Repository navigation
Retire CodeRabbit: keep its review contract and checks - #21
Merged
Merged
Conversation
CodeRabbit is no longer used. Removing .coderabbit.yaml outright would have dropped two guard layers AGENTS.md relies on, so both are kept: - Its review contract (the path instructions) moves to a new Review checklist in AGENTS.md, in English. It also covers the rules added since: clean verdicts only from a NUL-terminated reply (ADR-0007) and no source error other than io.EOF treated as end of input. - Its workflow checks move to the required lint job: actionlint (pinned, also run by make lint) and zizmor (action pinned by SHA). The gating zizmor run reports as annotations and fails the job; a separate zizmor-sarif job, the only one with security-events: write, uploads the same audit to code scanning, which cannot gate because zizmor exits 0 with SARIF output. gitleaks is covered by GitHub secret scanning with push protection; yamllint and markdownlint are dropped. The CodeRabbit review step becomes an independent review against the checklist by someone other than the author (the maintainer, a fresh reviewer agent or Codex adversarial-review). The review must cover the merged commit, which the PR records, and every finding must be fixed or answered before merging. AGENTS.md, CONTRIBUTING.md, CLAUDE.md, the pr-flow skill and the PR template say so consistently. ADR-0002 keeps its original text with a dated note. zizmor's dependabot-cooldown audit flagged the Dependabot config, so every ecosystem now waits 7 days before proposing a new version; security updates are not delayed.
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
The independent review of b292ac2 found that dropping CodeRabbit's gitleaks check leaves a gap: GitHub secret scanning covers provider token formats, and its non-provider patterns are disabled on this repository, so generic high-entropy credentials were no longer caught. Run gitleaks (pinned v8.30.1, installed with go install like actionlint) in the required lint job over the whole git history, so a secret that is committed and removed again within a PR is still found; the lint job checks out full history for it. make lint runs the same scan. The current history scans clean, and a synthetic generic API key is detected by the generic-api-key rule. The CHANGELOG no longer claims GitHub's scanning replaces gitleaks, and the Review checklist asks reviewers to look for credentials in the diff.
Owner
Author
Independent review recordReviewer: Codex
Reviewed commit for merge: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
CodeRabbit is no longer used. Deleting
.coderabbit.yamloutright wouldhave removed two guard layers AGENTS.md relies on, so both are kept.
This is a maintainer decision; the design gate's "new tool / CI job"
approval for actionlint and zizmor came from the maintainer directly, so
there is no ADR.
Review contract → AGENTS.md. The path instructions move to a new
Review checklist section in English. It also covers rules added
since: clean verdicts only from a NUL-terminated reply (ADR-0007), and no
source error other than
io.EOFtreated as end of input.Review step → independent review. The CodeRabbit step becomes an
independent review against the checklist by someone other than the
author: the maintainer, a fresh reviewer agent or Codex
adversarial-review. The review must cover the merged commit, which thePR records, and every finding must be fixed or answered before merging.
AGENTS.md, CONTRIBUTING.md, CLAUDE.md, the pr-flow skill and the PR
template say so consistently. ADR-0002 keeps its original text with a
dated note.
CodeRabbit-only checks → CI.
lintjob (pinned viago install), also inmake lintlint(advanced-security: false, annotations, fails on findings) plus azizmor-sarifjob that uploads to code scanning; that job is the only one withsecurity-events: writelintscanning the whole git history (pinned viago install, full-history checkout), also inmake lint. GitHub secret scanning with push protection stays on, but its non-provider patterns are disabled, so it does not replace gitleaks for generic credentialsThe upload runs as a separate job because zizmor exits 0 with SARIF
output, so it cannot gate.
Dependabot cooldown. zizmor's
dependabot-cooldownaudit flaggedevery ecosystem, so each now waits 7 days before proposing a new version.
Security updates are not delayed.
Verification
make verify(now including actionlint and gitleaks; the history scans clean).generic-api-keyrule).with online audits: no findings. Under the pedantic persona, the new
job's permissions are documented.
grep -ri coderabbit: only the CHANGELOG entry, the ADR-0002 note anda provenance comment in
ci.yamlremain.Independent review
Codex
adversarial-reviewapproved the merged commitdf705c8after one fixed finding; see the review record.Checklist
make verifypasses locally (build + lint + tests)make integrationpasses (required whenclient.go/conn.go/commands.go/internal/proto//docker/changed) — not run; none of those paths changedREADME.mdandREADME.ja.mdupdated together, or the change touches neitherCHANGELOG.mdupdated under[Unreleased]for user-visible changes