Skip to content

Retire CodeRabbit: keep its review contract and checks - #21

Merged
PyYoshi merged 2 commits into
mainfrom
chore/retire-coderabbit
Sep 23, 2026
Merged

PyYoshi merged 2 commits into
mainfrom
chore/retire-coderabbit

Conversation

@PyYoshi

@PyYoshi PyYoshi commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

Summary

CodeRabbit is no longer used. Deleting .coderabbit.yaml outright would
have removed two guard layers AGENTS.md relies on, so both are kept.
This is a maintainer decision; the design gate's "new tool / CI job"
approval for actionlint and zizmor came from the maintainer directly, so
there is no ADR.

Review contract → AGENTS.md. The path instructions move to a new
Review checklist section in English. It also covers rules added
since: clean verdicts only from a NUL-terminated reply (ADR-0007), and no
source error other than io.EOF treated as end of input.

Review step → independent review. The CodeRabbit step becomes an
independent review against the checklist by someone other than the
author: the maintainer, a fresh reviewer agent or Codex
adversarial-review. The review must cover the merged commit, which the
PR records, and every finding must be fixed or answered before merging.
AGENTS.md, CONTRIBUTING.md, CLAUDE.md, the pr-flow skill and the PR
template say so consistently. ADR-0002 keeps its original text with a
dated note.

CodeRabbit-only checks → CI.

Check Now
actionlint Step of the required lint job (pinned via go install), also in make lint
zizmor Gating step in lint (advanced-security: false, annotations, fails on findings) plus a zizmor-sarif job that uploads to code scanning; that job is the only one with security-events: write
gitleaks Step of lint scanning the whole git history (pinned via go install, full-history checkout), also in make lint. GitHub secret scanning with push protection stays on, but its non-provider patterns are disabled, so it does not replace gitleaks for generic credentials
yamllint, markdownlint Dropped (style only)

The upload runs as a separate job because zizmor exits 0 with SARIF
output, so it cannot gate.

Dependabot cooldown. zizmor's dependabot-cooldown audit flagged
every ecosystem, so each now waits 7 days before proposing a new version.
Security updates are not delayed.

Verification

  • make verify (now including actionlint and gitleaks; the history scans clean).
  • gitleaks detects a synthetic generic API key (generic-api-key rule).
  • actionlint 1.7.12 with shellcheck (official image) and zizmor 1.30.1
    with online audits: no findings. Under the pedantic persona, the new
    job's permissions are documented.
  • grep -ri coderabbit: only the CHANGELOG entry, the ADR-0002 note and
    a provenance comment in ci.yaml remain.

Independent review

Codex adversarial-review approved the merged commit df705c8 after one fixed finding; see the review record.

Checklist

  • make verify passes locally (build + lint + tests)
  • make integration passes (required when client.go / conn.go / commands.go / internal/proto/ / docker/ changed) — not run; none of those paths changed
  • README.md and README.ja.md updated together, or the change touches neither
  • CHANGELOG.md updated under [Unreleased] for user-visible changes
  • No new dependencies, no assembled EICAR string, no weakened guards; design changes reference an ADR — no guard dropped (moved or replaced as above); maintainer-approved process change, no ADR
  • Reviewed against the AGENTS.md Review checklist by someone other than the author, covering the merged commit (recorded in the PR); every finding fixed or answered

CodeRabbit is no longer used. Removing .coderabbit.yaml outright would
have dropped two guard layers AGENTS.md relies on, so both are kept:

- Its review contract (the path instructions) moves to a new Review
  checklist in AGENTS.md, in English. It also covers the rules added
  since: clean verdicts only from a NUL-terminated reply (ADR-0007) and
  no source error other than io.EOF treated as end of input.
- Its workflow checks move to the required lint job: actionlint (pinned,
  also run by make lint) and zizmor (action pinned by SHA). The gating
  zizmor run reports as annotations and fails the job; a separate
  zizmor-sarif job, the only one with security-events: write, uploads
  the same audit to code scanning, which cannot gate because zizmor
  exits 0 with SARIF output. gitleaks is covered by GitHub secret
  scanning with push protection; yamllint and markdownlint are dropped.

The CodeRabbit review step becomes an independent review against the
checklist by someone other than the author (the maintainer, a fresh
reviewer agent or Codex adversarial-review). The review must cover the
merged commit, which the PR records, and every finding must be fixed or
answered before merging. AGENTS.md, CONTRIBUTING.md, CLAUDE.md, the
pr-flow skill and the PR template say so consistently. ADR-0002 keeps
its original text with a dated note.

zizmor's dependabot-cooldown audit flagged the Dependabot config, so
every ecosystem now waits 7 days before proposing a new version;
security updates are not delayed.
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

The independent review of b292ac2 found that dropping CodeRabbit's
gitleaks check leaves a gap: GitHub secret scanning covers provider
token formats, and its non-provider patterns are disabled on this
repository, so generic high-entropy credentials were no longer caught.

Run gitleaks (pinned v8.30.1, installed with go install like actionlint)
in the required lint job over the whole git history, so a secret that is
committed and removed again within a PR is still found; the lint job
checks out full history for it. make lint runs the same scan. The
current history scans clean, and a synthetic generic API key is
detected by the generic-api-key rule.

The CHANGELOG no longer claims GitHub's scanning replaces gitleaks, and
the Review checklist asks reviewers to look for credentials in the diff.
@PyYoshi

PyYoshi commented Sep 23, 2026

Copy link
Copy Markdown
Owner Author

Independent review record

Reviewer: Codex adversarial-review (separate from the authoring session), run against the AGENTS.md Review checklist with the branch diff against origin/main.

Round Commit Verdict Findings
1 b292ac2 needs-attention [high] Removing CodeRabbit's gitleaks left generic secret detection uncovered: GitHub secret scanning covers provider token formats, and its non-provider patterns are disabled on this repository. Fixed in df705c8. gitleaks v8.30.1 now scans the whole history in the required lint job and in make lint. The CHANGELOG claim was corrected, and a credentials item was added to the checklist.
2 df705c8 (df705c80f24d22ab8a5a2788b0d664bae8ab07a6) approve None. The round-1 finding is resolved: gitleaks scans full history including the PR commits, exits non-zero on findings, and redacts. Guards, permissions, pinning, review requirements and docs are consistent.

Reviewed commit for merge: df705c80f24d22ab8a5a2788b0d664bae8ab07a6. Every finding is fixed; none were rejected.

@PyYoshi
PyYoshi merged commit 3185381 into main Sep 23, 2026
10 checks passed
@PyYoshi
PyYoshi deleted the chore/retire-coderabbit branch September 23, 2026 10:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants