fix(ci): make the docs-bot changelog exemption actually match - #3683
Conversation
The changelog gate exempted the docs bot by comparing the pull request author against "app/lightspeed-docs-bot", which is the shape GraphQL reports. The webhook payload this gate reads carries the REST shape, "lightspeed-docs-bot[bot]", so the comparison never matched and the exemption was dead code. Every docs-bot pull request fell through to the changelog requirement, including the fixed-branch README regeneration and metrics pull requests, which have no user-facing content to record. Observed on #3603 and #3448, both opened by app/lightspeed-docs-bot, both failing `Require changelog or skip label`. The other two bot exemptions in the repository are unaffected and stay as they are: pr-template-routing.yml:152 and ai-feedback-validation.yml:63 already use the webhook form, which is why those checks passed on the same pull requests. Rather than swapping one literal for another, both exemptions now compare a normalised slug, so they hold whichever shape GitHub supplies. That also retires the dead "app/dependabot" alternative beside the Dependabot check, which had been carrying the same ambiguity in the opposite direction. tests/js/bot-author-exemptions.test.js extracts the normaliser from the workflow and executes it against both forms for both bots, asserts near-miss slugs and ordinary accounts are not swept in, and pins the two already-correct workflows to the webhook form so a future edit cannot reintroduce the mismatch there. Verified non-vacuous: 4 of its 7 tests fail against the previous version of the workflow.
|
ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: lightspeedwp/.github/.coderabbit.yml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe changelog workflow normalizes pull request author logins before checking Dependabot and docs-bot exemptions. Tests cover both login forms, selected non-exempt logins, and related workflow checks. ChangesChangelog bot-author exemptions
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~12 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The bot-login exemption change is ready to merge after normal checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Docs-bot pull requests will now bypass the changelog gate even when their files or labels change. Other review requirements remain, but the scope of this exemption and the result of skipping a required validation job need confirmation. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 1 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Warning Some tools did not complete. Review the errors below. 🔧 ESLint
tests/js/bot-author-exemptions.test.js(node:2) ESLintIgnoreWarning: The ".eslintignore" file is no longer supported. Switch to using the "ignores" property in "eslint.config.js": https://eslint.org/docs/latest/use/configure/migration-guide#ignore-files Oops! Something went wrong! :( ESLint: 10.10.0 ReferenceError: module is not defined in ES module scope Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
No description provided. |
PR Template RoutingBranch Type: This PR was automatically routed based on the branch naming strategy. |
📋 Changelog Quality Validation
Status✅ Validation PASSED - No new failures introduced by this PR. No action required. |
The changelog quality gate reported one new critical failure, CHK_MAX_LENGTH: the entry was 403 characters against a 250 limit. Trimmed to 214, keeping the issue references and the user-facing effect. Verified with the gate's own validator rather than by inspection: `.github/validation/changelog` reports Non-Compliant 10, which is the pre-existing baseline on develop, so this entry introduces no new failures.
Linked issues
Refs #3603 and #3448 — both opened by the docs bot, both failing
Require changelog or skip labelfor the same reason.Closes nothing: this fixes a gate in the repository that governs automation, not a customer-facing defect, and the two pull requests above were unblocked separately with the
meta:no-changeloglabel rather than by this change.Context
developand any consuming repository..github/workflows/changelog-unified.yml, plus a test.Reproduction
Open any pull request authored by
app/lightspeed-docs-botthat touches at least one non-Markdown file, so the docs-only exemption does not apply.Require changelog or skip labelfails:Observed on chore: Update branch validation metrics #3603 and chore(docs): regenerate impacted README files #3448.
The gate logs no exemption message at any point, which is the tell: the branch that should have returned early was never entered.
Root Cause
The gate compared the author against the GraphQL login shape while reading the webhook payload, which carries the REST shape:
lightspeed-docs-bot[bot]pull_request.user.loginin the event payloadapp/lightspeed-docs-botauthor.loginchangelog-unified.yml:74compared againstapp/lightspeed-docs-bot, so it never matched. The same file had the mirror-image problem at line 65, listingapp/dependabotas an alternative for Dependabot: the Dependabot exemption still worked because the correct form sat beside the dead one, so the bug was invisible there and fatal for the docs bot.This survived review because
gh pr view --json authorreturns the GraphQL form, so checking the string by hand gives the reassuring answer.Fix Summary
Both exemptions now compare a normalised slug, so they hold whichever shape GitHub supplies:
That also retires the dead
app/dependabotalternative, which carried the same ambiguity in the opposite direction.The two other bot exemptions in the repository are not affected and are left untouched:
pr-template-routing.yml:152andai-feedback-validation.yml:63already use the webhook form, which is why those checks passed on the very same pull requests. A test now pins them so a future edit cannot reintroduce the mismatch there.Verification
tests/js/bot-author-exemptions.test.jsextracts theslugarrow function out of the workflow and executes it against both shapes for both bots, rather than pattern-matching the text. It also asserts near-miss slugs and ordinary accounts are not swept in.npx jest --config .jest.config.cjs tests/js/bot-author-exemptions.test.js— 7 passedNon-vacuity checked: against develop's current workflow, 4 of 7 fail, including both shape-agreement tests:
actionlint .github/workflows/changelog-unified.yml— cleannpm run validate:workflows— 14 passed, 0 failednpx jest --config .jest.config.cjs— 297 suites, 6151 tests, 0 failuressemgrep --config p/security-audit --config p/secrets --config p/phpon both changed paths — 0 findingscoderabbit review --base develop— 2 files reviewed, no findingsThe bare forms
dependabotandlightspeed-docs-botare deliberately matched: the bare slug is what both shapes reduce to, and both names are reserved so a human account cannot hold them.Risk & Rollback
Changelog
Entry added under
CHANGELOG.md→[Unreleased]→Fixed:Scope
Workflow fix, its test, and the changelog entry. Not bundled with #3604 or #3532.
Summary by CodeRabbit