Skip to content

Address PR #166 review feedback - #174

Merged
jeremy merged 2 commits into
mainfrom
address-pr-166-reviews
Mar 1, 2026
Merged

Address PR #166 review feedback#174
jeremy merged 2 commits into
mainfrom
address-pr-166-reviews

Conversation

@jeremy

@jeremy jeremy commented Mar 1, 2026

Copy link
Copy Markdown
Member

Summary

  • Fix CI labeler config to drop area/ prefix from labels
  • Harden release workflow: add worktree trap cleanup, jq guard, stderr capture in surface check

Test plan

  • CI passes on this branch

- Rename labeler keys to area/* namespace (area/commands, area/tui, etc.)
  and add area/docs, area/deps categories
- Capture stderr from --help --agent instead of suppressing with 2>/dev/null
- Write changelog diff to file instead of shell variable to avoid size limits
- Add worktree cleanup trap for baseline surface check on failure
- Add jq preflight check to make check-surface
Keep the plain names — no namespace needed for this repo.
Copilot AI review requested due to automatic review settings March 1, 2026 02:03
@github-actions github-actions Bot added ci CI/CD workflows bug Something isn't working labels Mar 1, 2026
@jeremy
jeremy merged commit 7796950 into main Mar 1, 2026
46 checks passed
@jeremy
jeremy deleted the address-pr-166-reviews branch March 1, 2026 02:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens CI/release reliability around CLI surface checks and release changelog context generation, and updates label automation.

Changes:

  • Improve CLI surface snapshot error reporting by capturing and printing stderr on failure.
  • Add a jq presence guard to make check-surface, and harden release workflow worktree cleanup via trap.
  • Extend PR label automation with docs and deps path-based labels.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 3 comments.

File Description
scripts/check-cli-surface.sh Capture stderr from --help --agent calls to improve debuggability on failures.
Makefile Add an explicit jq preflight check before generating CLI surface snapshots.
.github/workflows/release.yml Add worktree cleanup trap and avoid storing large diffs in shell variables by writing to a file.
.github/labeler.yml Add docs and deps label rules.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread scripts/check-cli-surface.sh
Comment thread .github/workflows/release.yml
Comment thread .github/labeler.yml
jeremy added a commit that referenced this pull request Sep 10, 2026
* Reference in-repo workflows with GitHub's self-repository syntax

zizmor 1.30.0, which zizmor-action 0.6.3 runs by default, adds a
self-repository audit that flags workspace-relative `uses: ./...` references
to in-repo actions and reusable workflows. GitHub's `uses: $/...` form resolves
against the running commit rather than the checked-out filesystem, so it can't
pick up an action cloned by an earlier step, and GitHub counts it as pinned.
This repo pins zizmor 1.29.0 explicitly (the action's `version:` input and
.mise.toml) and would fail the audit as soon as that pin moves to 1.30.0.

actionlint 1.7.12 rejects the new form and no release knows it yet
(rhysd/actionlint#711), so an actionlint config ignores that one message for
workflow files, with a note to drop it once a release does.

Same change as basecamp/hey-sdk#171 and #174.

* Scope the actionlint ignore to the calls it covers

The ignore for actionlint 1.7.12's rejection of the `$/` reusable-workflow
form now names the exact calls this repository makes, so a new `$/` call is
a deliberate edit to the config rather than a silent pass. actionlint accepts
`$/path@ref` as the owner/repo/path@ref shape with or without this ignore, so
the scoping is about new sites, not malformed references.

* Move to zizmor-action 0.6.3 and zizmor 1.30.0 so CI runs the audit this fixes

This repo pins zizmor explicitly through the action's version input and
.mise.toml, so the Dependabot bump of the action alone (#698) would have left
CI on 1.29.0 and the self-repository fix in the previous commit untested.
Both pins move to 1.30.0 together with the action, whose version map at
0.6.2 does not know 1.30.0, so the audit job on this branch is the proof.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working ci CI/CD workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants