-
Notifications
You must be signed in to change notification settings - Fork 1
ci(review-swarm): guard wrapper from candidates #285
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,26 @@ | ||
| name: Review swarm wrapper guard | ||
|
|
||
| on: | ||
| pull_request_target: | ||
| types: [opened, synchronize, reopened, ready_for_review] | ||
|
|
||
| permissions: | ||
| contents: read | ||
| pull-requests: read | ||
|
|
||
| jobs: | ||
| guard: | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| # pull_request_target always reads this workflow and script from the PR | ||
| # base. A candidate therefore cannot relax the guard that evaluates it. | ||
| - uses: actions/checkout@v4 | ||
| with: | ||
| ref: ${{ github.event.pull_request.base.sha }} | ||
| persist-credentials: false | ||
|
|
||
| - name: Reject candidate-owned wrapper changes | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| REVIEW_PR_NUMBER: ${{ github.event.pull_request.number }} | ||
| run: .github/workflows/scripts/swarm-wrapper-guard.sh "$REVIEW_PR_NUMBER" |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,11 @@ | ||
| #!/usr/bin/env bash | ||
| set -euo pipefail | ||
|
|
||
| response=${1:-} | ||
| reason=$(jq -r '.result.error // .error // empty' <<<"$response" 2>/dev/null) | ||
| if [ -n "$reason" ]; then | ||
| safe_reason=$(printf '%s\n' "$reason" | sed 's/^/ /') | ||
| echo "swarm failure reason:" >&2 | ||
| printf '%s\n' "$safe_reason" >&2 | ||
| { echo "### Swarm failure reason"; echo; printf '%s\n' "$safe_reason"; } >> "$GITHUB_STEP_SUMMARY" | ||
| fi |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,12 @@ | ||
| #!/usr/bin/env bash | ||
| set -euo pipefail | ||
|
|
||
| pr_number=${1:?usage: swarm-wrapper-guard.sh PR_NUMBER} | ||
| changed_files=$(gh api --paginate "repos/${GITHUB_REPOSITORY}/pulls/${pr_number}/files" --jq '.[].filename') | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
When a PR renames AGENTS.md reference: AGENTS.md:L34-L34 Useful? React with 👍 / 👎. |
||
|
|
||
| if grep -Fxq '.github/workflows/review-swarm.yml' <<<"$changed_files"; then | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Guard misses renamed wrapper fileMedium Severity The guard only reads each file's Reviewed by Cursor Bugbot for commit 8a8ece9. Configure here. |
||
| echo "candidate changes review-swarm.yml; wrapper enforcement is base-owned and immutable" >&2 | ||
| exit 1 | ||
| fi | ||
|
|
||
| echo "REVIEW_SWARM_WRAPPER_GUARD_OK" | ||


There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Diagnostic script path is wrong
High Severity
The wait step calls
swarm-status-diagnostic.shvia../gate-fileswithoutworking-directory: pr-head, so the path resolves outside the workspace.set +eswallows that miss, and swarm failure reasons never reach the log or step summary.Reviewed by Cursor Bugbot for commit 8a8ece9. Configure here.