Skip to content

feat(ci): give the AI reviewer the team's own review history - #6177

Open
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context
Open

feat(ci): give the AI reviewer the team's own review history#6177
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context

Conversation

@jam-jee

Copy link
Copy Markdown
Collaborator

Why

The AI reviewer reads the diff and the base checkout, so it re-derives context on every run and cannot see what the team has already said. Feedback that has been given before gets given again, and decisions settled in an earlier PR get relitigated in this one.

What

Adds one step between credential setup and the review action. It derives its own retrieval queries from the diff — changed file stems, added symbols, plus one for general conventions — queries a Bedrock Knowledge Base built from this repository's merged PRs, closed issues, and review discussions, and writes the result to /tmp/historical_context.md. The review action reads that file with the Read tool it already uses for the diff.

No per-PR prompt authoring is needed: the queries come from the diff.

Measured on a real diff

A 28,175-byte diff across sagemaker-train and sagemaker-core:

12 derived queries -> 31 chunks -> 38,140 bytes of context

Concrete prior guidance it surfaced, each with a source URL to check:

  • "Move local imports to module level rather than inside function bodies"#6135
  • "Raise exceptions for access-denied errors in validation paths instead of silently warning"#6135
  • "Ensure Model Customization trainer classes are re-exported in sagemaker.train.__init__.py"#5832

This merges inert

The step is skipped entirely unless the repo variable PYSDK_CONTEXT_KB_ID is set. Until then the workflow behaves exactly as it does today, so the mechanism can be reviewed and merged without committing to activation.

It cannot break a review

Four independent layers:

  1. if: vars.PYSDK_CONTEXT_KB_ID != '' — unset variable, step never runs
  2. continue-on-error: true — a failing step does not fail the job
  3. timeout-minutes: 5 — a hung Bedrock call cannot stall the review
  4. Every failure path inside the script exits 0 having written nothing

Verified for: unset KB id, invalid KB id, missing diff file, unwritable output. The prompt states the file's absence is normal, not an error.

Security

  • Runs in the base checkout (pull_request.base.sha) — the trusted context this workflow already established as its pwn-request defence. Never executes fork code.
  • No new tool permissions.allowedTools is unchanged and Bash stays excluded.
  • Retrieval is read-only: bedrock:Retrieve, bedrock:GetKnowledgeBase.
  • The script is vendored, not installed from a registry — so the code shaping the reviewer's context is reviewable in this same PR, needs no install step (boto3 is already on the runner), and cannot change under a fork PR without a repo change.

On trusting the retrieved text

Entries are model-extracted from historical discussion and can be confidently wrong. Both the file header and the prompt instruct the reviewer to treat each entry as a claim to verify, cite the source URL when relying on it, and prefer the current source tree wherever the two disagree.

The AI reviewer reads the diff and the base checkout, so it re-derives
context every run and cannot see what the team has already said. Feedback
that has been given before gets given again, and decisions that were
settled in an earlier PR get relitigated in this one.
Add a retrieval step between credential setup and the review action. It
derives its own queries from the diff -- changed file stems, added symbols,
plus one for general conventions -- queries a Bedrock Knowledge Base built
from this repository's merged PRs, closed issues, and review discussions,
and writes the results to /tmp/historical_context.md. The review action
reads that file with the Read tool it already uses for the diff.
Measured on a real 28KB diff across sagemaker-train and sagemaker-core:
12 derived queries, 31 chunks, 38KB of context carrying concrete prior
guidance ("move local imports to module level", "raise on AccessDenied in
validation paths instead of warning"), each with a source URL to check.
The step cannot break a review. It is skipped entirely unless the repo
variable PYSDK_CONTEXT_KB_ID is set, so this merges inert; it is
continue-on-error with a 5 minute timeout; and every failure path inside
the script exits 0 having written nothing. The prompt states the file's
absence is normal.
The script is vendored rather than installed from a package registry so
that the code shaping the reviewer's context is reviewable in the same
pull request that runs it, cannot change under a fork PR without a repo
change, and needs no install step -- it uses only the standard library
and boto3, which the runner already has.
Retrieval is read-only (bedrock:Retrieve, bedrock:GetKnowledgeBase) and
adds no tool permissions: allowedTools is unchanged and Bash stays
excluded. The step runs in the trusted base checkout, never fork code.
Retrieved entries are model-extracted from historical discussion and can
be wrong, so both the file header and the prompt tell the reviewer to
treat them as claims to verify, cite the source URL, and prefer the
current source tree on any disagreement.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 20:57 — with GitHub Actions Active
The knowledge base is a private corpus. It is currently built only from
this repository's own pull requests and issues, but it can also hold
documents from non-public sources, and this script's output is posted as
comments on a public pull request. Retrieval had no source restriction, so
adding one non-public document to the corpus would have been enough to
surface it here.
Restrict retrieval to an allowlist of sources whose contents are already
public in this repository. Enforced in the Retrieve filter server-side, so
non-public text never crosses into the process at all, with a second
client-side check in case that filter ever regresses. A chunk carrying no
source label is refused rather than assumed public, and the refusal warning
counts rather than names what it dropped, since the label itself can be the
sensitive part.
An allowlist, not a denylist: a source added to the corpus in future is
excluded here until it is added deliberately.
No loss of context. On the same 28KB diff used to validate the original
step, output is byte-identical at 38,140 bytes from 31 chunks -- the corpus
is 1,134 documents, all from this repository.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 21:22 — with GitHub Actions Active
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jam-jee
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat(ci): give the AI reviewer the team's own review history by jam-jee · Pull Request #6177 · aws/sagemaker-python-sdk · GitHub
Skip to content

feat(ci): give the AI reviewer the team's own review history - #6177

Open
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context
Open

feat(ci): give the AI reviewer the team's own review history#6177
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context

Conversation

@jam-jee

Copy link
Copy Markdown
Collaborator

Why

The AI reviewer reads the diff and the base checkout, so it re-derives context on every run and cannot see what the team has already said. Feedback that has been given before gets given again, and decisions settled in an earlier PR get relitigated in this one.

What

Adds one step between credential setup and the review action. It derives its own retrieval queries from the diff — changed file stems, added symbols, plus one for general conventions — queries a Bedrock Knowledge Base built from this repository's merged PRs, closed issues, and review discussions, and writes the result to /tmp/historical_context.md. The review action reads that file with the Read tool it already uses for the diff.

No per-PR prompt authoring is needed: the queries come from the diff.

Measured on a real diff

A 28,175-byte diff across sagemaker-train and sagemaker-core:

12 derived queries -> 31 chunks -> 38,140 bytes of context

Concrete prior guidance it surfaced, each with a source URL to check:

  • "Move local imports to module level rather than inside function bodies"#6135
  • "Raise exceptions for access-denied errors in validation paths instead of silently warning"#6135
  • "Ensure Model Customization trainer classes are re-exported in sagemaker.train.__init__.py"#5832

This merges inert

The step is skipped entirely unless the repo variable PYSDK_CONTEXT_KB_ID is set. Until then the workflow behaves exactly as it does today, so the mechanism can be reviewed and merged without committing to activation.

It cannot break a review

Four independent layers:

  1. if: vars.PYSDK_CONTEXT_KB_ID != '' — unset variable, step never runs
  2. continue-on-error: true — a failing step does not fail the job
  3. timeout-minutes: 5 — a hung Bedrock call cannot stall the review
  4. Every failure path inside the script exits 0 having written nothing

Verified for: unset KB id, invalid KB id, missing diff file, unwritable output. The prompt states the file's absence is normal, not an error.

Security

  • Runs in the base checkout (pull_request.base.sha) — the trusted context this workflow already established as its pwn-request defence. Never executes fork code.
  • No new tool permissions.allowedTools is unchanged and Bash stays excluded.
  • Retrieval is read-only: bedrock:Retrieve, bedrock:GetKnowledgeBase.
  • The script is vendored, not installed from a registry — so the code shaping the reviewer's context is reviewable in this same PR, needs no install step (boto3 is already on the runner), and cannot change under a fork PR without a repo change.

On trusting the retrieved text

Entries are model-extracted from historical discussion and can be confidently wrong. Both the file header and the prompt instruct the reviewer to treat each entry as a claim to verify, cite the source URL when relying on it, and prefer the current source tree wherever the two disagree.

The AI reviewer reads the diff and the base checkout, so it re-derives
context every run and cannot see what the team has already said. Feedback
that has been given before gets given again, and decisions that were
settled in an earlier PR get relitigated in this one.
Add a retrieval step between credential setup and the review action. It
derives its own queries from the diff -- changed file stems, added symbols,
plus one for general conventions -- queries a Bedrock Knowledge Base built
from this repository's merged PRs, closed issues, and review discussions,
and writes the results to /tmp/historical_context.md. The review action
reads that file with the Read tool it already uses for the diff.
Measured on a real 28KB diff across sagemaker-train and sagemaker-core:
12 derived queries, 31 chunks, 38KB of context carrying concrete prior
guidance ("move local imports to module level", "raise on AccessDenied in
validation paths instead of warning"), each with a source URL to check.
The step cannot break a review. It is skipped entirely unless the repo
variable PYSDK_CONTEXT_KB_ID is set, so this merges inert; it is
continue-on-error with a 5 minute timeout; and every failure path inside
the script exits 0 having written nothing. The prompt states the file's
absence is normal.
The script is vendored rather than installed from a package registry so
that the code shaping the reviewer's context is reviewable in the same
pull request that runs it, cannot change under a fork PR without a repo
change, and needs no install step -- it uses only the standard library
and boto3, which the runner already has.
Retrieval is read-only (bedrock:Retrieve, bedrock:GetKnowledgeBase) and
adds no tool permissions: allowedTools is unchanged and Bash stays
excluded. The step runs in the trusted base checkout, never fork code.
Retrieved entries are model-extracted from historical discussion and can
be wrong, so both the file header and the prompt tell the reviewer to
treat them as claims to verify, cite the source URL, and prefer the
current source tree on any disagreement.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 20:57 — with GitHub Actions Active
The knowledge base is a private corpus. It is currently built only from
this repository's own pull requests and issues, but it can also hold
documents from non-public sources, and this script's output is posted as
comments on a public pull request. Retrieval had no source restriction, so
adding one non-public document to the corpus would have been enough to
surface it here.
Restrict retrieval to an allowlist of sources whose contents are already
public in this repository. Enforced in the Retrieve filter server-side, so
non-public text never crosses into the process at all, with a second
client-side check in case that filter ever regresses. A chunk carrying no
source label is refused rather than assumed public, and the refusal warning
counts rather than names what it dropped, since the label itself can be the
sensitive part.
An allowlist, not a denylist: a source added to the corpus in future is
excluded here until it is added deliberately.
No loss of context. On the same 28KB diff used to validate the original
step, output is byte-identical at 38,140 bytes from 31 chunks -- the corpus
is 1,134 documents, all from this repository.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 21:22 — with GitHub Actions Active
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jam-jee
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(ci): give the AI reviewer the team's own review history by jam-jee · Pull Request #6177 · aws/sagemaker-python-sdk · GitHub
Skip to content

feat(ci): give the AI reviewer the team's own review history - #6177

Open
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context
Open

feat(ci): give the AI reviewer the team's own review history#6177
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context

Conversation

@jam-jee

Copy link
Copy Markdown
Collaborator

Why

The AI reviewer reads the diff and the base checkout, so it re-derives context on every run and cannot see what the team has already said. Feedback that has been given before gets given again, and decisions settled in an earlier PR get relitigated in this one.

What

Adds one step between credential setup and the review action. It derives its own retrieval queries from the diff — changed file stems, added symbols, plus one for general conventions — queries a Bedrock Knowledge Base built from this repository's merged PRs, closed issues, and review discussions, and writes the result to /tmp/historical_context.md. The review action reads that file with the Read tool it already uses for the diff.

No per-PR prompt authoring is needed: the queries come from the diff.

Measured on a real diff

A 28,175-byte diff across sagemaker-train and sagemaker-core:

12 derived queries -> 31 chunks -> 38,140 bytes of context

Concrete prior guidance it surfaced, each with a source URL to check:

  • "Move local imports to module level rather than inside function bodies"#6135
  • "Raise exceptions for access-denied errors in validation paths instead of silently warning"#6135
  • "Ensure Model Customization trainer classes are re-exported in sagemaker.train.__init__.py"#5832

This merges inert

The step is skipped entirely unless the repo variable PYSDK_CONTEXT_KB_ID is set. Until then the workflow behaves exactly as it does today, so the mechanism can be reviewed and merged without committing to activation.

It cannot break a review

Four independent layers:

  1. if: vars.PYSDK_CONTEXT_KB_ID != '' — unset variable, step never runs
  2. continue-on-error: true — a failing step does not fail the job
  3. timeout-minutes: 5 — a hung Bedrock call cannot stall the review
  4. Every failure path inside the script exits 0 having written nothing

Verified for: unset KB id, invalid KB id, missing diff file, unwritable output. The prompt states the file's absence is normal, not an error.

Security

  • Runs in the base checkout (pull_request.base.sha) — the trusted context this workflow already established as its pwn-request defence. Never executes fork code.
  • No new tool permissions.allowedTools is unchanged and Bash stays excluded.
  • Retrieval is read-only: bedrock:Retrieve, bedrock:GetKnowledgeBase.
  • The script is vendored, not installed from a registry — so the code shaping the reviewer's context is reviewable in this same PR, needs no install step (boto3 is already on the runner), and cannot change under a fork PR without a repo change.

On trusting the retrieved text

Entries are model-extracted from historical discussion and can be confidently wrong. Both the file header and the prompt instruct the reviewer to treat each entry as a claim to verify, cite the source URL when relying on it, and prefer the current source tree wherever the two disagree.

The AI reviewer reads the diff and the base checkout, so it re-derives
context every run and cannot see what the team has already said. Feedback
that has been given before gets given again, and decisions that were
settled in an earlier PR get relitigated in this one.
Add a retrieval step between credential setup and the review action. It
derives its own queries from the diff -- changed file stems, added symbols,
plus one for general conventions -- queries a Bedrock Knowledge Base built
from this repository's merged PRs, closed issues, and review discussions,
and writes the results to /tmp/historical_context.md. The review action
reads that file with the Read tool it already uses for the diff.
Measured on a real 28KB diff across sagemaker-train and sagemaker-core:
12 derived queries, 31 chunks, 38KB of context carrying concrete prior
guidance ("move local imports to module level", "raise on AccessDenied in
validation paths instead of warning"), each with a source URL to check.
The step cannot break a review. It is skipped entirely unless the repo
variable PYSDK_CONTEXT_KB_ID is set, so this merges inert; it is
continue-on-error with a 5 minute timeout; and every failure path inside
the script exits 0 having written nothing. The prompt states the file's
absence is normal.
The script is vendored rather than installed from a package registry so
that the code shaping the reviewer's context is reviewable in the same
pull request that runs it, cannot change under a fork PR without a repo
change, and needs no install step -- it uses only the standard library
and boto3, which the runner already has.
Retrieval is read-only (bedrock:Retrieve, bedrock:GetKnowledgeBase) and
adds no tool permissions: allowedTools is unchanged and Bash stays
excluded. The step runs in the trusted base checkout, never fork code.
Retrieved entries are model-extracted from historical discussion and can
be wrong, so both the file header and the prompt tell the reviewer to
treat them as claims to verify, cite the source URL, and prefer the
current source tree on any disagreement.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 20:57 — with GitHub Actions Active
The knowledge base is a private corpus. It is currently built only from
this repository's own pull requests and issues, but it can also hold
documents from non-public sources, and this script's output is posted as
comments on a public pull request. Retrieval had no source restriction, so
adding one non-public document to the corpus would have been enough to
surface it here.
Restrict retrieval to an allowlist of sources whose contents are already
public in this repository. Enforced in the Retrieve filter server-side, so
non-public text never crosses into the process at all, with a second
client-side check in case that filter ever regresses. A chunk carrying no
source label is refused rather than assumed public, and the refusal warning
counts rather than names what it dropped, since the label itself can be the
sensitive part.
An allowlist, not a denylist: a source added to the corpus in future is
excluded here until it is added deliberately.
No loss of context. On the same 28KB diff used to validate the original
step, output is byte-identical at 38,140 bytes from 31 chunks -- the corpus
is 1,134 documents, all from this repository.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 21:22 — with GitHub Actions Active
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jam-jee
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(ci): give the AI reviewer the team's own review history by jam-jee · Pull Request #6177 · aws/sagemaker-python-sdk · GitHub
Skip to content

feat(ci): give the AI reviewer the team's own review history - #6177

Open
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context
Open

feat(ci): give the AI reviewer the team's own review history#6177
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context

Conversation

@jam-jee

Copy link
Copy Markdown
Collaborator

Why

The AI reviewer reads the diff and the base checkout, so it re-derives context on every run and cannot see what the team has already said. Feedback that has been given before gets given again, and decisions settled in an earlier PR get relitigated in this one.

What

Adds one step between credential setup and the review action. It derives its own retrieval queries from the diff — changed file stems, added symbols, plus one for general conventions — queries a Bedrock Knowledge Base built from this repository's merged PRs, closed issues, and review discussions, and writes the result to /tmp/historical_context.md. The review action reads that file with the Read tool it already uses for the diff.

No per-PR prompt authoring is needed: the queries come from the diff.

Measured on a real diff

A 28,175-byte diff across sagemaker-train and sagemaker-core:

12 derived queries -> 31 chunks -> 38,140 bytes of context

Concrete prior guidance it surfaced, each with a source URL to check:

  • "Move local imports to module level rather than inside function bodies"#6135
  • "Raise exceptions for access-denied errors in validation paths instead of silently warning"#6135
  • "Ensure Model Customization trainer classes are re-exported in sagemaker.train.__init__.py"#5832

This merges inert

The step is skipped entirely unless the repo variable PYSDK_CONTEXT_KB_ID is set. Until then the workflow behaves exactly as it does today, so the mechanism can be reviewed and merged without committing to activation.

It cannot break a review

Four independent layers:

  1. if: vars.PYSDK_CONTEXT_KB_ID != '' — unset variable, step never runs
  2. continue-on-error: true — a failing step does not fail the job
  3. timeout-minutes: 5 — a hung Bedrock call cannot stall the review
  4. Every failure path inside the script exits 0 having written nothing

Verified for: unset KB id, invalid KB id, missing diff file, unwritable output. The prompt states the file's absence is normal, not an error.

Security

  • Runs in the base checkout (pull_request.base.sha) — the trusted context this workflow already established as its pwn-request defence. Never executes fork code.
  • No new tool permissions.allowedTools is unchanged and Bash stays excluded.
  • Retrieval is read-only: bedrock:Retrieve, bedrock:GetKnowledgeBase.
  • The script is vendored, not installed from a registry — so the code shaping the reviewer's context is reviewable in this same PR, needs no install step (boto3 is already on the runner), and cannot change under a fork PR without a repo change.

On trusting the retrieved text

Entries are model-extracted from historical discussion and can be confidently wrong. Both the file header and the prompt instruct the reviewer to treat each entry as a claim to verify, cite the source URL when relying on it, and prefer the current source tree wherever the two disagree.

The AI reviewer reads the diff and the base checkout, so it re-derives
context every run and cannot see what the team has already said. Feedback
that has been given before gets given again, and decisions that were
settled in an earlier PR get relitigated in this one.
Add a retrieval step between credential setup and the review action. It
derives its own queries from the diff -- changed file stems, added symbols,
plus one for general conventions -- queries a Bedrock Knowledge Base built
from this repository's merged PRs, closed issues, and review discussions,
and writes the results to /tmp/historical_context.md. The review action
reads that file with the Read tool it already uses for the diff.
Measured on a real 28KB diff across sagemaker-train and sagemaker-core:
12 derived queries, 31 chunks, 38KB of context carrying concrete prior
guidance ("move local imports to module level", "raise on AccessDenied in
validation paths instead of warning"), each with a source URL to check.
The step cannot break a review. It is skipped entirely unless the repo
variable PYSDK_CONTEXT_KB_ID is set, so this merges inert; it is
continue-on-error with a 5 minute timeout; and every failure path inside
the script exits 0 having written nothing. The prompt states the file's
absence is normal.
The script is vendored rather than installed from a package registry so
that the code shaping the reviewer's context is reviewable in the same
pull request that runs it, cannot change under a fork PR without a repo
change, and needs no install step -- it uses only the standard library
and boto3, which the runner already has.
Retrieval is read-only (bedrock:Retrieve, bedrock:GetKnowledgeBase) and
adds no tool permissions: allowedTools is unchanged and Bash stays
excluded. The step runs in the trusted base checkout, never fork code.
Retrieved entries are model-extracted from historical discussion and can
be wrong, so both the file header and the prompt tell the reviewer to
treat them as claims to verify, cite the source URL, and prefer the
current source tree on any disagreement.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 20:57 — with GitHub Actions Active
The knowledge base is a private corpus. It is currently built only from
this repository's own pull requests and issues, but it can also hold
documents from non-public sources, and this script's output is posted as
comments on a public pull request. Retrieval had no source restriction, so
adding one non-public document to the corpus would have been enough to
surface it here.
Restrict retrieval to an allowlist of sources whose contents are already
public in this repository. Enforced in the Retrieve filter server-side, so
non-public text never crosses into the process at all, with a second
client-side check in case that filter ever regresses. A chunk carrying no
source label is refused rather than assumed public, and the refusal warning
counts rather than names what it dropped, since the label itself can be the
sensitive part.
An allowlist, not a denylist: a source added to the corpus in future is
excluded here until it is added deliberately.
No loss of context. On the same 28KB diff used to validate the original
step, output is byte-identical at 38,140 bytes from 31 chunks -- the corpus
is 1,134 documents, all from this repository.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 21:22 — with GitHub Actions Active
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jam-jee
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat(ci): give the AI reviewer the team's own review history by jam-jee · Pull Request #6177 · aws/sagemaker-python-sdk · GitHub
Skip to content

feat(ci): give the AI reviewer the team's own review history - #6177

Open
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context
Open

feat(ci): give the AI reviewer the team's own review history#6177
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context

Conversation

@jam-jee

Copy link
Copy Markdown
Collaborator

Why

The AI reviewer reads the diff and the base checkout, so it re-derives context on every run and cannot see what the team has already said. Feedback that has been given before gets given again, and decisions settled in an earlier PR get relitigated in this one.

What

Adds one step between credential setup and the review action. It derives its own retrieval queries from the diff — changed file stems, added symbols, plus one for general conventions — queries a Bedrock Knowledge Base built from this repository's merged PRs, closed issues, and review discussions, and writes the result to /tmp/historical_context.md. The review action reads that file with the Read tool it already uses for the diff.

No per-PR prompt authoring is needed: the queries come from the diff.

Measured on a real diff

A 28,175-byte diff across sagemaker-train and sagemaker-core:

12 derived queries -> 31 chunks -> 38,140 bytes of context

Concrete prior guidance it surfaced, each with a source URL to check:

  • "Move local imports to module level rather than inside function bodies"#6135
  • "Raise exceptions for access-denied errors in validation paths instead of silently warning"#6135
  • "Ensure Model Customization trainer classes are re-exported in sagemaker.train.__init__.py"#5832

This merges inert

The step is skipped entirely unless the repo variable PYSDK_CONTEXT_KB_ID is set. Until then the workflow behaves exactly as it does today, so the mechanism can be reviewed and merged without committing to activation.

It cannot break a review

Four independent layers:

  1. if: vars.PYSDK_CONTEXT_KB_ID != '' — unset variable, step never runs
  2. continue-on-error: true — a failing step does not fail the job
  3. timeout-minutes: 5 — a hung Bedrock call cannot stall the review
  4. Every failure path inside the script exits 0 having written nothing

Verified for: unset KB id, invalid KB id, missing diff file, unwritable output. The prompt states the file's absence is normal, not an error.

Security

  • Runs in the base checkout (pull_request.base.sha) — the trusted context this workflow already established as its pwn-request defence. Never executes fork code.
  • No new tool permissions.allowedTools is unchanged and Bash stays excluded.
  • Retrieval is read-only: bedrock:Retrieve, bedrock:GetKnowledgeBase.
  • The script is vendored, not installed from a registry — so the code shaping the reviewer's context is reviewable in this same PR, needs no install step (boto3 is already on the runner), and cannot change under a fork PR without a repo change.

On trusting the retrieved text

Entries are model-extracted from historical discussion and can be confidently wrong. Both the file header and the prompt instruct the reviewer to treat each entry as a claim to verify, cite the source URL when relying on it, and prefer the current source tree wherever the two disagree.

The AI reviewer reads the diff and the base checkout, so it re-derives
context every run and cannot see what the team has already said. Feedback
that has been given before gets given again, and decisions that were
settled in an earlier PR get relitigated in this one.
Add a retrieval step between credential setup and the review action. It
derives its own queries from the diff -- changed file stems, added symbols,
plus one for general conventions -- queries a Bedrock Knowledge Base built
from this repository's merged PRs, closed issues, and review discussions,
and writes the results to /tmp/historical_context.md. The review action
reads that file with the Read tool it already uses for the diff.
Measured on a real 28KB diff across sagemaker-train and sagemaker-core:
12 derived queries, 31 chunks, 38KB of context carrying concrete prior
guidance ("move local imports to module level", "raise on AccessDenied in
validation paths instead of warning"), each with a source URL to check.
The step cannot break a review. It is skipped entirely unless the repo
variable PYSDK_CONTEXT_KB_ID is set, so this merges inert; it is
continue-on-error with a 5 minute timeout; and every failure path inside
the script exits 0 having written nothing. The prompt states the file's
absence is normal.
The script is vendored rather than installed from a package registry so
that the code shaping the reviewer's context is reviewable in the same
pull request that runs it, cannot change under a fork PR without a repo
change, and needs no install step -- it uses only the standard library
and boto3, which the runner already has.
Retrieval is read-only (bedrock:Retrieve, bedrock:GetKnowledgeBase) and
adds no tool permissions: allowedTools is unchanged and Bash stays
excluded. The step runs in the trusted base checkout, never fork code.
Retrieved entries are model-extracted from historical discussion and can
be wrong, so both the file header and the prompt tell the reviewer to
treat them as claims to verify, cite the source URL, and prefer the
current source tree on any disagreement.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 20:57 — with GitHub Actions Active
The knowledge base is a private corpus. It is currently built only from
this repository's own pull requests and issues, but it can also hold
documents from non-public sources, and this script's output is posted as
comments on a public pull request. Retrieval had no source restriction, so
adding one non-public document to the corpus would have been enough to
surface it here.
Restrict retrieval to an allowlist of sources whose contents are already
public in this repository. Enforced in the Retrieve filter server-side, so
non-public text never crosses into the process at all, with a second
client-side check in case that filter ever regresses. A chunk carrying no
source label is refused rather than assumed public, and the refusal warning
counts rather than names what it dropped, since the label itself can be the
sensitive part.
An allowlist, not a denylist: a source added to the corpus in future is
excluded here until it is added deliberately.
No loss of context. On the same 28KB diff used to validate the original
step, output is byte-identical at 38,140 bytes from 31 chunks -- the corpus
is 1,134 documents, all from this repository.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 21:22 — with GitHub Actions Active
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jam-jee
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(ci): give the AI reviewer the team's own review history by jam-jee · Pull Request #6177 · aws/sagemaker-python-sdk · GitHub
Skip to content

feat(ci): give the AI reviewer the team's own review history - #6177

Open
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context
Open

feat(ci): give the AI reviewer the team's own review history#6177
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context

Conversation

@jam-jee

Copy link
Copy Markdown
Collaborator

Why

The AI reviewer reads the diff and the base checkout, so it re-derives context on every run and cannot see what the team has already said. Feedback that has been given before gets given again, and decisions settled in an earlier PR get relitigated in this one.

What

Adds one step between credential setup and the review action. It derives its own retrieval queries from the diff — changed file stems, added symbols, plus one for general conventions — queries a Bedrock Knowledge Base built from this repository's merged PRs, closed issues, and review discussions, and writes the result to /tmp/historical_context.md. The review action reads that file with the Read tool it already uses for the diff.

No per-PR prompt authoring is needed: the queries come from the diff.

Measured on a real diff

A 28,175-byte diff across sagemaker-train and sagemaker-core:

12 derived queries -> 31 chunks -> 38,140 bytes of context

Concrete prior guidance it surfaced, each with a source URL to check:

  • "Move local imports to module level rather than inside function bodies"#6135
  • "Raise exceptions for access-denied errors in validation paths instead of silently warning"#6135
  • "Ensure Model Customization trainer classes are re-exported in sagemaker.train.__init__.py"#5832

This merges inert

The step is skipped entirely unless the repo variable PYSDK_CONTEXT_KB_ID is set. Until then the workflow behaves exactly as it does today, so the mechanism can be reviewed and merged without committing to activation.

It cannot break a review

Four independent layers:

  1. if: vars.PYSDK_CONTEXT_KB_ID != '' — unset variable, step never runs
  2. continue-on-error: true — a failing step does not fail the job
  3. timeout-minutes: 5 — a hung Bedrock call cannot stall the review
  4. Every failure path inside the script exits 0 having written nothing

Verified for: unset KB id, invalid KB id, missing diff file, unwritable output. The prompt states the file's absence is normal, not an error.

Security

  • Runs in the base checkout (pull_request.base.sha) — the trusted context this workflow already established as its pwn-request defence. Never executes fork code.
  • No new tool permissions.allowedTools is unchanged and Bash stays excluded.
  • Retrieval is read-only: bedrock:Retrieve, bedrock:GetKnowledgeBase.
  • The script is vendored, not installed from a registry — so the code shaping the reviewer's context is reviewable in this same PR, needs no install step (boto3 is already on the runner), and cannot change under a fork PR without a repo change.

On trusting the retrieved text

Entries are model-extracted from historical discussion and can be confidently wrong. Both the file header and the prompt instruct the reviewer to treat each entry as a claim to verify, cite the source URL when relying on it, and prefer the current source tree wherever the two disagree.

The AI reviewer reads the diff and the base checkout, so it re-derives
context every run and cannot see what the team has already said. Feedback
that has been given before gets given again, and decisions that were
settled in an earlier PR get relitigated in this one.
Add a retrieval step between credential setup and the review action. It
derives its own queries from the diff -- changed file stems, added symbols,
plus one for general conventions -- queries a Bedrock Knowledge Base built
from this repository's merged PRs, closed issues, and review discussions,
and writes the results to /tmp/historical_context.md. The review action
reads that file with the Read tool it already uses for the diff.
Measured on a real 28KB diff across sagemaker-train and sagemaker-core:
12 derived queries, 31 chunks, 38KB of context carrying concrete prior
guidance ("move local imports to module level", "raise on AccessDenied in
validation paths instead of warning"), each with a source URL to check.
The step cannot break a review. It is skipped entirely unless the repo
variable PYSDK_CONTEXT_KB_ID is set, so this merges inert; it is
continue-on-error with a 5 minute timeout; and every failure path inside
the script exits 0 having written nothing. The prompt states the file's
absence is normal.
The script is vendored rather than installed from a package registry so
that the code shaping the reviewer's context is reviewable in the same
pull request that runs it, cannot change under a fork PR without a repo
change, and needs no install step -- it uses only the standard library
and boto3, which the runner already has.
Retrieval is read-only (bedrock:Retrieve, bedrock:GetKnowledgeBase) and
adds no tool permissions: allowedTools is unchanged and Bash stays
excluded. The step runs in the trusted base checkout, never fork code.
Retrieved entries are model-extracted from historical discussion and can
be wrong, so both the file header and the prompt tell the reviewer to
treat them as claims to verify, cite the source URL, and prefer the
current source tree on any disagreement.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 20:57 — with GitHub Actions Active
The knowledge base is a private corpus. It is currently built only from
this repository's own pull requests and issues, but it can also hold
documents from non-public sources, and this script's output is posted as
comments on a public pull request. Retrieval had no source restriction, so
adding one non-public document to the corpus would have been enough to
surface it here.
Restrict retrieval to an allowlist of sources whose contents are already
public in this repository. Enforced in the Retrieve filter server-side, so
non-public text never crosses into the process at all, with a second
client-side check in case that filter ever regresses. A chunk carrying no
source label is refused rather than assumed public, and the refusal warning
counts rather than names what it dropped, since the label itself can be the
sensitive part.
An allowlist, not a denylist: a source added to the corpus in future is
excluded here until it is added deliberately.
No loss of context. On the same 28KB diff used to validate the original
step, output is byte-identical at 38,140 bytes from 31 chunks -- the corpus
is 1,134 documents, all from this repository.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 21:22 — with GitHub Actions Active
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jam-jee
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(ci): give the AI reviewer the team's own review history by jam-jee · Pull Request #6177 · aws/sagemaker-python-sdk · GitHub
Skip to content

feat(ci): give the AI reviewer the team's own review history - #6177

Open
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context
Open

feat(ci): give the AI reviewer the team's own review history#6177
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context

Conversation

@jam-jee

Copy link
Copy Markdown
Collaborator

Why

The AI reviewer reads the diff and the base checkout, so it re-derives context on every run and cannot see what the team has already said. Feedback that has been given before gets given again, and decisions settled in an earlier PR get relitigated in this one.

What

Adds one step between credential setup and the review action. It derives its own retrieval queries from the diff — changed file stems, added symbols, plus one for general conventions — queries a Bedrock Knowledge Base built from this repository's merged PRs, closed issues, and review discussions, and writes the result to /tmp/historical_context.md. The review action reads that file with the Read tool it already uses for the diff.

No per-PR prompt authoring is needed: the queries come from the diff.

Measured on a real diff

A 28,175-byte diff across sagemaker-train and sagemaker-core:

12 derived queries -> 31 chunks -> 38,140 bytes of context

Concrete prior guidance it surfaced, each with a source URL to check:

  • "Move local imports to module level rather than inside function bodies"#6135
  • "Raise exceptions for access-denied errors in validation paths instead of silently warning"#6135
  • "Ensure Model Customization trainer classes are re-exported in sagemaker.train.__init__.py"#5832

This merges inert

The step is skipped entirely unless the repo variable PYSDK_CONTEXT_KB_ID is set. Until then the workflow behaves exactly as it does today, so the mechanism can be reviewed and merged without committing to activation.

It cannot break a review

Four independent layers:

  1. if: vars.PYSDK_CONTEXT_KB_ID != '' — unset variable, step never runs
  2. continue-on-error: true — a failing step does not fail the job
  3. timeout-minutes: 5 — a hung Bedrock call cannot stall the review
  4. Every failure path inside the script exits 0 having written nothing

Verified for: unset KB id, invalid KB id, missing diff file, unwritable output. The prompt states the file's absence is normal, not an error.

Security

  • Runs in the base checkout (pull_request.base.sha) — the trusted context this workflow already established as its pwn-request defence. Never executes fork code.
  • No new tool permissions.allowedTools is unchanged and Bash stays excluded.
  • Retrieval is read-only: bedrock:Retrieve, bedrock:GetKnowledgeBase.
  • The script is vendored, not installed from a registry — so the code shaping the reviewer's context is reviewable in this same PR, needs no install step (boto3 is already on the runner), and cannot change under a fork PR without a repo change.

On trusting the retrieved text

Entries are model-extracted from historical discussion and can be confidently wrong. Both the file header and the prompt instruct the reviewer to treat each entry as a claim to verify, cite the source URL when relying on it, and prefer the current source tree wherever the two disagree.

The AI reviewer reads the diff and the base checkout, so it re-derives
context every run and cannot see what the team has already said. Feedback
that has been given before gets given again, and decisions that were
settled in an earlier PR get relitigated in this one.
Add a retrieval step between credential setup and the review action. It
derives its own queries from the diff -- changed file stems, added symbols,
plus one for general conventions -- queries a Bedrock Knowledge Base built
from this repository's merged PRs, closed issues, and review discussions,
and writes the results to /tmp/historical_context.md. The review action
reads that file with the Read tool it already uses for the diff.
Measured on a real 28KB diff across sagemaker-train and sagemaker-core:
12 derived queries, 31 chunks, 38KB of context carrying concrete prior
guidance ("move local imports to module level", "raise on AccessDenied in
validation paths instead of warning"), each with a source URL to check.
The step cannot break a review. It is skipped entirely unless the repo
variable PYSDK_CONTEXT_KB_ID is set, so this merges inert; it is
continue-on-error with a 5 minute timeout; and every failure path inside
the script exits 0 having written nothing. The prompt states the file's
absence is normal.
The script is vendored rather than installed from a package registry so
that the code shaping the reviewer's context is reviewable in the same
pull request that runs it, cannot change under a fork PR without a repo
change, and needs no install step -- it uses only the standard library
and boto3, which the runner already has.
Retrieval is read-only (bedrock:Retrieve, bedrock:GetKnowledgeBase) and
adds no tool permissions: allowedTools is unchanged and Bash stays
excluded. The step runs in the trusted base checkout, never fork code.
Retrieved entries are model-extracted from historical discussion and can
be wrong, so both the file header and the prompt tell the reviewer to
treat them as claims to verify, cite the source URL, and prefer the
current source tree on any disagreement.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 20:57 — with GitHub Actions Active
The knowledge base is a private corpus. It is currently built only from
this repository's own pull requests and issues, but it can also hold
documents from non-public sources, and this script's output is posted as
comments on a public pull request. Retrieval had no source restriction, so
adding one non-public document to the corpus would have been enough to
surface it here.
Restrict retrieval to an allowlist of sources whose contents are already
public in this repository. Enforced in the Retrieve filter server-side, so
non-public text never crosses into the process at all, with a second
client-side check in case that filter ever regresses. A chunk carrying no
source label is refused rather than assumed public, and the refusal warning
counts rather than names what it dropped, since the label itself can be the
sensitive part.
An allowlist, not a denylist: a source added to the corpus in future is
excluded here until it is added deliberately.
No loss of context. On the same 28KB diff used to validate the original
step, output is byte-identical at 38,140 bytes from 31 chunks -- the corpus
is 1,134 documents, all from this repository.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 21:22 — with GitHub Actions Active
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jam-jee
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); feat(ci): give the AI reviewer the team's own review history by jam-jee · Pull Request #6177 · aws/sagemaker-python-sdk · GitHub
Skip to content

feat(ci): give the AI reviewer the team's own review history - #6177

Open
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context
Open

feat(ci): give the AI reviewer the team's own review history#6177
jam-jee wants to merge 2 commits into
aws:masterfrom
jam-jee:feat/ai-review-historical-context

Conversation

@jam-jee

Copy link
Copy Markdown
Collaborator

Why

The AI reviewer reads the diff and the base checkout, so it re-derives context on every run and cannot see what the team has already said. Feedback that has been given before gets given again, and decisions settled in an earlier PR get relitigated in this one.

What

Adds one step between credential setup and the review action. It derives its own retrieval queries from the diff — changed file stems, added symbols, plus one for general conventions — queries a Bedrock Knowledge Base built from this repository's merged PRs, closed issues, and review discussions, and writes the result to /tmp/historical_context.md. The review action reads that file with the Read tool it already uses for the diff.

No per-PR prompt authoring is needed: the queries come from the diff.

Measured on a real diff

A 28,175-byte diff across sagemaker-train and sagemaker-core:

12 derived queries -> 31 chunks -> 38,140 bytes of context

Concrete prior guidance it surfaced, each with a source URL to check:

  • "Move local imports to module level rather than inside function bodies"#6135
  • "Raise exceptions for access-denied errors in validation paths instead of silently warning"#6135
  • "Ensure Model Customization trainer classes are re-exported in sagemaker.train.__init__.py"#5832

This merges inert

The step is skipped entirely unless the repo variable PYSDK_CONTEXT_KB_ID is set. Until then the workflow behaves exactly as it does today, so the mechanism can be reviewed and merged without committing to activation.

It cannot break a review

Four independent layers:

  1. if: vars.PYSDK_CONTEXT_KB_ID != '' — unset variable, step never runs
  2. continue-on-error: true — a failing step does not fail the job
  3. timeout-minutes: 5 — a hung Bedrock call cannot stall the review
  4. Every failure path inside the script exits 0 having written nothing

Verified for: unset KB id, invalid KB id, missing diff file, unwritable output. The prompt states the file's absence is normal, not an error.

Security

  • Runs in the base checkout (pull_request.base.sha) — the trusted context this workflow already established as its pwn-request defence. Never executes fork code.
  • No new tool permissions.allowedTools is unchanged and Bash stays excluded.
  • Retrieval is read-only: bedrock:Retrieve, bedrock:GetKnowledgeBase.
  • The script is vendored, not installed from a registry — so the code shaping the reviewer's context is reviewable in this same PR, needs no install step (boto3 is already on the runner), and cannot change under a fork PR without a repo change.

On trusting the retrieved text

Entries are model-extracted from historical discussion and can be confidently wrong. Both the file header and the prompt instruct the reviewer to treat each entry as a claim to verify, cite the source URL when relying on it, and prefer the current source tree wherever the two disagree.

The AI reviewer reads the diff and the base checkout, so it re-derives
context every run and cannot see what the team has already said. Feedback
that has been given before gets given again, and decisions that were
settled in an earlier PR get relitigated in this one.
Add a retrieval step between credential setup and the review action. It
derives its own queries from the diff -- changed file stems, added symbols,
plus one for general conventions -- queries a Bedrock Knowledge Base built
from this repository's merged PRs, closed issues, and review discussions,
and writes the results to /tmp/historical_context.md. The review action
reads that file with the Read tool it already uses for the diff.
Measured on a real 28KB diff across sagemaker-train and sagemaker-core:
12 derived queries, 31 chunks, 38KB of context carrying concrete prior
guidance ("move local imports to module level", "raise on AccessDenied in
validation paths instead of warning"), each with a source URL to check.
The step cannot break a review. It is skipped entirely unless the repo
variable PYSDK_CONTEXT_KB_ID is set, so this merges inert; it is
continue-on-error with a 5 minute timeout; and every failure path inside
the script exits 0 having written nothing. The prompt states the file's
absence is normal.
The script is vendored rather than installed from a package registry so
that the code shaping the reviewer's context is reviewable in the same
pull request that runs it, cannot change under a fork PR without a repo
change, and needs no install step -- it uses only the standard library
and boto3, which the runner already has.
Retrieval is read-only (bedrock:Retrieve, bedrock:GetKnowledgeBase) and
adds no tool permissions: allowedTools is unchanged and Bash stays
excluded. The step runs in the trusted base checkout, never fork code.
Retrieved entries are model-extracted from historical discussion and can
be wrong, so both the file header and the prompt tell the reviewer to
treat them as claims to verify, cite the source URL, and prefer the
current source tree on any disagreement.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 20:57 — with GitHub Actions Active
The knowledge base is a private corpus. It is currently built only from
this repository's own pull requests and issues, but it can also hold
documents from non-public sources, and this script's output is posted as
comments on a public pull request. Retrieval had no source restriction, so
adding one non-public document to the corpus would have been enough to
surface it here.
Restrict retrieval to an allowlist of sources whose contents are already
public in this repository. Enforced in the Retrieve filter server-side, so
non-public text never crosses into the process at all, with a second
client-side check in case that filter ever regresses. A chunk carrying no
source label is refused rather than assumed public, and the refusal warning
counts rather than names what it dropped, since the label itself can be the
sensitive part.
An allowlist, not a denylist: a source added to the corpus in future is
excluded here until it is added deliberately.
No loss of context. On the same 28KB diff used to validate the original
step, output is byte-identical at 38,140 bytes from 31 chunks -- the corpus
is 1,134 documents, all from this repository.
@jam-jee
jam-jeedeployed to auto-approve August 12, 2026 21:22 — with GitHub Actions Active
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@jam-jee