Skip to content

fix: harden sdk auto-review gate - #26

Merged
mekilis merged 3 commits into
mainfrom
ci/harden-sdk-auto-review
Jul 20, 2026
Merged

fix: harden sdk auto-review gate#26
mekilis merged 3 commits into
mainfrom
ci/harden-sdk-auto-review

Conversation

@mekilis

@mekilis mekilis commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Summary

  • deny paths in the auto-review step now clear any stale auto-merge before commenting, and fail the step if the disable errors instead of swallowing it
  • an empty changed-files listing no longer counts as an allowlist pass
  • approvals are pinned to the head commit this run pushed (base + head-sha checks), and renames are checked on both sides

Follow-up to #25, applying the same review-gate hardening already on the other SDK repos' CI PRs.


Note

Medium Risk
Changes merge automation and approval logic in CI; mistakes could block safe regen merges or briefly affect auto-merge state, but scope is limited to the bot regen workflow.

Overview
Hardens the “Approve and enable auto-merge” step in sdk_generation.yaml so regen PRs only get bot approval when stricter checks pass, and failed gates cannot leave a stale auto-merge enabled.

A shared deny() path now disables auto-merge before commenting on any rejection; with set -euo pipefail, a --disable-auto failure fails the step instead of leaving a bad head mergeable. New gates require base main, PR head equals the commit this run pushed, and reject an empty changed-files API response when the run actually produced a diff.

The generated-path allowlist now considers rename old and new paths (previous_filename). Approvals are submitted with commit_id, then the step re-reads head SHA and dismisses its own review + deny() if the head moved during submission. Gate failures route through deny() instead of ad-hoc comments.

Reviewed by Cursor Bugbot for commit 4bfc8a4. Bugbot is set up for automated code reviews on this repo. Configure here.

mekilis added 2 commits July 20, 2026 20:32
deny paths now clear stale auto-merge before commenting and fail the
step if the disable errors, instead of best-effort || true. an empty
changed-files listing no longer counts as an allowlist pass. renames
are checked on both sides everywhere. approvals are pinned to the
head commit.
pin the approval to the head captured before the allowlist run, then
re-read the head after submitting; if it moved, dismiss the approval
and deny. dismiss_stale_reviews (now enabled) covers pushes after the
review; this covers the window before it.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 1c9193f. Configure here.

Comment thread .github/workflows/sdk_generation.yaml
a dismiss failure under set -e must not skip deny, which is the hard
gate that clears stale auto-merge. dismiss_stale_reviews already
covers the dismissal in the normal case.
@mekilis
mekilis merged commit ac730da into main Jul 20, 2026
3 checks passed
@mekilis
mekilis deleted the ci/harden-sdk-auto-review branch July 20, 2026 20:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant