fix(ci): the hygiene gate diffs against the base branch as it is, not as it was at the last push - #1804
Conversation
…e sha the pr was opened on The fallow action scopes its audit to files changed since github.event.pull_request.base.sha unless told otherwise. GitHub records that sha when the pull request is opened and never moves it, while the merge ref the job checks out is rebuilt against the live base branch — so every file main gained while a pull request was open read as changed by it, and functions its author never touched (listEntries, generateCollectionUpdate, invalidatePermissionCache on #1787, which touches none of those files) failed the gate as introduced. The same pull request passed at 13:46Z and failed at 14:29Z with nothing pushed in between. The step now names origin/<base_ref>, as the envelope step in the same job already did; on the merge ref the three-dot diff has the live tip as its merge-base, so the scope is exactly the pull request. Ledger: task:ci-hygiene-gate-diffs-against-current-main, implementing finding:fallow-ci-blames-a-pr-for-main-moving.
|
Warning Review limit reachedNext included review available in 50 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. 🎉 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
@nextlyhq/adapter-drizzle
@nextlyhq/adapter-mysql
@nextlyhq/adapter-postgres
@nextlyhq/adapter-sqlite
@nextlyhq/admin
@nextlyhq/admin-css
@nextlyhq/blocks-engine
@nextlyhq/blocks-react
@nextlyhq/builder
create-nextly-app
@nextlyhq/eslint-plugin
nextly
@nextlyhq/plugin-form-builder
@nextlyhq/plugin-page-builder
@nextlyhq/plugin-sdk
@nextlyhq/plugin-seo
@nextlyhq/storage-s3
@nextlyhq/storage-uploadthing
@nextlyhq/storage-vercel-blob
@nextlyhq/ui
commit: |
…on push but not with main The first commit said pull_request.base.sha is fixed when the pull request is opened and never moves. Measured since: GitHub sets it at opening (the base tip, #1804: 0121364) and again on each push (the merge-base then: #1796 ebf8f78, #1803 da323d5 after a merge of main). What it never does is follow the base branch, and the merge ref the audit reads is rebuilt against the live base — so the drift is everything main gained since the last push, which a long queue makes likely. The fix is unchanged; the comment now says that. The first commit's body also cited #1794 as passing and then failing with nothing pushed between; a push landed at 14:24Z and the failing run is on it, so that example is withdrawn.
|
@codex review |
|
Codex Review: Didn't find any major issues. Bravo. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
What
The
Changed fileshygiene gate now diffs a pull request against the base branch as it is now (origin/${{ github.base_ref }}), not againstpull_request.base.sha, which does not move when the base branch advances.Ledger:
task:ci-hygiene-gate-diffs-against-current-main, implementingfinding:fallow-ci-blames-a-pr-for-main-moving(open since 2026-09-02; remedy named there, unowned until now).What was true
The fallow action, when
changed-sinceis not set, scopes its audit to files changed sincegithub.event.pull_request.base.sha(action.ymlL385 →PR_BASE_SHA;analyze.shL433-438; thengit diff <sha>...HEAD). GitHub setsbase.shawhen the pull request is opened (the base tip then — #1804:0121364ce, while its branch point isda323d583) and again on each push (the merge-base of head and base then — #1796:ebf8f78d9; #1803 moved toda323d583after a merge ofmain, measured by a peer session). It does not follow the base branch afterwards. The job checks outrefs/pull/N/merge, which GitHub rebuilds against the live base. So the diff the gate audited was "the pull request + everythingmaingained since the last push", and--gate new-onlyattributed the base's pre-existing findings to the pull request. With runs waiting 40-60 minutes in the queue today, that window was rarely empty.Two observations on #1787 (whose
base.shawasc80d0da, its merge-base at its last push, whilemainhad advanced 20 commits by the time the run executed), 13:22Z (4cb335098) and 15:12Z (1037dbbf3):verdict=failon CRAP inlistEntries/getEntry(collection-query-service.ts, changed onmainby #1642),generateCollectionUpdate(#1793),saveMultiComponentsInTx(#1788),invalidatePermissionCache(#1783) — the pull request's 17 files include none of those. Reproduced the mechanism locally: the same head audited with--changed-since origin/main(fallow 3.15.0, the repo's own) →verdict=warn,changed_files_count=17,complexity_introduced=0; with--changed-since c80d0da→ the CI verdict. The job's own envelope step (Generate audit review envelope) already usedorigin/$BASE_REF; only the gating call did not, so the two invocations in one job measured different things.How
One input on the action step,
changed-since: origin/${{ github.base_ref }}, with the reason beside it.auto-changed-sinceis documented as ignored whenchanged-sinceis set. On the merge ref,origin/main...HEADhas the live tip as its merge-base, so the scope is exactly the pull request — the same base the envelope step and the localpnpm fallow:audituse.Verification
pnpm test:scripts1344/1344 (includesgithub-yaml-parses.test.mjs, which loads every workflow).Changed filesjob ran on the fixed workflow (apull_requestrun takes the workflow from the merge ref): its log showsINPUT_CHANGED_SINCE: origin/main, no "Auto-scoping analysis to files changed since PR base" notice, andverdict=passon4f81bfb79.3393e336e), and the functions it names are in files fix(nextly): fail closed on an unread role set, and retire derived key grants #1794 changes — that example is withdrawn. The second commit also corrects the workflow comment's account of whenbase.shais set.origin/<base_ref>is absent from the checkout —actions/checkoutwithfetch-depth: 0fetches every branch, and the envelope step in this job has relied on that ref all along.No changeset: workflow-only.