Skip to content

fix(ci): the hygiene gate diffs against the base branch as it is, not as it was at the last push - #1804

Merged
mobeenabdullah merged 2 commits into
mainfrom
fix/hygiene-gate-diffs-against-current-main
Sep 11, 2026
Merged

mobeenabdullah merged 2 commits into
mainfrom
fix/hygiene-gate-diffs-against-current-main

Conversation

@mobeenabdullah

@mobeenabdullah mobeenabdullah commented Sep 11, 2026 •

Copy link
Copy Markdown
Collaborator

What

The Changed files hygiene gate now diffs a pull request against the base branch as it is now (origin/${{ github.base_ref }}), not against pull_request.base.sha, which does not move when the base branch advances.

Ledger: task:ci-hygiene-gate-diffs-against-current-main, implementing finding:fallow-ci-blames-a-pr-for-main-moving (open since 2026-09-02; remedy named there, unowned until now).

What was true

The fallow action, when changed-since is not set, scopes its audit to files changed since github.event.pull_request.base.sha (action.yml L385 → PR_BASE_SHA; analyze.sh L433-438; then git diff <sha>...HEAD). GitHub sets base.sha when the pull request is opened (the base tip then — #1804: 0121364ce, while its branch point is da323d583) and again on each push (the merge-base of head and base then — #1796: ebf8f78d9; #1803 moved to da323d583 after a merge of main, measured by a peer session). It does not follow the base branch afterwards. The job checks out refs/pull/N/merge, which GitHub rebuilds against the live base. So the diff the gate audited was "the pull request + everything main gained since the last push", and --gate new-only attributed the base's pre-existing findings to the pull request. With runs waiting 40-60 minutes in the queue today, that window was rarely empty.

Two observations on #1787 (whose base.sha was c80d0da, its merge-base at its last push, while main had advanced 20 commits by the time the run executed), 13:22Z (4cb335098) and 15:12Z (1037dbbf3): verdict=fail on CRAP in listEntries/getEntry (collection-query-service.ts, changed on main by #1642), generateCollectionUpdate (#1793), saveMultiComponentsInTx (#1788), invalidatePermissionCache (#1783) — the pull request's 17 files include none of those. Reproduced the mechanism locally: the same head audited with --changed-since origin/main (fallow 3.15.0, the repo's own) → verdict=warn, changed_files_count=17, complexity_introduced=0; with --changed-since c80d0da → the CI verdict. The job's own envelope step (Generate audit review envelope) already used origin/$BASE_REF; only the gating call did not, so the two invocations in one job measured different things.

How

One input on the action step, changed-since: origin/${{ github.base_ref }}, with the reason beside it. auto-changed-since is documented as ignored when changed-since is set. On the merge ref, origin/main...HEAD has the live tip as its merge-base, so the scope is exactly the pull request — the same base the envelope step and the local pnpm fallow:audit use.

Verification

  • pnpm test:scripts 1344/1344 (includes github-yaml-parses.test.mjs, which loads every workflow).
  • This pull request's own Changed files job ran on the fixed workflow (a pull_request run takes the workflow from the merge ref): its log shows INPUT_CHANGED_SINCE: origin/main, no "Auto-scoping analysis to files changed since PR base" notice, and verdict=pass on 4f81bfb79.
  • Correction to the first commit's body, which cited fix(nextly): fail closed on an unread role set, and retire derived key grants #1794 as passing and then failing with nothing pushed between: a push landed at 14:24Z and the failing run is on it (3393e336e), and the functions it names are in files fix(nextly): fail closed on an unread role set, and retire derived key grants #1794 changes — that example is withdrawn. The second commit also corrects the workflow comment's account of when base.sha is set.
  • Not verified here: the action's behaviour when origin/<base_ref> is absent from the checkout — actions/checkout with fetch-depth: 0 fetches every branch, and the envelope step in this job has relied on that ref all along.

No changeset: workflow-only.

…e sha the pr was opened on

The fallow action scopes its audit to files changed since
github.event.pull_request.base.sha unless told otherwise. GitHub records that
sha when the pull request is opened and never moves it, while the merge ref the
job checks out is rebuilt against the live base branch — so every file main
gained while a pull request was open read as changed by it, and functions its
author never touched (listEntries, generateCollectionUpdate,
invalidatePermissionCache on #1787, which touches none of those files) failed
the gate as introduced. The same pull request passed at 13:46Z and failed at
14:29Z with nothing pushed in between.

The step now names origin/<base_ref>, as the envelope step in the same job
already did; on the merge ref the three-dot diff has the live tip as its
merge-base, so the scope is exactly the pull request. Ledger:
task:ci-hygiene-gate-diffs-against-current-main, implementing
finding:fallow-ci-blames-a-pr-for-main-moving.
@coderabbitai

coderabbitai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 50 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 5238f838-2f00-4a93-ac87-aa473fe6c894

📥 Commits

Reviewing files that changed from the base of the PR and between 0121364 and 5842535.

📒 Files selected for processing (1)
  • .github/workflows/code-hygiene.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review 🔄 Running since 2026-09-11T15:38:56.185431Z 4f81bfb PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mobeenabdullah

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-11T17:30:05.273969Z 5842535 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🎉

Reviewed commit: 4f81bfb79f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@pkg-pr-new

pkg-pr-new Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

@nextlyhq/adapter-drizzle

npm i https://pkg.pr.new/@nextlyhq/adapter-drizzle@5842535

@nextlyhq/adapter-mysql

npm i https://pkg.pr.new/@nextlyhq/adapter-mysql@5842535

@nextlyhq/adapter-postgres

npm i https://pkg.pr.new/@nextlyhq/adapter-postgres@5842535

@nextlyhq/adapter-sqlite

npm i https://pkg.pr.new/@nextlyhq/adapter-sqlite@5842535

@nextlyhq/admin

npm i https://pkg.pr.new/@nextlyhq/admin@5842535

@nextlyhq/admin-css

npm i https://pkg.pr.new/@nextlyhq/admin-css@5842535

@nextlyhq/blocks-engine

npm i https://pkg.pr.new/@nextlyhq/blocks-engine@5842535

@nextlyhq/blocks-react

npm i https://pkg.pr.new/@nextlyhq/blocks-react@5842535

@nextlyhq/builder

npm i https://pkg.pr.new/@nextlyhq/builder@5842535

create-nextly-app

npm i https://pkg.pr.new/create-nextly-app@5842535

@nextlyhq/eslint-plugin

npm i https://pkg.pr.new/@nextlyhq/eslint-plugin@5842535

nextly

npm i https://pkg.pr.new/nextly@5842535

@nextlyhq/plugin-form-builder

npm i https://pkg.pr.new/@nextlyhq/plugin-form-builder@5842535

@nextlyhq/plugin-page-builder

npm i https://pkg.pr.new/@nextlyhq/plugin-page-builder@5842535

@nextlyhq/plugin-sdk

npm i https://pkg.pr.new/@nextlyhq/plugin-sdk@5842535

@nextlyhq/plugin-seo

npm i https://pkg.pr.new/@nextlyhq/plugin-seo@5842535

@nextlyhq/storage-s3

npm i https://pkg.pr.new/@nextlyhq/storage-s3@5842535

@nextlyhq/storage-uploadthing

npm i https://pkg.pr.new/@nextlyhq/storage-uploadthing@5842535

@nextlyhq/storage-vercel-blob

npm i https://pkg.pr.new/@nextlyhq/storage-vercel-blob@5842535

@nextlyhq/ui

npm i https://pkg.pr.new/@nextlyhq/ui@5842535

commit: 5842535

@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Whole-Repository Code Hygiene Summary

Full dead-code, duplication, and complexity report for the PR branch as it stands now. Playground is excluded. Quality gate enforcement on introduced issues is performed by the Changed files job.

🌿 Fallow

Warning

Review needed

⚠️ 73 code issues · ⚠️ 689 clone groups · ⚠️ 1045 health findings

See inline review comments for per-finding details.

Code issues (73)
Category Count
Unused files 2
Unused exports 5
Unused dependencies 19
Unused devDependencies 6
Unresolved imports 2
Unlisted dependencies 1
Circular dependencies 38
Duplication (689 groups · 28875 lines · 4.1%)
Locations Lines Tokens
schemas/_dialect-bundles/mysql.relations.ts:40-134
schemas/_dialect-bundles/postgres.relations.ts:40-134
schemas/_dialect-bundles/sqlite.relations.ts:40-134
95 593
cli/commands/db-sync-demote.ts:70-75
cli/commands/db-sync-promote.ts:38-43
cli/commands/dev-build.ts:100-105
cli/commands/dev-build.ts:179-184
cli/commands/dev-build.ts:299-304
cli/commands/dev-build.ts:411-416
cli/commands/dev-build.ts:552-557
cli/commands/dev-server.ts:575-580
cli/commands/dev-server.ts:840-845
cli/commands/dev-server.ts:1143-1148
cli/commands/migrate-field-groups.ts:110-115
6 70
entries/EntryList/EntryTableSkeleton.tsx:74-98
collection/components/CollectionTableSkeleton.tsx:94-118
field-group/components/FieldGroupTableSkeleton.tsx:90-114
plugins/components/PluginsTableSkeleton.tsx:86-110
singles/components/SinglesTableSkeleton.tsx:77-101
src/components/table-skeleton.tsx:100-124
25 89
collections/config/validate-config.ts:380-433
field-groups/config/validate-field-group.ts:185-238
singles/config/validate-single.ts:190-243
54 152
dispatcher/handlers/collection-dispatcher.ts:925-967
field-groups/services/field-group-table-provisioning.ts:186-236
singles/services/reconcile-single-companion.ts:110-160
51 149

… and 684 more groups.

Across 422 files.

Complexity (1045 functions above threshold)
File Function Severity Cyclomatic Cognitive CRAP Lines
singles/services/single-mutation-service.ts:981 <arrow> critical 251 ! 324 ! 13859.2 ! 1625
collections/services/collection-mutation-service.ts:6264 <arrow> critical 174 ! 177 ! 6713.6 ! 1301
src/init/reload-config.ts:1319 applyReload critical 144 ! 228 ! 4623 ! 1433
shared/lib/entry-validation.ts:223 validateFieldValue critical 109 ! 157 ! 2675.3 ! 432
blocks-engine/src/measure-bytes.ts:646 surveyDocument critical 102 ! 250 ! 137.1 ! 658

5009 files, 76756 functions analyzed (thresholds: cyclomatic > 20, cognitive > 15, CRAP >= 30)

Codebase health

Metric Value
Maintainability 91.7 / 100
Avg complexity 1.8

Tip

Run fallow fix --dry-run to preview auto-fixes.
Add /** @public */ above exports to preserve them.

…on push but not with main

The first commit said pull_request.base.sha is fixed when the pull request is
opened and never moves. Measured since: GitHub sets it at opening (the base tip,
#1804: 0121364) and again on each push (the merge-base then: #1796 ebf8f78,
#1803 da323d5 after a merge of main). What it never does is follow the base
branch, and the merge ref the audit reads is rebuilt against the live base — so
the drift is everything main gained since the last push, which a long queue
makes likely. The fix is unchanged; the comment now says that.

The first commit's body also cited #1794 as passing and then failing with
nothing pushed between; a push landed at 14:24Z and the failing run is on it, so
that example is withdrawn.
@mobeenabdullah mobeenabdullah changed the title fix(ci): the hygiene gate diffs against the base branch's tip, not the sha the PR was opened on fix(ci): the hygiene gate diffs against the base branch as it is, not as it was at the last push Sep 11, 2026
@mobeenabdullah

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Bravo.

Reviewed commit: 5842535f08

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mobeenabdullah
mobeenabdullah merged commit 4a03d2c into main Sep 11, 2026
17 of 21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant