Skip to content

fix(tooling)!: adopt shared approvals and generated command help - #266

Merged
acgetchell merged 3 commits into
mainfrom
fix/258-dependabot-tooling
Oct 2, 2026
Merged

acgetchell merged 3 commits into
mainfrom
fix/258-dependabot-tooling

Conversation

@acgetchell

@acgetchell acgetchell commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Dependabot PRs can have a successful CodeRabbit status while remaining blocked without an approving review. This adopts markov-chain-monte-carlo's pinned research-repo-tools approval workflow, which verifies signed bot commits, complete ecosystem/file allowlists, and the current head before approving and enabling native squash auto-merge. The trusted caller never checks out or executes PR code.

The patch also replaces hand-maintained help with a complete generated Just list, sorts and documents recipes, moves contributor validation out of README usage, and preserves active navigation on main. Historical measurements and citation provenance remain pinned. Duplicate subprocess and zizmor implementations and their unit tests are removed in favor of research-repo-tools; la-stack retains its benchmark schemas, scientific policy, and thin benchmark phase adapters. Zizmor findings now block CI before a separate SARIF export. Semgrep uploads honor reviewed inline suppressions, and benchmark snapshot fixtures verify exact LF and CRLF preservation across platforms.

Contributor command compatibility changes: use audit, shell-fix, toml-fix, and test-unit instead of security-osv, shell-fmt, toml-fmt, and test-lib. Redundant aliases and help-workflows are removed; bare just lists canonical commands. The Rust library API is unchanged.

Validation

  • Native Linux, macOS, and Windows just ci passed on f748db0: 528 Python tests, 893 Rust tests, default and exact doctests, examples, benchmark compilation, and the tooling/security checks composed by the recipe.
  • The final script inventory edit passed just markdown-fix markdown-ci doc-check.
  • Python wheel/sdist construction and isolated installed-module imports passed.
  • Staged and unstaged diff whitespace checks passed.

Deployment and remaining verification

The repository settings are already applied and verified: read-only default Actions permissions with PR approvals enabled, the two shared approval dependencies added to the existing selected-action allowlist, and stale-review dismissal enabled. The six required checks, one required approval, strict checks, resolved-thread requirement, and existing bypass policy are preserved. Enabling Actions approvals intentionally replaces #258's earlier CodeRabbit-only approach, as requested.

After merge, trigger a fresh eligible Dependabot event and record the current-head approval, workflow run, squash merge, and resulting default-branch checks. Old workflow reruns retain their original definition. Keep the old review token until the caller on main has been replaced and no remaining consumer needs it. The procedure is documented in Managing Changes. CodeRabbit's underlying provider failure remains unconfirmed, so #258 stays open for rollout verification.

Closes #260
Refs #258

Summary by CodeRabbit

  • Documentation

    • Updated contributor and development guides with clearer command discovery, security checks, dependency updates, and release procedures.
    • Refreshed README links, added instructions for running repository examples, and clarified documentation and release-link guidance.
  • Chores

    • Reorganized maintenance commands and added an OSV audit to the security checks.
    • Updated repository workflow permissions, branch protections, and dependency approval automation.
    • Improved security scan reports by excluding findings suppressed in source.

- Replace owner-issued CodeRabbit requests with the pinned MCMC
  Dependabot approval workflow and document the repository settings.
- Fail workflow security checks on findings before exporting SARIF.
- Generate sorted Just help and keep usage, contributor guidance, and
  active documentation navigation with their respective owners.
- Replace duplicate process and zizmor implementations with the
  published research-repo-tools APIs.

BREAKING CHANGE: contributor recipes use audit, shell-fix, toml-fix,
and test-unit. Redundant aliases and help-workflows are removed; use
bare just to discover the canonical commands.

Closes #260
Refs #258
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: acgetchell/la-stack/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: c5af61ef-2c68-4cb9-8093-ee614692780c

📥 Commits

Reviewing files that changed from the base of the PR and between c314554 and f748db0.

📒 Files selected for processing (1)
  • scripts/tests/test_archive_performance.py

Included review availability: This review used your included allowance. 1 included review remains after this review. Your included PR review attempts over the past 7 days set your current allowance at 3 reviews per hour.


📝 Walkthrough

Walkthrough

The pull request updates repository automation, review settings, and security workflows. It migrates process utilities to a shared package while retaining benchmark adapters. It also reorganizes Just recipes, updates command-discovery and contributor guidance, and revises repository navigation links.

