Skip to content

fix(ci): repoint io-triage to wave-foundation-public mirror - #41

Merged
yakimoto merged 1 commit into
mainfrom
fix/repoint-io-triage-to-mirror
Sep 1, 2026
Merged

yakimoto merged 1 commit into
mainfrom
fix/repoint-io-triage-to-mirror

Conversation

@yakimoto

@yakimoto yakimoto commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Repoints .github/workflows/issue-ops-triage.yml from the private wave-av/wave-foundation repo to the published public mirror wave-av/wave-foundation-public.

Symptom. This is a public repo. Actions -> issue-ops-triage shows 7 consecutive failure conclusions on the issues event. Every run fails with zero jobs and zero logs - it never showed as a check anywhere, because it triggers on issues, not pull_request, so there was no PR check rollup to notice it in either. Issue triage has effectively never worked on this repo.

Cause. A public repo cannot uses: a reusable workflow hosted in a private repo (wave-av/wave-foundation). GitHub Actions refuses the job before it starts (startup_failure) - no job list, no log output, nothing actionable in the UI beyond the bare failed run.

Fix - three pointers, all required together:

  1. uses: -> wave-av/wave-foundation-public/.github/workflows/io-triage.yml@f63b91566ab311b09599db6195da8c353cab1f69
  2. scripts_repo: -> wave-av/wave-foundation-public
  3. scripts_ref: -> "f63b91566ab311b09599db6195da8c353cab1f69"

scripts_repo/scripts_ref are not optional companions to uses: - io-triage.yml does not embed its scripts; it does a sparse-checkout of scripts/issue-ops from scripts_repo at scripts_ref and executes them at runtime. Moving only uses: clears the startup_failure and then fails one step later on a checkout of a private repo the caller repo token cannot read. All three must move together, to the same pinned SHA.

This exact fix is proven green on the pilot repo (wave-av/adk, first success in 9 runs all-time, 2026-09-01T13:07) after all seven scripts in the io-triage dependency closure were published to the mirror.

Verify after merge (by run outcome, not the PR check rollup - this workflow does not run on pull_request):

gh run list --repo wave-av/examples --workflow issue-ops-triage.yml --json conclusion

Expect a success (or at minimum no startup_failure) on the next issues: opened/edited event.

Change is scoped to exactly these three YAML values; nothing else in the file was touched.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Note

Low Risk
CI-only pointer updates to a known public mirror; no application or secret-handling logic changes in this repo.

Overview
Fixes issue-ops triage on this public repo by moving all three workflow dependencies from private wave-av/wave-foundation to the public mirror wave-av/wave-foundation-public, pinned to SHA f63b915.

The reusable workflow uses: target, plus scripts_repo and scripts_ref (used for sparse-checkout of scripts/issue-ops at runtime), are updated together so runs no longer hit GitHub’s startup_failure from calling a private reusable workflow—or a later checkout failure on the private scripts repo.

Reviewed by Cursor Bugbot for commit 8afff04. Bugbot is set up for automated code reviews on this repo. Configure here.

Review in cubic

Summary by Sourcery

Fix issue triage failures by using the public wave-foundation mirror for both the reusable workflow and its scripts.

Bug Fixes:

  • Restore issue triage for the public repository by switching the reusable workflow and its runtime scripts to the published public mirror.

CI:

  • Repoint the issue-ops triage workflow and its pinned scripts reference to the public mirror at a consistent commit.

The public->private uses: reference produces a startup_failure with no
jobs, no logs, and no visible check - it is invisible on issue events.

Repoint all three pointers (uses/scripts_repo/scripts_ref) to the
published mirror at the pinned SHA.
@codeant-ai

codeant-ai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Your free trial PR review limit of 300 PRs has been reached. Please upgrade your plan to continue using CodeAnt AI.

@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your workspace is out of credits. Ask your workspace admin to add credits to resume reviews. Manage billing

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @yakimoto, this account has used its review budget of 2,500,000 diff characters for the last 7 days.

You can request another review in 1 day and 4 hours by commenting @sourcery-ai review.

@cursor

cursor Bot commented Sep 1, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_6416f412-8dcb-4acf-acfe-17806e0d5bdf)

@sourcery-ai

sourcery-ai Bot commented Sep 1, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Fix issue triage startup failures in this public repository by switching all three dependency pointers—the reusable workflow, script repository, and script ref—to the public mirror at the same pinned commit, enabling the workflow to start and load its scripts.

Sequence diagram for public issue triage workflow execution

sequenceDiagram
    participant GitHub as GitHub Actions
    participant Workflow as Public io-triage workflow
    participant Mirror as wave-foundation-public
    participant Scripts as issue-ops scripts

    GitHub->>Workflow: issues event
    Workflow->>Mirror: sparse-checkout scripts at f63b91566ab311b09599db6195da8c353cab1f69
    Mirror-->>Workflow: scripts/issue-ops
    Workflow->>Scripts: execute triage scripts
    Scripts-->>GitHub: update issue triage
Loading

File-Level Changes

Change Details Files
Repoint the reusable issue-triage workflow and its runtime script checkout to the public mirror at one pinned commit.
  • Update the reusable workflow reference from the private repository to the public mirror.
  • Update the script repository and checkout ref to the same public repository and pinned SHA.
  • Preserve the existing permissions, inputs, secrets, gating condition, and all other workflow behavior.
.github/workflows/issue-ops-triage.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Team

Run ID: 33354ef9-a028-489c-90c3-f544215356cc

📥 Commits

Reviewing files that changed from the base of the PR and between 622fb8a and 8afff04.

📒 Files selected for processing (1)
  • .github/workflows/issue-ops-triage.yml

Included review availability: 0 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: Macroscope - Approvability Check
  • GitHub Check: semgrep-cloud-platform/scan
🧰 Additional context used
🪛 zizmor (1.29.0)
.github/workflows/issue-ops-triage.yml

[warning] 17-17: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment

(undocumented-permissions)

🔇 Additional comments (1)
.github/workflows/issue-ops-triage.yml (1)

14-20: LGTM!


📝 Walkthrough

Summary by CodeRabbit

  • Chores
    • Updated issue triage automation to use a publicly accessible workflow.
    • Pinned the workflow to a specific revision for more consistent operation.

Walkthrough

The issue triage workflow now uses the public wave-foundation-public reusable workflow and passes its pinned commit through the script configuration.

Changes

Issue triage workflow

Layer / File(s) Summary
Update triage workflow source
.github/workflows/issue-ops-triage.yml
The reusable workflow and script configuration now reference wave-av/wave-foundation-public at the pinned f63b915... revision.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: ⚪ Minimal · up to 8afff

The workflow now points its reusable workflow and runtime scripts to the same pinned public mirror, restoring issue triage for this public repository; no actionable merge-blocking risk remains after normal checks and review.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description check ✅ Passed The description clearly explains the workflow failure and the three coordinated pointer updates to the public mirror.
Title check ✅ Passed The title concisely and accurately identifies the CI fix: repointing issue triage to the public mirror.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/repoint-io-triage-to-mirror
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch fix/repoint-io-triage-to-mirror

Comment @coderabbitai help to get the list of available commands.

@gitar-bot

gitar-bot Bot commented Sep 1, 2026

Copy link
Copy Markdown
Code Review ✅ Approved

Repoints the issue-ops-triage workflow from the private wave-av/wave-foundation repo to the public wave-av/wave-foundation-public mirror across all three required YAML pointers (uses, scripts_repo, scripts_ref), fixing consecutive startup failures on this public repo. No issues found.

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@macroscopeapp

macroscopeapp Bot commented Sep 1, 2026

Copy link
Copy Markdown

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The three pointer updates restore issue triage but also switch the secret-bearing reusable workflow and runtime scripts to a different repository. Although both sources are pinned and the change is narrowly scoped, the resulting execution and credential trust-boundary change merits human review.

Not approved because:

  • Credit balance exhausted. Approvability relies on correctness review in order to determine eligibility

Review your spending limits in Billing settings. You can add or adjust custom eligibility rules. Learn more.

@yakimoto
yakimoto merged commit f63dd01 into main Sep 1, 2026
23 checks passed
@yakimoto
yakimoto deleted the fix/repoint-io-triage-to-mirror branch September 1, 2026 14:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant