Skip to content

fix: make harness PR reviewer evaluate against the PR base branch - #2106

Merged
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch
Aug 25, 2026
Merged

fix: make harness PR reviewer evaluate against the PR base branch#2106
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch

Conversation

@notgitika

Copy link
Copy Markdown
Contributor

Problem

The AI PR reviewer (agentcore-devx-automation "AgentCore Harness Review") reviews PRs against the default branch (main) rather than the PR's actual base branch. Its local context clones (/opt/workspace/agentcore-cli) sit on main, so PRs targeting refactor are analyzed against the main source layout.

This produces confidently-wrong findings: e.g. on #2105 it reported a "split-brain read/write" regression citing src/cli/commands/deploy/actions.ts, src/lib/schemas/io/path-resolver.ts, and src/cli/operations/init/files.ts — none of which exist on refactor (which uses src/handlers/ and src/core/).

Fix

The actual checkout logic lives in the reusable workflow in aws/agentcore-devx-devtools (not editable here), so this fixes it at the lever we control — the prompts referenced by pr-automation.yml:

  • review.md: instruct the reviewer to determine the PR's base.ref and git fetch/git checkout it in the local clone before reading files for context, and to not raise findings premised on a file/path being absent without verifying against that base branch.
  • system.md: document that agentcore-cli has a long-lived refactor branch that diverges from main, and that PRs must be analyzed against their own base branch.

Notes

  • pull_request_target reads the workflow + prompts from the base branch, so this must land on refactor to fix refactor-targeted PRs. A parallel change on main keeps parity for main-targeted PRs.
  • A more robust fix (checking out the base branch in the runner) belongs in aws/agentcore-devx-devtools; this prompt-level mitigation is the in-repo stopgap.

The AI PR reviewer's local context clones sit on the default branch
(main), so PRs targeting the refactor branch were reviewed against the
main source layout — producing findings about files and code paths that
do not exist on refactor (e.g. src/cli / src/lib vs src/handlers /
src/core).
Instruct the reviewer, in both the system and review prompts, to sync the
local clone to the PR's base branch before reading files for context, and
to not raise findings premised on a file or path being absent without
verifying against that base branch.
@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Changes requested

Nice, well-scoped fix — the base-branch-vs-main mismatch is a real problem that will bite refactor-targeted PRs, and the layout facts in both prompts (src/handlers/+src/core/ on refactor vs. src/cli/+src/lib/ on main) match what's actually on those branches. One concrete concern before merging:

The example curl uses $CLONE_TOKEN, which isn't present at container runtime

In .github/harness/prompts/review.md (the new block, roughly lines 11–30) the recipe is:

curl -sH "Authorization: Bearer $CLONE_TOKEN" https://api.github.com/repos/aws/agentcore-cli/pulls/<number> | jq -r .base.ref

But per .github/harness/Dockerfile and .github/harness/README.md, CLONE_TOKEN is a build-time ARG used only to configure git config --global url."https://${CLONE_TOKEN}@github.com/".insteadOf .... The README explicitly states: "The token is never sent to the Harness runtime or persisted in this image." So at review time $CLONE_TOKEN will be empty, and curl -H "Authorization: Bearer " against api.github.com returns HTTP 401 (verified). jq -r .base.ref then emits null, and the follow-up git checkout null will fail — dropping the agent back to main, i.e. the exact failure mode this PR is trying to prevent.

Options:

  1. Drop the auth header entirely. aws/agentcore-cli is public, so an unauthenticated call to /repos/aws/agentcore-cli/pulls/<n> succeeds and returns .base.ref. Simplest fix and matches how the review agent already fetches PR metadata today.
  2. Rely on git ls-remote / a plain git fetch --all plus resolving the base ref from the diff/PR context the harness already passes in, rather than a fresh REST call.
  3. If you actually want an authenticated call, arrange for the reusable workflow (aws/agentcore-devx-devtools/.github/workflows/reusable-pr-ai-review.yml) to inject a token env var into the runtime container, and reference that variable here — and update .github/harness/README.md to match.

Everything else (the system.md blurb, the "don't raise findings whose premise is a missing file until you've confirmed the base branch" guardrail, the file paths modified) looks good.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.42%. Comparing base (1d96d1f) to head (cf80f92).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2106 +/- ##
=========================================
Coverage 97.42% 97.42% =========================================
Files 429 429 Lines 26286 26286 =========================================
Hits 25609 25609 Misses 677 677 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

CLONE_TOKEN is a build-time ARG (git config only), not present at
container runtime, so the Authorization header would send an empty bearer
and 401 — yielding a null base ref and a failed checkout back to main.
aws/agentcore-cli is public, so drop the header.
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@jariy17
jariy17 merged commit 0c79e59 into refactorAug 25, 2026
20 of 21 checks passed
@jariy17
jariy17 deleted the fix/harness-review-base-branch branch August 25, 2026 22:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@notgitika@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix: make harness PR reviewer evaluate against the PR base branch by notgitika · Pull Request #2106 · aws/agentcore-cli · GitHub
Skip to content

fix: make harness PR reviewer evaluate against the PR base branch - #2106

Merged
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch
Aug 25, 2026
Merged

fix: make harness PR reviewer evaluate against the PR base branch#2106
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch

Conversation

@notgitika

Copy link
Copy Markdown
Contributor

Problem

The AI PR reviewer (agentcore-devx-automation "AgentCore Harness Review") reviews PRs against the default branch (main) rather than the PR's actual base branch. Its local context clones (/opt/workspace/agentcore-cli) sit on main, so PRs targeting refactor are analyzed against the main source layout.

This produces confidently-wrong findings: e.g. on #2105 it reported a "split-brain read/write" regression citing src/cli/commands/deploy/actions.ts, src/lib/schemas/io/path-resolver.ts, and src/cli/operations/init/files.ts — none of which exist on refactor (which uses src/handlers/ and src/core/).

Fix

The actual checkout logic lives in the reusable workflow in aws/agentcore-devx-devtools (not editable here), so this fixes it at the lever we control — the prompts referenced by pr-automation.yml:

  • review.md: instruct the reviewer to determine the PR's base.ref and git fetch/git checkout it in the local clone before reading files for context, and to not raise findings premised on a file/path being absent without verifying against that base branch.
  • system.md: document that agentcore-cli has a long-lived refactor branch that diverges from main, and that PRs must be analyzed against their own base branch.

Notes

  • pull_request_target reads the workflow + prompts from the base branch, so this must land on refactor to fix refactor-targeted PRs. A parallel change on main keeps parity for main-targeted PRs.
  • A more robust fix (checking out the base branch in the runner) belongs in aws/agentcore-devx-devtools; this prompt-level mitigation is the in-repo stopgap.

The AI PR reviewer's local context clones sit on the default branch
(main), so PRs targeting the refactor branch were reviewed against the
main source layout — producing findings about files and code paths that
do not exist on refactor (e.g. src/cli / src/lib vs src/handlers /
src/core).
Instruct the reviewer, in both the system and review prompts, to sync the
local clone to the PR's base branch before reading files for context, and
to not raise findings premised on a file or path being absent without
verifying against that base branch.
@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Changes requested

Nice, well-scoped fix — the base-branch-vs-main mismatch is a real problem that will bite refactor-targeted PRs, and the layout facts in both prompts (src/handlers/+src/core/ on refactor vs. src/cli/+src/lib/ on main) match what's actually on those branches. One concrete concern before merging:

The example curl uses $CLONE_TOKEN, which isn't present at container runtime

In .github/harness/prompts/review.md (the new block, roughly lines 11–30) the recipe is:

curl -sH "Authorization: Bearer $CLONE_TOKEN" https://api.github.com/repos/aws/agentcore-cli/pulls/<number> | jq -r .base.ref

But per .github/harness/Dockerfile and .github/harness/README.md, CLONE_TOKEN is a build-time ARG used only to configure git config --global url."https://${CLONE_TOKEN}@github.com/".insteadOf .... The README explicitly states: "The token is never sent to the Harness runtime or persisted in this image." So at review time $CLONE_TOKEN will be empty, and curl -H "Authorization: Bearer " against api.github.com returns HTTP 401 (verified). jq -r .base.ref then emits null, and the follow-up git checkout null will fail — dropping the agent back to main, i.e. the exact failure mode this PR is trying to prevent.

Options:

  1. Drop the auth header entirely. aws/agentcore-cli is public, so an unauthenticated call to /repos/aws/agentcore-cli/pulls/<n> succeeds and returns .base.ref. Simplest fix and matches how the review agent already fetches PR metadata today.
  2. Rely on git ls-remote / a plain git fetch --all plus resolving the base ref from the diff/PR context the harness already passes in, rather than a fresh REST call.
  3. If you actually want an authenticated call, arrange for the reusable workflow (aws/agentcore-devx-devtools/.github/workflows/reusable-pr-ai-review.yml) to inject a token env var into the runtime container, and reference that variable here — and update .github/harness/README.md to match.

Everything else (the system.md blurb, the "don't raise findings whose premise is a missing file until you've confirmed the base branch" guardrail, the file paths modified) looks good.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.42%. Comparing base (1d96d1f) to head (cf80f92).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2106 +/- ##
=========================================
Coverage 97.42% 97.42% =========================================
Files 429 429 Lines 26286 26286 =========================================
Hits 25609 25609 Misses 677 677 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

CLONE_TOKEN is a build-time ARG (git config only), not present at
container runtime, so the Authorization header would send an empty bearer
and 401 — yielding a null base ref and a failed checkout back to main.
aws/agentcore-cli is public, so drop the header.
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@jariy17
jariy17 merged commit 0c79e59 into refactorAug 25, 2026
20 of 21 checks passed
@jariy17
jariy17 deleted the fix/harness-review-base-branch branch August 25, 2026 22:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@notgitika@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: make harness PR reviewer evaluate against the PR base branch by notgitika · Pull Request #2106 · aws/agentcore-cli · GitHub
Skip to content

fix: make harness PR reviewer evaluate against the PR base branch - #2106

Merged
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch
Aug 25, 2026
Merged

fix: make harness PR reviewer evaluate against the PR base branch#2106
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch

Conversation

@notgitika

Copy link
Copy Markdown
Contributor

Problem

The AI PR reviewer (agentcore-devx-automation "AgentCore Harness Review") reviews PRs against the default branch (main) rather than the PR's actual base branch. Its local context clones (/opt/workspace/agentcore-cli) sit on main, so PRs targeting refactor are analyzed against the main source layout.

This produces confidently-wrong findings: e.g. on #2105 it reported a "split-brain read/write" regression citing src/cli/commands/deploy/actions.ts, src/lib/schemas/io/path-resolver.ts, and src/cli/operations/init/files.ts — none of which exist on refactor (which uses src/handlers/ and src/core/).

Fix

The actual checkout logic lives in the reusable workflow in aws/agentcore-devx-devtools (not editable here), so this fixes it at the lever we control — the prompts referenced by pr-automation.yml:

  • review.md: instruct the reviewer to determine the PR's base.ref and git fetch/git checkout it in the local clone before reading files for context, and to not raise findings premised on a file/path being absent without verifying against that base branch.
  • system.md: document that agentcore-cli has a long-lived refactor branch that diverges from main, and that PRs must be analyzed against their own base branch.

Notes

  • pull_request_target reads the workflow + prompts from the base branch, so this must land on refactor to fix refactor-targeted PRs. A parallel change on main keeps parity for main-targeted PRs.
  • A more robust fix (checking out the base branch in the runner) belongs in aws/agentcore-devx-devtools; this prompt-level mitigation is the in-repo stopgap.

The AI PR reviewer's local context clones sit on the default branch
(main), so PRs targeting the refactor branch were reviewed against the
main source layout — producing findings about files and code paths that
do not exist on refactor (e.g. src/cli / src/lib vs src/handlers /
src/core).
Instruct the reviewer, in both the system and review prompts, to sync the
local clone to the PR's base branch before reading files for context, and
to not raise findings premised on a file or path being absent without
verifying against that base branch.
@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Changes requested

Nice, well-scoped fix — the base-branch-vs-main mismatch is a real problem that will bite refactor-targeted PRs, and the layout facts in both prompts (src/handlers/+src/core/ on refactor vs. src/cli/+src/lib/ on main) match what's actually on those branches. One concrete concern before merging:

The example curl uses $CLONE_TOKEN, which isn't present at container runtime

In .github/harness/prompts/review.md (the new block, roughly lines 11–30) the recipe is:

curl -sH "Authorization: Bearer $CLONE_TOKEN" https://api.github.com/repos/aws/agentcore-cli/pulls/<number> | jq -r .base.ref

But per .github/harness/Dockerfile and .github/harness/README.md, CLONE_TOKEN is a build-time ARG used only to configure git config --global url."https://${CLONE_TOKEN}@github.com/".insteadOf .... The README explicitly states: "The token is never sent to the Harness runtime or persisted in this image." So at review time $CLONE_TOKEN will be empty, and curl -H "Authorization: Bearer " against api.github.com returns HTTP 401 (verified). jq -r .base.ref then emits null, and the follow-up git checkout null will fail — dropping the agent back to main, i.e. the exact failure mode this PR is trying to prevent.

Options:

  1. Drop the auth header entirely. aws/agentcore-cli is public, so an unauthenticated call to /repos/aws/agentcore-cli/pulls/<n> succeeds and returns .base.ref. Simplest fix and matches how the review agent already fetches PR metadata today.
  2. Rely on git ls-remote / a plain git fetch --all plus resolving the base ref from the diff/PR context the harness already passes in, rather than a fresh REST call.
  3. If you actually want an authenticated call, arrange for the reusable workflow (aws/agentcore-devx-devtools/.github/workflows/reusable-pr-ai-review.yml) to inject a token env var into the runtime container, and reference that variable here — and update .github/harness/README.md to match.

Everything else (the system.md blurb, the "don't raise findings whose premise is a missing file until you've confirmed the base branch" guardrail, the file paths modified) looks good.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.42%. Comparing base (1d96d1f) to head (cf80f92).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2106 +/- ##
=========================================
Coverage 97.42% 97.42% =========================================
Files 429 429 Lines 26286 26286 =========================================
Hits 25609 25609 Misses 677 677 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

CLONE_TOKEN is a build-time ARG (git config only), not present at
container runtime, so the Authorization header would send an empty bearer
and 401 — yielding a null base ref and a failed checkout back to main.
aws/agentcore-cli is public, so drop the header.
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@jariy17
jariy17 merged commit 0c79e59 into refactorAug 25, 2026
20 of 21 checks passed
@jariy17
jariy17 deleted the fix/harness-review-base-branch branch August 25, 2026 22:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@notgitika@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: make harness PR reviewer evaluate against the PR base branch by notgitika · Pull Request #2106 · aws/agentcore-cli · GitHub
Skip to content

fix: make harness PR reviewer evaluate against the PR base branch - #2106

Merged
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch
Aug 25, 2026
Merged

fix: make harness PR reviewer evaluate against the PR base branch#2106
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch

Conversation

@notgitika

Copy link
Copy Markdown
Contributor

Problem

The AI PR reviewer (agentcore-devx-automation "AgentCore Harness Review") reviews PRs against the default branch (main) rather than the PR's actual base branch. Its local context clones (/opt/workspace/agentcore-cli) sit on main, so PRs targeting refactor are analyzed against the main source layout.

This produces confidently-wrong findings: e.g. on #2105 it reported a "split-brain read/write" regression citing src/cli/commands/deploy/actions.ts, src/lib/schemas/io/path-resolver.ts, and src/cli/operations/init/files.ts — none of which exist on refactor (which uses src/handlers/ and src/core/).

Fix

The actual checkout logic lives in the reusable workflow in aws/agentcore-devx-devtools (not editable here), so this fixes it at the lever we control — the prompts referenced by pr-automation.yml:

  • review.md: instruct the reviewer to determine the PR's base.ref and git fetch/git checkout it in the local clone before reading files for context, and to not raise findings premised on a file/path being absent without verifying against that base branch.
  • system.md: document that agentcore-cli has a long-lived refactor branch that diverges from main, and that PRs must be analyzed against their own base branch.

Notes

  • pull_request_target reads the workflow + prompts from the base branch, so this must land on refactor to fix refactor-targeted PRs. A parallel change on main keeps parity for main-targeted PRs.
  • A more robust fix (checking out the base branch in the runner) belongs in aws/agentcore-devx-devtools; this prompt-level mitigation is the in-repo stopgap.

The AI PR reviewer's local context clones sit on the default branch
(main), so PRs targeting the refactor branch were reviewed against the
main source layout — producing findings about files and code paths that
do not exist on refactor (e.g. src/cli / src/lib vs src/handlers /
src/core).
Instruct the reviewer, in both the system and review prompts, to sync the
local clone to the PR's base branch before reading files for context, and
to not raise findings premised on a file or path being absent without
verifying against that base branch.
@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Changes requested

Nice, well-scoped fix — the base-branch-vs-main mismatch is a real problem that will bite refactor-targeted PRs, and the layout facts in both prompts (src/handlers/+src/core/ on refactor vs. src/cli/+src/lib/ on main) match what's actually on those branches. One concrete concern before merging:

The example curl uses $CLONE_TOKEN, which isn't present at container runtime

In .github/harness/prompts/review.md (the new block, roughly lines 11–30) the recipe is:

curl -sH "Authorization: Bearer $CLONE_TOKEN" https://api.github.com/repos/aws/agentcore-cli/pulls/<number> | jq -r .base.ref

But per .github/harness/Dockerfile and .github/harness/README.md, CLONE_TOKEN is a build-time ARG used only to configure git config --global url."https://${CLONE_TOKEN}@github.com/".insteadOf .... The README explicitly states: "The token is never sent to the Harness runtime or persisted in this image." So at review time $CLONE_TOKEN will be empty, and curl -H "Authorization: Bearer " against api.github.com returns HTTP 401 (verified). jq -r .base.ref then emits null, and the follow-up git checkout null will fail — dropping the agent back to main, i.e. the exact failure mode this PR is trying to prevent.

Options:

  1. Drop the auth header entirely. aws/agentcore-cli is public, so an unauthenticated call to /repos/aws/agentcore-cli/pulls/<n> succeeds and returns .base.ref. Simplest fix and matches how the review agent already fetches PR metadata today.
  2. Rely on git ls-remote / a plain git fetch --all plus resolving the base ref from the diff/PR context the harness already passes in, rather than a fresh REST call.
  3. If you actually want an authenticated call, arrange for the reusable workflow (aws/agentcore-devx-devtools/.github/workflows/reusable-pr-ai-review.yml) to inject a token env var into the runtime container, and reference that variable here — and update .github/harness/README.md to match.

Everything else (the system.md blurb, the "don't raise findings whose premise is a missing file until you've confirmed the base branch" guardrail, the file paths modified) looks good.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.42%. Comparing base (1d96d1f) to head (cf80f92).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2106 +/- ##
=========================================
Coverage 97.42% 97.42% =========================================
Files 429 429 Lines 26286 26286 =========================================
Hits 25609 25609 Misses 677 677 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

CLONE_TOKEN is a build-time ARG (git config only), not present at
container runtime, so the Authorization header would send an empty bearer
and 401 — yielding a null base ref and a failed checkout back to main.
aws/agentcore-cli is public, so drop the header.
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@jariy17
jariy17 merged commit 0c79e59 into refactorAug 25, 2026
20 of 21 checks passed
@jariy17
jariy17 deleted the fix/harness-review-base-branch branch August 25, 2026 22:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@notgitika@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix: make harness PR reviewer evaluate against the PR base branch by notgitika · Pull Request #2106 · aws/agentcore-cli · GitHub
Skip to content

fix: make harness PR reviewer evaluate against the PR base branch - #2106

Merged
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch
Aug 25, 2026
Merged

fix: make harness PR reviewer evaluate against the PR base branch#2106
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch

Conversation

@notgitika

Copy link
Copy Markdown
Contributor

Problem

The AI PR reviewer (agentcore-devx-automation "AgentCore Harness Review") reviews PRs against the default branch (main) rather than the PR's actual base branch. Its local context clones (/opt/workspace/agentcore-cli) sit on main, so PRs targeting refactor are analyzed against the main source layout.

This produces confidently-wrong findings: e.g. on #2105 it reported a "split-brain read/write" regression citing src/cli/commands/deploy/actions.ts, src/lib/schemas/io/path-resolver.ts, and src/cli/operations/init/files.ts — none of which exist on refactor (which uses src/handlers/ and src/core/).

Fix

The actual checkout logic lives in the reusable workflow in aws/agentcore-devx-devtools (not editable here), so this fixes it at the lever we control — the prompts referenced by pr-automation.yml:

  • review.md: instruct the reviewer to determine the PR's base.ref and git fetch/git checkout it in the local clone before reading files for context, and to not raise findings premised on a file/path being absent without verifying against that base branch.
  • system.md: document that agentcore-cli has a long-lived refactor branch that diverges from main, and that PRs must be analyzed against their own base branch.

Notes

  • pull_request_target reads the workflow + prompts from the base branch, so this must land on refactor to fix refactor-targeted PRs. A parallel change on main keeps parity for main-targeted PRs.
  • A more robust fix (checking out the base branch in the runner) belongs in aws/agentcore-devx-devtools; this prompt-level mitigation is the in-repo stopgap.

The AI PR reviewer's local context clones sit on the default branch
(main), so PRs targeting the refactor branch were reviewed against the
main source layout — producing findings about files and code paths that
do not exist on refactor (e.g. src/cli / src/lib vs src/handlers /
src/core).
Instruct the reviewer, in both the system and review prompts, to sync the
local clone to the PR's base branch before reading files for context, and
to not raise findings premised on a file or path being absent without
verifying against that base branch.
@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Changes requested

Nice, well-scoped fix — the base-branch-vs-main mismatch is a real problem that will bite refactor-targeted PRs, and the layout facts in both prompts (src/handlers/+src/core/ on refactor vs. src/cli/+src/lib/ on main) match what's actually on those branches. One concrete concern before merging:

The example curl uses $CLONE_TOKEN, which isn't present at container runtime

In .github/harness/prompts/review.md (the new block, roughly lines 11–30) the recipe is:

curl -sH "Authorization: Bearer $CLONE_TOKEN" https://api.github.com/repos/aws/agentcore-cli/pulls/<number> | jq -r .base.ref

But per .github/harness/Dockerfile and .github/harness/README.md, CLONE_TOKEN is a build-time ARG used only to configure git config --global url."https://${CLONE_TOKEN}@github.com/".insteadOf .... The README explicitly states: "The token is never sent to the Harness runtime or persisted in this image." So at review time $CLONE_TOKEN will be empty, and curl -H "Authorization: Bearer " against api.github.com returns HTTP 401 (verified). jq -r .base.ref then emits null, and the follow-up git checkout null will fail — dropping the agent back to main, i.e. the exact failure mode this PR is trying to prevent.

Options:

  1. Drop the auth header entirely. aws/agentcore-cli is public, so an unauthenticated call to /repos/aws/agentcore-cli/pulls/<n> succeeds and returns .base.ref. Simplest fix and matches how the review agent already fetches PR metadata today.
  2. Rely on git ls-remote / a plain git fetch --all plus resolving the base ref from the diff/PR context the harness already passes in, rather than a fresh REST call.
  3. If you actually want an authenticated call, arrange for the reusable workflow (aws/agentcore-devx-devtools/.github/workflows/reusable-pr-ai-review.yml) to inject a token env var into the runtime container, and reference that variable here — and update .github/harness/README.md to match.

Everything else (the system.md blurb, the "don't raise findings whose premise is a missing file until you've confirmed the base branch" guardrail, the file paths modified) looks good.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.42%. Comparing base (1d96d1f) to head (cf80f92).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2106 +/- ##
=========================================
Coverage 97.42% 97.42% =========================================
Files 429 429 Lines 26286 26286 =========================================
Hits 25609 25609 Misses 677 677 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

CLONE_TOKEN is a build-time ARG (git config only), not present at
container runtime, so the Authorization header would send an empty bearer
and 401 — yielding a null base ref and a failed checkout back to main.
aws/agentcore-cli is public, so drop the header.
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@jariy17
jariy17 merged commit 0c79e59 into refactorAug 25, 2026
20 of 21 checks passed
@jariy17
jariy17 deleted the fix/harness-review-base-branch branch August 25, 2026 22:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@notgitika@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: make harness PR reviewer evaluate against the PR base branch by notgitika · Pull Request #2106 · aws/agentcore-cli · GitHub
Skip to content

fix: make harness PR reviewer evaluate against the PR base branch - #2106

Merged
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch
Aug 25, 2026
Merged

fix: make harness PR reviewer evaluate against the PR base branch#2106
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch

Conversation

@notgitika

Copy link
Copy Markdown
Contributor

Problem

The AI PR reviewer (agentcore-devx-automation "AgentCore Harness Review") reviews PRs against the default branch (main) rather than the PR's actual base branch. Its local context clones (/opt/workspace/agentcore-cli) sit on main, so PRs targeting refactor are analyzed against the main source layout.

This produces confidently-wrong findings: e.g. on #2105 it reported a "split-brain read/write" regression citing src/cli/commands/deploy/actions.ts, src/lib/schemas/io/path-resolver.ts, and src/cli/operations/init/files.ts — none of which exist on refactor (which uses src/handlers/ and src/core/).

Fix

The actual checkout logic lives in the reusable workflow in aws/agentcore-devx-devtools (not editable here), so this fixes it at the lever we control — the prompts referenced by pr-automation.yml:

  • review.md: instruct the reviewer to determine the PR's base.ref and git fetch/git checkout it in the local clone before reading files for context, and to not raise findings premised on a file/path being absent without verifying against that base branch.
  • system.md: document that agentcore-cli has a long-lived refactor branch that diverges from main, and that PRs must be analyzed against their own base branch.

Notes

  • pull_request_target reads the workflow + prompts from the base branch, so this must land on refactor to fix refactor-targeted PRs. A parallel change on main keeps parity for main-targeted PRs.
  • A more robust fix (checking out the base branch in the runner) belongs in aws/agentcore-devx-devtools; this prompt-level mitigation is the in-repo stopgap.

The AI PR reviewer's local context clones sit on the default branch
(main), so PRs targeting the refactor branch were reviewed against the
main source layout — producing findings about files and code paths that
do not exist on refactor (e.g. src/cli / src/lib vs src/handlers /
src/core).
Instruct the reviewer, in both the system and review prompts, to sync the
local clone to the PR's base branch before reading files for context, and
to not raise findings premised on a file or path being absent without
verifying against that base branch.
@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Changes requested

Nice, well-scoped fix — the base-branch-vs-main mismatch is a real problem that will bite refactor-targeted PRs, and the layout facts in both prompts (src/handlers/+src/core/ on refactor vs. src/cli/+src/lib/ on main) match what's actually on those branches. One concrete concern before merging:

The example curl uses $CLONE_TOKEN, which isn't present at container runtime

In .github/harness/prompts/review.md (the new block, roughly lines 11–30) the recipe is:

curl -sH "Authorization: Bearer $CLONE_TOKEN" https://api.github.com/repos/aws/agentcore-cli/pulls/<number> | jq -r .base.ref

But per .github/harness/Dockerfile and .github/harness/README.md, CLONE_TOKEN is a build-time ARG used only to configure git config --global url."https://${CLONE_TOKEN}@github.com/".insteadOf .... The README explicitly states: "The token is never sent to the Harness runtime or persisted in this image." So at review time $CLONE_TOKEN will be empty, and curl -H "Authorization: Bearer " against api.github.com returns HTTP 401 (verified). jq -r .base.ref then emits null, and the follow-up git checkout null will fail — dropping the agent back to main, i.e. the exact failure mode this PR is trying to prevent.

Options:

  1. Drop the auth header entirely. aws/agentcore-cli is public, so an unauthenticated call to /repos/aws/agentcore-cli/pulls/<n> succeeds and returns .base.ref. Simplest fix and matches how the review agent already fetches PR metadata today.
  2. Rely on git ls-remote / a plain git fetch --all plus resolving the base ref from the diff/PR context the harness already passes in, rather than a fresh REST call.
  3. If you actually want an authenticated call, arrange for the reusable workflow (aws/agentcore-devx-devtools/.github/workflows/reusable-pr-ai-review.yml) to inject a token env var into the runtime container, and reference that variable here — and update .github/harness/README.md to match.

Everything else (the system.md blurb, the "don't raise findings whose premise is a missing file until you've confirmed the base branch" guardrail, the file paths modified) looks good.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.42%. Comparing base (1d96d1f) to head (cf80f92).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2106 +/- ##
=========================================
Coverage 97.42% 97.42% =========================================
Files 429 429 Lines 26286 26286 =========================================
Hits 25609 25609 Misses 677 677 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

CLONE_TOKEN is a build-time ARG (git config only), not present at
container runtime, so the Authorization header would send an empty bearer
and 401 — yielding a null base ref and a failed checkout back to main.
aws/agentcore-cli is public, so drop the header.
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@jariy17
jariy17 merged commit 0c79e59 into refactorAug 25, 2026
20 of 21 checks passed
@jariy17
jariy17 deleted the fix/harness-review-base-branch branch August 25, 2026 22:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@notgitika@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: make harness PR reviewer evaluate against the PR base branch by notgitika · Pull Request #2106 · aws/agentcore-cli · GitHub
Skip to content

fix: make harness PR reviewer evaluate against the PR base branch - #2106

Merged
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch
Aug 25, 2026
Merged

fix: make harness PR reviewer evaluate against the PR base branch#2106
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch

Conversation

@notgitika

Copy link
Copy Markdown
Contributor

Problem

The AI PR reviewer (agentcore-devx-automation "AgentCore Harness Review") reviews PRs against the default branch (main) rather than the PR's actual base branch. Its local context clones (/opt/workspace/agentcore-cli) sit on main, so PRs targeting refactor are analyzed against the main source layout.

This produces confidently-wrong findings: e.g. on #2105 it reported a "split-brain read/write" regression citing src/cli/commands/deploy/actions.ts, src/lib/schemas/io/path-resolver.ts, and src/cli/operations/init/files.ts — none of which exist on refactor (which uses src/handlers/ and src/core/).

Fix

The actual checkout logic lives in the reusable workflow in aws/agentcore-devx-devtools (not editable here), so this fixes it at the lever we control — the prompts referenced by pr-automation.yml:

  • review.md: instruct the reviewer to determine the PR's base.ref and git fetch/git checkout it in the local clone before reading files for context, and to not raise findings premised on a file/path being absent without verifying against that base branch.
  • system.md: document that agentcore-cli has a long-lived refactor branch that diverges from main, and that PRs must be analyzed against their own base branch.

Notes

  • pull_request_target reads the workflow + prompts from the base branch, so this must land on refactor to fix refactor-targeted PRs. A parallel change on main keeps parity for main-targeted PRs.
  • A more robust fix (checking out the base branch in the runner) belongs in aws/agentcore-devx-devtools; this prompt-level mitigation is the in-repo stopgap.

The AI PR reviewer's local context clones sit on the default branch
(main), so PRs targeting the refactor branch were reviewed against the
main source layout — producing findings about files and code paths that
do not exist on refactor (e.g. src/cli / src/lib vs src/handlers /
src/core).
Instruct the reviewer, in both the system and review prompts, to sync the
local clone to the PR's base branch before reading files for context, and
to not raise findings premised on a file or path being absent without
verifying against that base branch.
@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Changes requested

Nice, well-scoped fix — the base-branch-vs-main mismatch is a real problem that will bite refactor-targeted PRs, and the layout facts in both prompts (src/handlers/+src/core/ on refactor vs. src/cli/+src/lib/ on main) match what's actually on those branches. One concrete concern before merging:

The example curl uses $CLONE_TOKEN, which isn't present at container runtime

In .github/harness/prompts/review.md (the new block, roughly lines 11–30) the recipe is:

curl -sH "Authorization: Bearer $CLONE_TOKEN" https://api.github.com/repos/aws/agentcore-cli/pulls/<number> | jq -r .base.ref

But per .github/harness/Dockerfile and .github/harness/README.md, CLONE_TOKEN is a build-time ARG used only to configure git config --global url."https://${CLONE_TOKEN}@github.com/".insteadOf .... The README explicitly states: "The token is never sent to the Harness runtime or persisted in this image." So at review time $CLONE_TOKEN will be empty, and curl -H "Authorization: Bearer " against api.github.com returns HTTP 401 (verified). jq -r .base.ref then emits null, and the follow-up git checkout null will fail — dropping the agent back to main, i.e. the exact failure mode this PR is trying to prevent.

Options:

  1. Drop the auth header entirely. aws/agentcore-cli is public, so an unauthenticated call to /repos/aws/agentcore-cli/pulls/<n> succeeds and returns .base.ref. Simplest fix and matches how the review agent already fetches PR metadata today.
  2. Rely on git ls-remote / a plain git fetch --all plus resolving the base ref from the diff/PR context the harness already passes in, rather than a fresh REST call.
  3. If you actually want an authenticated call, arrange for the reusable workflow (aws/agentcore-devx-devtools/.github/workflows/reusable-pr-ai-review.yml) to inject a token env var into the runtime container, and reference that variable here — and update .github/harness/README.md to match.

Everything else (the system.md blurb, the "don't raise findings whose premise is a missing file until you've confirmed the base branch" guardrail, the file paths modified) looks good.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.42%. Comparing base (1d96d1f) to head (cf80f92).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2106 +/- ##
=========================================
Coverage 97.42% 97.42% =========================================
Files 429 429 Lines 26286 26286 =========================================
Hits 25609 25609 Misses 677 677 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

CLONE_TOKEN is a build-time ARG (git config only), not present at
container runtime, so the Authorization header would send an empty bearer
and 401 — yielding a null base ref and a failed checkout back to main.
aws/agentcore-cli is public, so drop the header.
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@jariy17
jariy17 merged commit 0c79e59 into refactorAug 25, 2026
20 of 21 checks passed
@jariy17
jariy17 deleted the fix/harness-review-base-branch branch August 25, 2026 22:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@notgitika@codecov-commenter@jariy17
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix: make harness PR reviewer evaluate against the PR base branch by notgitika · Pull Request #2106 · aws/agentcore-cli · GitHub
Skip to content

fix: make harness PR reviewer evaluate against the PR base branch - #2106

Merged
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch
Aug 25, 2026
Merged

fix: make harness PR reviewer evaluate against the PR base branch#2106
jariy17 merged 2 commits into
refactorfrom
fix/harness-review-base-branch

Conversation

@notgitika

Copy link
Copy Markdown
Contributor

Problem

The AI PR reviewer (agentcore-devx-automation "AgentCore Harness Review") reviews PRs against the default branch (main) rather than the PR's actual base branch. Its local context clones (/opt/workspace/agentcore-cli) sit on main, so PRs targeting refactor are analyzed against the main source layout.

This produces confidently-wrong findings: e.g. on #2105 it reported a "split-brain read/write" regression citing src/cli/commands/deploy/actions.ts, src/lib/schemas/io/path-resolver.ts, and src/cli/operations/init/files.ts — none of which exist on refactor (which uses src/handlers/ and src/core/).

Fix

The actual checkout logic lives in the reusable workflow in aws/agentcore-devx-devtools (not editable here), so this fixes it at the lever we control — the prompts referenced by pr-automation.yml:

  • review.md: instruct the reviewer to determine the PR's base.ref and git fetch/git checkout it in the local clone before reading files for context, and to not raise findings premised on a file/path being absent without verifying against that base branch.
  • system.md: document that agentcore-cli has a long-lived refactor branch that diverges from main, and that PRs must be analyzed against their own base branch.

Notes

  • pull_request_target reads the workflow + prompts from the base branch, so this must land on refactor to fix refactor-targeted PRs. A parallel change on main keeps parity for main-targeted PRs.
  • A more robust fix (checking out the base branch in the runner) belongs in aws/agentcore-devx-devtools; this prompt-level mitigation is the in-repo stopgap.

The AI PR reviewer's local context clones sit on the default branch
(main), so PRs targeting the refactor branch were reviewed against the
main source layout — producing findings about files and code paths that
do not exist on refactor (e.g. src/cli / src/lib vs src/handlers /
src/core).
Instruct the reviewer, in both the system and review prompts, to sync the
local clone to the PR's base branch before reading files for context, and
to not raise findings premised on a file or path being absent without
verifying against that base branch.
@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Changes requested

Nice, well-scoped fix — the base-branch-vs-main mismatch is a real problem that will bite refactor-targeted PRs, and the layout facts in both prompts (src/handlers/+src/core/ on refactor vs. src/cli/+src/lib/ on main) match what's actually on those branches. One concrete concern before merging:

The example curl uses $CLONE_TOKEN, which isn't present at container runtime

In .github/harness/prompts/review.md (the new block, roughly lines 11–30) the recipe is:

curl -sH "Authorization: Bearer $CLONE_TOKEN" https://api.github.com/repos/aws/agentcore-cli/pulls/<number> | jq -r .base.ref

But per .github/harness/Dockerfile and .github/harness/README.md, CLONE_TOKEN is a build-time ARG used only to configure git config --global url."https://${CLONE_TOKEN}@github.com/".insteadOf .... The README explicitly states: "The token is never sent to the Harness runtime or persisted in this image." So at review time $CLONE_TOKEN will be empty, and curl -H "Authorization: Bearer " against api.github.com returns HTTP 401 (verified). jq -r .base.ref then emits null, and the follow-up git checkout null will fail — dropping the agent back to main, i.e. the exact failure mode this PR is trying to prevent.

Options:

  1. Drop the auth header entirely. aws/agentcore-cli is public, so an unauthenticated call to /repos/aws/agentcore-cli/pulls/<n> succeeds and returns .base.ref. Simplest fix and matches how the review agent already fetches PR metadata today.
  2. Rely on git ls-remote / a plain git fetch --all plus resolving the base ref from the diff/PR context the harness already passes in, rather than a fresh REST call.
  3. If you actually want an authenticated call, arrange for the reusable workflow (aws/agentcore-devx-devtools/.github/workflows/reusable-pr-ai-review.yml) to inject a token env var into the runtime container, and reference that variable here — and update .github/harness/README.md to match.

Everything else (the system.md blurb, the "don't raise findings whose premise is a missing file until you've confirmed the base branch" guardrail, the file paths modified) looks good.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 25, 2026
@codecov-commenter

codecov-commenter commented Aug 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.42%. Comparing base (1d96d1f) to head (cf80f92).

Additional details and impacted files
@@ Coverage Diff @@## refactor #2106 +/- ##
=========================================
Coverage 97.42% 97.42% =========================================
Files 429 429 Lines 26286 26286 =========================================
Hits 25609 25609 Misses 677 677 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

CLONE_TOKEN is a build-time ARG (git config only), not present at
container runtime, so the Authorization header would send an empty bearer
and 401 — yielding a null base ref and a failed checkout back to main.
aws/agentcore-cli is public, so drop the header.
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@jariy17
jariy17 merged commit 0c79e59 into refactorAug 25, 2026
20 of 21 checks passed
@jariy17
jariy17 deleted the fix/harness-review-base-branch branch August 25, 2026 22:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@notgitika@codecov-commenter@jariy17