Changes

Repository automation and security workflows

Layer / File(s) Summary
Actions permissions and branch rules
.github/settings/actions-selected.json, .github/settings/actions-workflow.json, .github/settings/main-ruleset.json
Adds an Actions allowlist, sets read-only default workflow permissions, and configures branch protection and required checks.
Dependabot approval workflow
.github/workflows/dependabot-auto-merge.yml, CONTRIBUTING.md, docs/dev/MANAGING_CHANGES.md, scripts/tests/test_justfile_discoverability.py
Replaces the inline Dependabot job with a pinned reusable workflow. Contributor and rollout guidance describe verification, requirements, settings, and deployment checks.
Zizmor and Semgrep reporting
.github/workflows/zizmor.yml, .github/workflows/semgrep-sarif.yml, justfile, pyproject.toml, semgrep.yaml, scripts/tests/test_justfile_discoverability.py
Separates the Zizmor audit and SARIF generation. Semgrep filters in-source-suppressed results. Action-reference rules and regression tests are updated.

Shared process tooling migration

Layer / File(s) Summary
Shared dependency and benchmark adapters
pyproject.toml, scripts/benchmark_process.py
Adds the shared process package dependency and local adapters for command execution, Git commands, and project-root discovery.
Benchmark and release script migration
scripts/archive_performance.py, scripts/bench_compare.py, scripts/criterion_dim_plot.py, scripts/release_baseline.py, scripts/subprocess_utils.py, scripts/run_zizmor.sh
Updates scripts to use shared process helpers and the local benchmark adapter. Removes the local process utilities and Zizmor wrapper.
Consumer tests and documentation
scripts/tests/*, scripts/README.md, docs/code_organization.md
Updates consumer tests for shared command APIs and removes dedicated tests for retired local utilities. Documents shared tooling ownership and the remaining local benchmark adapters.

Command discovery and repository guidance

Layer / File(s) Summary
Just recipes and grouped checks
justfile
Reorganizes and documents recipes, updates check and fix groups, and changes security, test, formatting, tool-update, and Zizmor targets.
Command placement and repository usage
AGENTS.md, CONTRIBUTING.md, README.md, docs/RELEASING.md, docs/dev/docs.md, pyproject.toml, scripts/README.md
Updates command-discovery and documentation guidance, adds example instructions, and revises active navigation and release-metadata descriptions.
Command and workflow regression checks
scripts/tests/test_justfile_discoverability.py, scripts/tests/test_maintenance_integration.py, scripts/tests/test_review_integration.py
Checks generated Just output, recipe ordering, workflow settings, and SARIF filtering. Existing command and link checks use revised interfaces.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to f748d

The selected test changes show no substantiated issue that should block merging.

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Out of Scope Changes check ⚠️ Warning The PR contains changes unrelated to the coding scope of #260. The changes add repository Actions settings in .github/settings/, replace the Dependabot auto-merge workflow with a shared approval wor… Remove the Dependabot workflow, related .github/settings/ files, Dependabot rollout documentation, and their dedicated test from this PR, or link them to a directly applicable issue that owns these requirements.
✅ Passed checks (3 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The PR meets the coding requirements in #260. README.md contains Quick start usage, just, and concrete example commands. CONTRIBUTING.md owns checks, fixes, tests, security, and PR preparation. …
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the two main changes: adoption of shared Dependabot approvals and generated command help. It is concise and specific.
Full details: Out of Scope Changes check

Explanation

The PR contains changes unrelated to the coding scope of #260. The changes add repository Actions settings in .github/settings/, replace the Dependabot auto-merge workflow with a shared approval workflow, add Dependabot rollout instructions to docs/dev/MANAGING_CHANGES.md and CONTRIBUTING.md, and add a Dependabot-specific discoverability test. These changes implement repository administration and deployment verification, not documentation ownership, generated Just help, or contributor command conventions. The Zizmor, Semgrep, and shared process-tooling changes remain connected to #260 security-scan and command-convention objectives.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/dependabot-auto-merge.yml Fixed
@codecov

codecov Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.02%. Comparing base (c50222c) to head (f748db0).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #266   +/-   ##
=======================================
  Coverage   98.02%   98.02%           
=======================================
  Files          13       13           
  Lines        6726     6726           
=======================================
  Hits         6593     6593           
  Misses        133      133           
Flag Coverage Δ
unittests 98.02% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Oct 1, 2026
- Remove in-source-suppressed results before GitHub code scanning
  ingests the report so reviewed inline exceptions stay effective.
- Preserve unsuppressed findings, their metadata, and the scanner's
  original exit status for the blocking security gate.

Refs #258
coderabbitai[bot]
coderabbitai Bot previously approved these changes Oct 1, 2026
- Declare LF and CRLF benchmark snapshot inputs explicitly instead of
  inheriting the host's text-write behavior.
- Check exact worktree bytes and staged contents against the selected
  line ending while preserving tracked-file and index guarantees.
@acgetchell
acgetchell marked this pull request as ready for review October 2, 2026 00:34
@acgetchell
acgetchell enabled auto-merge October 2, 2026 00:34
@acgetchell
acgetchell merged commit b570d0c into main Oct 2, 2026
18 checks passed
@acgetchell
acgetchell deleted the fix/258-dependabot-tooling branch October 2, 2026 00:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Align documentation ownership, Quick start, and generated Just help

2 participants