fix(ci): repoint io-triage to wave-foundation-public mirror - #41
Conversation
The public->private uses: reference produces a startup_failure with no jobs, no logs, and no visible check - it is invisible on issue events. Repoint all three pointers (uses/scripts_repo/scripts_ref) to the published mirror at the pinned SHA.
|
Your free trial PR review limit of 300 PRs has been reached. Please upgrade your plan to continue using CodeAnt AI. |
|
ⓘ Qodo reviews are paused because your workspace is out of credits. Ask your workspace admin to add credits to resume reviews. Manage billing |
There was a problem hiding this comment.
Sorry @yakimoto, this account has used its review budget of 2,500,000 diff characters for the last 7 days.
You can request another review in 1 day and 4 hours by commenting @sourcery-ai review.
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_6416f412-8dcb-4acf-acfe-17806e0d5bdf) |
Reviewer's guide (collapsed on small PRs)Reviewer's GuideFix issue triage startup failures in this public repository by switching all three dependency pointers—the reusable workflow, script repository, and script ref—to the public mirror at the same pinned commit, enabling the workflow to start and load its scripts. Sequence diagram for public issue triage workflow executionsequenceDiagram
participant GitHub as GitHub Actions
participant Workflow as Public io-triage workflow
participant Mirror as wave-foundation-public
participant Scripts as issue-ops scripts
GitHub->>Workflow: issues event
Workflow->>Mirror: sparse-checkout scripts at f63b91566ab311b09599db6195da8c353cab1f69
Mirror-->>Workflow: scripts/issue-ops
Workflow->>Scripts: execute triage scripts
Scripts-->>GitHub: update issue triage
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (1)
Included review availability: 0 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. 📜 Recent review details⏰ Context from checks skipped due to timeout. (3)
🧰 Additional context used🪛 zizmor (1.29.0).github/workflows/issue-ops-triage.yml[warning] 17-17: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment (undocumented-permissions) 🔇 Additional comments (1)
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe issue triage workflow now uses the public ChangesIssue triage workflow
Estimated code review effort: 1 (Trivial) | ~2 minutes Merge Risk: ⚪ Minimal · up to The workflow now points its reusable workflow and runtime scripts to the same pinned public mirror, restoring issue triage for this public repository; no actionable merge-blocking risk remains after normal checks and review. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Full details: Docstring CoverageExplanation No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.) ✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
Code Review ✅ ApprovedRepoints the issue-ops-triage workflow from the private OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — The three pointer updates restore issue triage but also switch the secret-bearing reusable workflow and runtime scripts to a different repository. Although both sources are pinned and the change is narrowly scoped, the resulting execution and credential trust-boundary change merits human review. Not approved because:
Review your spending limits in Billing settings. You can add or adjust custom eligibility rules. Learn more. |
Repoints
.github/workflows/issue-ops-triage.ymlfrom the privatewave-av/wave-foundationrepo to the published public mirrorwave-av/wave-foundation-public.Symptom. This is a public repo.
Actions -> issue-ops-triageshows 7 consecutivefailureconclusions on theissuesevent. Every run fails with zero jobs and zero logs - it never showed as a check anywhere, because it triggers onissues, notpull_request, so there was no PR check rollup to notice it in either. Issue triage has effectively never worked on this repo.Cause. A public repo cannot
uses:a reusable workflow hosted in a private repo (wave-av/wave-foundation). GitHub Actions refuses the job before it starts (startup_failure) - no job list, no log output, nothing actionable in the UI beyond the bare failed run.Fix - three pointers, all required together:
uses:->wave-av/wave-foundation-public/.github/workflows/io-triage.yml@f63b91566ab311b09599db6195da8c353cab1f69scripts_repo:->wave-av/wave-foundation-publicscripts_ref:->"f63b91566ab311b09599db6195da8c353cab1f69"scripts_repo/scripts_refare not optional companions touses:-io-triage.ymldoes not embed its scripts; it does asparse-checkoutofscripts/issue-opsfromscripts_repoatscripts_refand executes them at runtime. Moving onlyuses:clears thestartup_failureand then fails one step later on a checkout of a private repo the caller repo token cannot read. All three must move together, to the same pinned SHA.This exact fix is proven green on the pilot repo (
wave-av/adk, first success in 9 runs all-time, 2026-09-01T13:07) after all seven scripts in the io-triage dependency closure were published to the mirror.Verify after merge (by run outcome, not the PR check rollup - this workflow does not run on
pull_request):Expect a
success(or at minimum nostartup_failure) on the nextissues: opened/editedevent.Change is scoped to exactly these three YAML values; nothing else in the file was touched.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Note
Low Risk
CI-only pointer updates to a known public mirror; no application or secret-handling logic changes in this repo.
Overview
Fixes issue-ops triage on this public repo by moving all three workflow dependencies from private
wave-av/wave-foundationto the public mirrorwave-av/wave-foundation-public, pinned to SHAf63b915.The reusable workflow
uses:target, plusscripts_repoandscripts_ref(used for sparse-checkout ofscripts/issue-opsat runtime), are updated together so runs no longer hit GitHub’sstartup_failurefrom calling a private reusable workflow—or a later checkout failure on the private scripts repo.Reviewed by Cursor Bugbot for commit 8afff04. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by Sourcery
Fix issue triage failures by using the public wave-foundation mirror for both the reusable workflow and its scripts.
Bug Fixes:
CI: