Skip to content

gardener: Answer reviews on Gardener's pull requests (Gardener 0.1.10) - #188

Merged
scuffi merged 2 commits into
mainfrom
gardener-upgrade-0.1.10
Oct 1, 2026
Merged

scuffi merged 2 commits into
mainfrom
gardener-upgrade-0.1.10

Conversation

@scuffi

@scuffi scuffi commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Adds a pr-review-fix task, so Gardener answers reviews on the pull requests it opens. When a maintainer or Devin reviews one, Gardener checks each unresolved review thread against the code. It fixes the findings it can reproduce, with tests, and pushes one commit onto the pull request's branch. It declines the rest with a reason, then replies once. After three rounds it hands the pull request to a maintainer and stops.

How the task is scoped:

  • It runs only on reviews by maintainers or devin-ai-integration[bot], and only on pull requests opened by github-actions[bot] whose branch starts with gardener/. The generated workflow skips reviews on any other pull request before a job starts.
  • It builds on the pull request's head and pushes only to that branch. If the branch moved since the review, the push is refused rather than overwriting it.
  • Review text is treated as reports to verify, never as instructions. The task never touches workflows or .gardener/.
  • If nothing needs to change, it pushes nothing, which ends the loop.
  • One round runs at a time per pull request.

This PR is the gardener upgrade to 0.1.10, plus the new task:

  • The workflows move to 0.1.10's pinned release.
  • gardener:generate now points at @scuffi/gardener@0.1.10.
  • .gardener/SKILL.md is new: a guide to the task format for coding agents.
  • mention-reply and triage are unchanged, with the same bundle hashes.
  • The runtime is already deployed. Regenerating with the published package changes nothing.

GitHub doesn't run checks on its own for commits made with a workflow's token, so a maintainer approves CI on Gardener's commits.

A review starts a run only once the pull request's merge ref includes this workflow. Pull requests opened before this merges, such as #185, need their branch updated first.

Tested on a demo repository first:

  • Round 1: it fixed a real finding with a test, declined a false one with evidence, pushed one commit on the head and replied.
  • Clean review: it ended with no push.
  • Forged round markers: markers posted by another user were ignored.
  • Fourth review: it posted the hand-over comment without pushing.
  • Fifth review: it did nothing.
  • Pull request it didn't open: a review there was skipped before any job started.

Devin Review

@changeset-bot

changeset-bot Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 39c57b0

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 4 potential issues.

Devin Review

task-source: ".gardener/tasks/pr-review-fix/TASK.md"
task-bundle-hash: 2e496b0e60cf0e1022d276ab65a0543c8b0c8c8a26f768337232bc938f2b4d66
plan-timeout-minutes: 40
checkout-ref: ${{ github.event.pull_request.head.sha }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 Queued review feedback gets stranded

When an earlier round pushes before a queued review starts, checkout-ref still points at the review event's old head. The queued round exits on the head check, leaving feedback posted after the earlier thread fetch unanswered.

Learn more

The job checks out the SHA stored in the review webhook, while the branch check compares that checkout against the current pull request head. Jobs for one pull request are serialized, so a running job can push a commit before a queued review job starts. The queued job then exits as stale even if the earlier job did not see the later review threads. GitHub-token pushes do not start another review run.

Example: Review A starts a job and fetches threads. Review B is submitted while A writes a fix; B's job queues with the old SHA. A pushes, then B starts, detects a different head, and exits without answering B.

Recommended fix: Checkout the current pull request head when the queued job begins, validate it is the guarded PR branch, and use that exact checkout SHA as expectedHeadSha. Preserve the stale-head refusal at commit time if another actor moves the branch.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread .gardener/tasks/pr-review-fix/TASK.md Outdated
Comment on lines +52 to +55
3. **Read the unresolved review threads** with the provider API's GraphQL transport: the pull
request's `reviewThreads` (`isResolved`, `path`, `line`, and each thread's comments with author
and body). Answer every unresolved thread, not only those from the review that started this
run: a round can absorb a review whose own run GitHub dropped.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 General review feedback goes unanswered

When a reviewer submits feedback only in the review body, reviewThreads contains none of it. The task has no review-body read, so it posts an empty round and never addresses that feedback.

Learn more

A submitted pull request review can contain a general body without any inline comments. GitHub's reviewThreads collection contains inline conversations, not that general review body. The task reads only threads after it counts rounds. It can therefore spend a round without evaluating the triggering review's feedback.

Example: A maintainer submits “Please update the migration docs” in the review body with no inline comments. reviewThreads is empty, so the task proposes a round reply but makes no change and does not discuss the request.

Recommended fix: Include the triggering review's body and any applicable review-level feedback in the findings the task verifies; distinguish reviewed feedback from unrelated text, and do not count a round without processing the review.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Comment thread .gardener/tasks/pr-review-fix/TASK.md
tools:
- repository.list_files
- repository.read_file
- repository.exec

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟨 Unrestricted network access for review-triggered shell commands

A submitted review can trigger repository.exec with unrestricted network access despite no explicit user request. The task policy requires an explicit request and disclosure before granting that tool, exposing review runs to unintended network activity.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

@pkg-pr-new

pkg-pr-new Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@cloudflare/computer@188

commit: 39c57b0

@scuffi
scuffi merged commit 60d9002 into main Oct 1, 2026
25 checks passed
@scuffi
scuffi deleted the gardener-upgrade-0.1.10 branch October 1, 2026 15:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant