNC_TOKEN.

Change Type

  • CI / automation

Testing

  • actionlint 1.7.12: clean apart from a false positive on the action's conclusion output, which exists in action.yml at v1
  • YAML parses; the workflow has not run yet, since it needs the secret (first run via workflow_dispatch)

Checklist

  • No em dashes in added text

Review the commits merged to LibreChat dev since the last synced commit,
let Claude document what needs it, and open or refresh one draft pull
request. The sync marker in .github/docs-sync/state.json only advances when
that pull request merges.

The agent reads untrusted text, so it can only edit content/docs and its
report, only run read-only git commands, and never sees a stored token; the
job fails if git config or hooks change, and refuses locale files, files
outside content/docs, and dashes used as punctuation.
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
librechat-ai Ready Ready Preview Oct 2, 2026 9:41am UTC

Request Review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T09:42:47.678371Z 8f7e269 New commits
🔒 Security Review ✅ Completed 2026-10-02T09:30:45.727778Z d3e7db6 PR opened

Security findings

Advisory findings (1)

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d3e7db6dc5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +84 to +85
git -C .sync/librechat log --reverse --no-merges \
--format='%H %as %s' "${since}..origin/dev" | head -n "$MAX_COMMITS" > .sync/commits.txt

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve merge boundaries in the sync marker

When the range crosses an upstream merge with new commits on both parents, --no-merges leaves incomparable parent-side commits in this file, while last later selects only one of them as the persisted marker. Git's A..B revision range excludes only commits reachable from A, so the next run sees the other parent, saves that SHA, and subsequent runs can alternate between the two sides indefinitely. I reproduced this with a two-parent merge; the workflow repeatedly reviews the same commits and never converges. Derive the checkpoint from a merge or first-parent boundary that contains the entire reviewed set rather than the final line of the filtered log.

Useful? React with 👍 / 👎.

claude_args: |
--model ${{ inputs.model || 'claude-opus-5-5' }}
--max-turns 400
--allowedTools "Read,Glob,Grep,Task,TodoWrite,Edit(./content/docs/**),Write(./content/docs/**),Edit(./.sync/report.md),Write(./.sync/report.md),Bash(git -C .sync/librechat show:*),Bash(git -C .sync/librechat log:*),Bash(git -C .sync/librechat grep:*),Bash(git -C .sync/librechat ls-tree:*),Bash(git -C .sync/librechat diff:*),Bash(git diff:*),Bash(git status:*),Bash(ls:*),Bash(wc:*)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep the API credential out of agent-readable subprocesses

Because this step deliberately processes untrusted commit messages and source, an injected instruction can use the permitted Bash rule to run git diff --no-index /dev/null - < /proc/self/environ; --no-index accepts arbitrary inputs, and the shell redirection exposes its inherited environment, including ANTHROPIC_API_KEY, in the tool result. The model can then place the recovered value in the permitted .sync/report.md, which the later gh pr create or gh pr edit publishes as the PR body. persist-credentials: false protects the GitHub credential but not this API key, so run the agent tools with secrets scrubbed from their subprocess environment or in a sandbox that prevents access to the parent environment.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛡️ Codex Security Review · Automatically triggered

Here are some automated security review suggestions for this pull request.

Reviewed commit: d3e7db6dc5

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

claude_args: |
--model ${{ inputs.model || 'claude-opus-5-5' }}
--max-turns 400
--allowedTools "Read,Glob,Grep,Task,TodoWrite,Edit(./content/docs/**),Write(./content/docs/**),Edit(./.sync/report.md),Write(./.sync/report.md),Bash(git -C .sync/librechat show:*),Bash(git -C .sync/librechat log:*),Bash(git -C .sync/librechat grep:*),Bash(git -C .sync/librechat ls-tree:*),Bash(git -C .sync/librechat diff:*),Bash(git diff:*),Bash(git status:*),Bash(ls:*),Bash(wc:*)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛡️ Codex Security Review · Automatically triggered

P1 Badge Security: Remove command-executing options from the agent allowlist

When ANTHROPIC_API_KEY is configured, an attacker whose text reaches LibreChat dev can prompt-inject the scheduled agent into invoking git -C .sync/librechat grep --open-files-in-pager=<command> .... This matches the allowed git ... grep:* prefix, but Git executes the supplied pager as a shell command. It can persist BASH_ENV through $GITHUB_ENV; the later PR step starts Bash with GH_TOKEN (the optional PAT or contents/PR-write job token), enabling credential theft and repository writes. The workspace checks do not inspect runner environment files. Replace general Git Bash access with a fixed argument-validating wrapper.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8f7e2693fb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +84 to +85
git -C .sync/librechat log --reverse --no-merges \
--format='%H %as %s' "${since}..origin/dev" | head -n "$MAX_COMMITS" > .sync/commits.txt

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Include changes made directly in merge commits

When a merge commit contains conflict-resolution or other manual edits not present in either parent, --no-merges removes the only commit whose diff exposes those changes. The agent therefore never triages them, and once a later non-merge commit advances the marker, the documentation change is permanently skipped; include nontrivial merge commits in the review input or separately inspect their merge-result diffs.

Useful? React with 👍 / 👎.

exit 1
fi
git -C .sync/librechat log --reverse --no-merges \
--format='%H %as %s' "${since}..origin/dev" | head -n "$MAX_COMMITS" > .sync/commits.txt

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Avoid truncating the Git pipeline under pipefail

When the pending range is large enough for head to close the pipe before git log finishes, the Actions default Bash shell runs with -o pipefail, so Git's resulting SIGPIPE status (141) makes this step fail instead of processing the requested batch. I reproduced the exact git log | head shape with more than 150 commits; because the marker is never advanced, every scheduled retry encounters the same backlog and fails again. The Bash pipeline semantics specify that pipefail returns the rightmost nonzero command status, so apply the limit within Git (for example with -n) rather than truncating its output through head.

Useful? React with 👍 / 👎.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

📦 Next.js Bundle Analysis for librechat.ai

This analysis was generated by the Next.js Bundle Analysis action. 🤖

This PR introduced no changes to the JavaScript bundle! 🙌

This branch was successfully deployed

1 active deployment
Preview — 8f7e2693 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant