Repository navigation
🐛 fix(code-review): preserve workflow identity - #42
Conversation
- 🐛 replace the stripped HTML marker with a readable, stable workflow footer
|
| Filename | Overview |
|---|---|
| .github/workflows/code-review.yml | The workflow now consistently stamps its own comments, recognizes exact current and legacy markers, and confines Bash access to generated read-only query and diff wrappers. |
Reviews (12): Last reviewed commit: "🐛 fix(code-review): close bash write su..." | Re-trigger Greptile
There was a problem hiding this comment.
Pull request overview
This PR updates the code-review workflow prompt so the review agent can reliably identify its own prior inline review comments across runs, replacing the previously hidden HTML marker (which was being sanitized away) with a human-readable footer and using a stable workflow ID.
Changes:
- Switch previous-comment discovery from an HTML marker to a human-readable footer containing a stable workflow ID.
- Instruct the agent to end each inline review comment with the footer on its own line to support cross-run deduplication.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4f680426c5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
- 🐛 make comment identity durable across model output and legacy markers
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.
Suppressed comments (3)
.github/workflows/code-review.yml:194
- P1: The stamp step’s footer check only matches comments that end exactly with
\n<FOOTER>(or are exactly the footer). If the comment body already ends with the footer but also has a trailing newline, this will incorrectly append a second footer.
body="$(printf '%s' "$encoded_body" | base64 --decode)"
if [[ "$body" == "$REVIEW_FOOTER" || "$body" == *$'\n'"$REVIEW_FOOTER" ]]; then
continue
fi
.github/workflows/code-review.yml:141
- P1: The jq
ends_with_footerhelper doesn’t handle trailing newlines (e.g. comments ending with...\nAutomated review …\n). That can cause the workflow to miss its own prior comments and re-post duplicates, which is exactly what this PR is trying to prevent. Consider trimming trailing CR/LF before matching the footer.
This issue also appears on line 191 of the same file.
`gh api repos/${{ github.repository }}/pulls/${{ env.PR_NUMBER }}/comments --paginate --jq 'def ends_with_footer($footer): . == $footer or endswith("\n" + $footer); [.[] | select(.user.login == "github-actions[bot]" and (.body | (ends_with_footer("Automated review · workflow-id: krosdai/.github/code-review/v1") or ends_with_footer("<!-- claude-code-review -->"))) and .in_reply_to_id == null)]'`
.github/workflows/code-review.yml:186
- P2: The stamp step will append the footer to any new top-level
github-actions[bot]PR review comment created after the snapshot, even if it was created by other automation in the same repo. That undermines the goal of using the footer to distinguish this workflow’s comments and can mutate unrelated bot comments.
"repos/${{ github.repository }}/pulls/${{ env.PR_NUMBER }}/comments" \
--paginate \
--jq '.[] | select(.user.login == "github-actions[bot]" and .in_reply_to_id == null) | [.id, (.body | @base64)] | @tsv' |
while IFS=$'\t' read -r comment_id encoded_body; do
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 15ab5a16e8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
- 🐛 attach workflow identity through a deterministic `PreToolUse` hook
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a5c32d2e85
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 2 out of 2 changed files in this pull request and generated no new comments.
Suppressed comments (3)
.github/workflows/code-review.yml:125
- P2: The hook settings file is generated without verifying that the hook script exists at the computed path. If the sparse checkout path changes or the file is missing, the failure will only surface later when posting the first inline comment, making the workflow harder to diagnose. Fail fast by checking for the hook file before writing settings.
hook_path="${{ inputs.pr_number && '.review-policy/.github/scripts/stamp-review-comment.sh' || '.github/scripts/stamp-review-comment.sh' }}"
jq -n \
--arg command "bash \"$GITHUB_WORKSPACE/$hook_path\"" \
'{hooks: {PreToolUse: [{matcher: "mcp__github_inline_comment__create_inline_comment", hooks: [{type: "command", command: $command, timeout: 10}]}]}}' \
> "$RUNNER_TEMP/code-review-settings.json"
.github/workflows/code-review.yml:142
- P2: The jq predicate used to find prior comments requires the body to end exactly with the footer/marker, so a trailing newline (common when tools format output) will prevent matching. That can break cross-run deduplication during migration. Consider trimming trailing newlines before the ends-with check.
`gh api repos/${{ github.repository }}/pulls/${{ env.PR_NUMBER }}/comments --paginate --jq 'def ends_with_footer($footer): . == $footer or endswith("\n" + $footer); [.[] | select(.user.login == "github-actions[bot]" and (.body | (ends_with_footer("Automated review · workflow-id: krosdai/.github/code-review/v1") or ends_with_footer("<!-- claude-code-review -->"))) and .in_reply_to_id == null)]'`
.github/scripts/stamp-review-comment.sh:27
- P2: The stamping hook only considers an exact footer match with no trailing newline. If the model (or toolchain) includes a trailing newline after the footer, the hook will append a second footer. Also, when the incoming body is empty, the current logic produces a comment body starting with blank lines ("\n\n"). Normalizing trailing newlines and handling empty bodies avoids duplicate footers and odd formatting.
if $body == $footer or ($body | endswith("\n" + $footer)) then
$body
else
$body + "\n\n" + $footer
end
- 🐛 generate and self-test the footer hook before exposing review tools
- 🐛 stamp bounded replies and preserve resolved finding coverage
- 🐛 remove reply writes and reject shell composition in the review agent
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 1 changed files in this pull request and generated 1 comment.
Suppressed comments (1)
.github/workflows/code-review.yml:247
- P2: The review-thread jq filter assumes every
reviewThreadhas at least one comment ($comments[0]). If GitHub ever returns an emptycomments.nodesarray (e.g., deleted/top-level comment edge cases), this will throw and break the thread-dedup query for the whole PR run. Add a length guard before indexing.
.[].data.repository.pullRequest.reviewThreads.nodes[]
| .comments.nodes as $comments
| $comments[0] as $top
| select($top.author.login == "github-actions")
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 67ea68d. Configure here.
- 🐛 randomize generated paths and validate quoted shell operators
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.
Suppressed comments (1)
.github/workflows/code-review.yml:284
- P2: Legacy-marker migration may miss older comments if the
<!-- claude-code-review -->marker was appended at the end of the last line (not on its own line).ends_with_marker($legacy)only matches the marker when it is the entire body or preceded by a newline, so unresolved legacy threads could be invisible to the deduplication query and get re-commented.
| select(
$top.body
| (ends_with_marker($footer) or ends_with_marker($legacy))
)
- 🐛 expose only fixed read-only query and diff commands
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.
Suppressed comments (1)
.github/workflows/code-review.yml:253
- P1: The prior-thread GraphQL query filters for
$top.author.login == "github-actions", but Actions-authored comments typically have logingithub-actions[bot]. This will likely return an empty set and break deduplication (causing duplicate inline comments each run). Consider matchinggithub-actions[bot](and optionally keepinggithub-actionsas a fallback).
| $comments[0] as $top
| select($top.author.login == "github-actions")
| select(



Summary
PreToolUsehookValidation
pnpm lint400/500/500git log --output=...cannot reach its native file-write path