Repository navigation
Add CI gates, close out cycle 0006, and refine guidance - #3
Conversation
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 2 minutes and 9 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (4)
WalkthroughThe PR adds a GitHub Actions CI workflow that runs install/build/test on push and pull_request, updates Node engine to >=22, adds CI design/docs, augments METHOD process docs to include close → PR/review → ship-sync sequencing, adds retro/witness artifacts, new tests asserting CI/docs consistency, and ignores Changes
Sequence Diagram(s)sequenceDiagram
actor Developer
participant Repo as "Repository (.github/... , docs)"
participant GH_Actions as "GitHub Actions"
participant Runner as "ubuntu-24.04 · Node 22"
Developer->>Repo: push / open PR
Repo->>GH_Actions: trigger CI (push / pull_request)
GH_Actions->>Runner: checkout + setup-node (node 22) + npm cache
Runner->>Runner: npm ci
Runner->>Runner: npm run build
Runner->>Runner: npm test
Runner-->>GH_Actions: job result (pass/fail)
GH_Actions-->>Repo: status updated
GH_Actions-->>Developer: actionable feedback (logs)
Estimated Code Review Effort🎯 3 (Moderate) | ⏱️ ~23 minutes Possibly Related PRs
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/ci.yml:
- Around line 3-5: The workflow triggers currently use top-level keys push and
pull_request with no branch filters (symbols: on, push, pull_request), causing
CI to run on every branch and PR; to restrict it, add branch filters under those
keys (e.g., set branches: [main] or appropriate release branches for push and
branches: [main] or targets for pull_request) or use branches-ignore to exclude
ephemeral branches so CI only runs for the intended branches/PR targets.
- Around line 10-34: The "test" GitHub Actions job lacks a timeout, risking hung
runs consuming runner minutes; add a timeout by setting the job-level
timeout-minutes (e.g., in the "test" job block) to a reasonable value (such as
10 or 30) so the job will be terminated automatically if it exceeds that time;
update the job definition that contains "jobs: -> test:" and leave other fields
like "runs-on", "strategy", "steps" and the matrix (node-version) untouched.
In `@docs/design/0006-ci-gates/ci-gates.md`:
- Around line 34-36: Update the contract wording to use the plural "Node
versions" where the document currently says "Node version" so it matches the
two-version matrix; specifically change the phrase at the header/context
paragraph (the occurrence around "Node version") and the related mention near
the matrix definition (the section that lists the matrix values `18`, `22`) so
the language is unambiguous about multiple Node versions being tested.
In `@docs/method/backlog/up-next/PROCESS_git-branch-workflow-policy.md`:
- Around line 20-22: Replace the ambiguous phrase "git-aware and forge-aware,
but not forge-dependent doctrine" with the clearer policy wording
"forge-agnostic at the core, with forge-aware adapters" in the
PROCESS_git-branch-workflow-policy.md content; ensure the sentence preserves
surrounding context about GitHub workflow/PR cockpit and adjust punctuation for
grammatical flow so the policy intent is explicit and stable.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: b700c736-861e-4034-a42e-1d8bc7e59ac4
📒 Files selected for processing (14)
.github/workflows/ci.yml.gitignoreREADME.mddocs/design/0006-ci-gates/ci-gates.mddocs/method/backlog/asap/PROCESS_ci-gates.mddocs/method/backlog/inbox/PROCESS_retro-conversational-closeout.mddocs/method/backlog/up-next/PROCESS_git-branch-workflow-policy.mddocs/method/guide.mddocs/method/process.mddocs/method/retro/0006-ci-gates/ci-gates.mddocs/method/retro/0006-ci-gates/witness/README.mddocs/method/retro/0006-ci-gates/witness/playback.mddocs/method/retro/0006-ci-gates/witness/verification.mdtests/docs.test.ts
💤 Files with no reviewable changes (1)
- docs/method/backlog/asap/PROCESS_ci-gates.md
|
Resolved the remaining live review threads.
Local verification for the current branch tip:
|
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In @.github/workflows/ci.yml:
- Around line 15-16: Add the optional hardening to the GitHub Actions checkout
step: in the step named "Checkout repository" (uses: actions/checkout@v4)
include the key persist-credentials: false so the token is not left in the local
git config for subsequent steps; update that step to add this option while
keeping other existing fields intact.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 84b3e231-dc02-4626-bb37-b3c2b22034e2
📒 Files selected for processing (9)
.github/workflows/ci.ymlREADME.mddocs/design/0006-ci-gates/ci-gates.mddocs/method/backlog/up-next/PROCESS_git-branch-workflow-policy.mddocs/method/retro/0006-ci-gates/ci-gates.mddocs/method/retro/0006-ci-gates/witness/playback.mddocs/method/retro/0006-ci-gates/witness/verification.mdpackage.jsontests/docs.test.ts
|
Final follow-up for the last live CodeRabbit thread:
Local verification for the current branch tip:
|
Summary
This PR closes out cycle
0006-ci-gates, adds the repo's first CI gate, and folds in two small guidance captures that surfaced during the work.It does five things:
npm ci,npm run build, andnpm testonpushandpull_requestubuntu-24.04, scopes token permissions tocontents: read, and standardizes the repo on Node220006-ci-gatescycle with retro and witness artifactsmainafter mergedocs/method/guide.mdand captures the retro conversational closeout idea in the backlogWhy
Recent review feedback correctly pointed out that METHOD was claiming strict review and drift discipline without any automated build/test gate. This cycle fixes that gap while keeping the first cut narrow and explicit.
The branch also exposed two doctrine issues worth correcting now rather than leaving as chat-only context:
The first CI attempt also proved that the current test toolchain does not support Node
18. Rather than pretend otherwise, this PR now aligns the repo contract, CI, and docs on Node22.Impact
>=22Validation
npm testnpm run buildnpm run method -- status