Repository navigation
Releases: crunchtools/gatehouse
Releases · crunchtools/gatehouse
Release list
v0.15.3
Changed
- CI: the Gourmand job reports as
Code Quality (Gourmand) / Code Quality (Gourmand)like the rest of the fleet, so the org ruleset can require it. - Constitution is now a v1.18.0 manifest: purpose, CLI and workflow contract,
external API, agents and ignored paths; fleet and profile rules apply by
reference. - Constitution validation pinned to v1.18.0 via
constitution.yml, replacing
the unpinned validation job inci.yml. - Dependabot auto-merges GitHub Actions minor and patch updates.
Fixed
- Reviewers no longer flag a version, tag or release as nonexistent. Every
Dependabot bump to a major newer than the model's cutoff (checkout@v7,
setup-python@v7, ...) drew a "tag does not exist" finding, repeated on
each rebase. examples/gourmand.ymlpinnedgourmand.yml@v0.5.0and was a bare job
fragment. It is now a complete workflow onpull_requestat the current
release, and a test fails any example that pins a different release than
the one it ships in (crunchtools/constitution#22).
v0.15.2
Fixed
- Replies with trailing content no longer abort an agent. Before this fix, GLM-5.3 replies that followed the findings array with another array or with prose failed as
Extra data. Consecutive JSON values are now merged, and trailing text is ignored.
v0.15.1
v0.15.0
Added
- Incremental re-review (#57). On a push to an open PR,
review.yml
passes--incremental: gatehouse reviews only the commits since its last
complete review, fetched through the compare API with nothing checked
out. It falls back to the whole PR for a first review, a force-push or
rebase, when the last review had an unfinished agent, or when the compare
fails. Files the PR does not touch are cut from the range, so merging the
base branch in does not review the base's changes. The review summary
states the scope. - Serving model and usage per agent (#58). Each agent logs
agent=… model=… prompt=… completion=… reasoning=… cost=$… fallback=yes|no
to stderr, followed by a total line. In CI the same table goes to the job's
step summary, and--usage-json PATHwrites it as JSON. - Fallback is visible. When a fallback model served any agent, the posted
review says so, e.g. "3 of 8 agents served by google/gemini-3.1-flash-lite".
Changed
- Findings on a line outside the PR diff are not posted, and the summary
counts them. GitHub rejects a whole review over one such comment. - The posted review is pinned to the head commit that was reviewed, and a
review in which every agent finished carries a hidden
<!-- gatehouse review complete -->marker; incremental review starts
from the newest one. call_modelreturns aCompletion(text, requested and serving model,
usage) instead of the bare text.
v0.14.0
LOW findings were 26% of the threads triage required an answer to, and a
30-finding sample from four crunchtools PRs held 18 noise, 6 re-raises of
answered threads and 1 with invented evidence (#56).
Added
- Findings with invented evidence are dropped, at every severity. The
quoted evidence must appear in the diff (or the styleguide/constitution
agents were given), ignoring whitespace, line-number prefixes and...
elisions. mcp-trentina#258 quoteddef _cases(split: str, csv_bytes: bytes):for code that reads-> list[Case]:. - Answered threads are not re-raised. On a PR, a MEDIUM or LOW from the
same agent within 5 lines of a thread someone replied to is dropped.
HIGH and CRITICAL always post: next to a "fixed in" thread they may be a
regression. - At most 5 advisory LOWs per review, highest confidence first. LOWs
from the--required-low-agentslist (Bug Hunter and Security Scan by
default) are never capped. - The review summary counts each kind of dropped finding.
- Each finding comment carries a hidden
agentandconfidencemarker, so
replies can be joined to confidence before deciding whether LOW needs a
higher threshold. required_low_agentsinput ontriage.ymlandreview.yml(default
Bug Hunter,Security Scan), and--required-low-agentson the CLI. Give
both workflows the same list.
Changed
- Triage requires an answer to LOW findings only from
required_low_agents.
Other LOWs still post, as advisory. CRITICAL, HIGH and MEDIUM are required
from every agent, as before. - The Documentation agent no longer asks for docstrings on private or
non-exported names, or beyond a file's one-line-docstring-plus-type-hints
convention; itslowtier is gone. - Consistency Check findings must cite the in-repo code that sets the
convention, asfile:line, or are not reported.
v0.13.0
Changed
- The Constitution agent reviews amendments as amendments. A diff that
changes the constitution file itself is reviewed for rules that contradict
each other or the code, not against the text it replaces, which it can
only ever contradict. crunchtools/petit#77 and #78 each drew CRITICAL
findings for changing the rule they were changing. Other files in the
same diff are still judged by the base branch's constitution, so a PR
still cannot relax a rule and use the relaxation at once. The agent is
also told it does not know today's date, which made it flag same-day
Amended:lines as stale.
v0.12.0
Added
.gatehouse-ignore: gitignore-syntax paths that are never reviewed.
Matching files leave the diff and the file listing before any agent runs;
on crunchtools/petit#61 that cuts each agent's diff from 263 KB of deleted
fingerprint data to 3 KB. A change is skipped only when every path it
touches matches, changes to the ignore file itself are always reviewed,
and in CI the file comes from the base branch so a PR cannot hide its own
changes. The posted review says how many files were skipped (when every changed
file is ignored, nothing is posted).- Under a trusted base (
GATEHOUSE_CONTEXT_REPO/REF), the styleguide,
ignore file and auto-discovered constitution come only from the base; a
missing base copy no longer falls back to the working tree. An explicit
--constitutionpath still wins, as before.
v0.11.0
Added
retriage.ymlandexamples/gatehouse-retriage.yml: a reply now clears
the triage check. Triage re-ran onpull_request_review_comment, but that
run's checks do not count toward branch rules: on #50, four passing reply
runs left the PR blocked until thepull_request_targetrun's triage job
was re-run by hand. The newworkflow_runlistener does that re-run
automatically, from the default-branch definition. Repos that require
Gatehouse triageshould add the example file.
Security
- Answers #47. Because reply-event checks do not count toward the
ruleset, a fork that rewrites its copy of the workflow cannot satisfy
Protect workflowsorGatehouse triageon a reply. The re-run that does
count uses the base definition.
v0.10.0
Changed
- An agent that cannot finish now exits 2. It used to print a warning and
count as zero findings, so an OpenRouter outage or a garbled reply passed
as a clean review (the pre-commit hook included). Findings from the agents
that did finish are still printed and posted, and the posted review names
the ones that did not.--advisory, and so the defaultreview.yml, still
exits 0 (#41).
Fixed
--stdincrashed onhttpx.ReadTimeoutover a large diff. Timeouts and
dropped connections are now retried with the same backoff as a 429 (#41).review.ymlfailed on diffs containing escape sequences.gh pr diff
refuses such a diff unless told otherwise, printed nothing, and the job
reportedNo changes to review.before exiting 1. The diff is now fetched
with--allow-escape-sequencesinto a file, and a failed fetch says so
(#44).- The workflow guard missed renames. It read
gh pr diff --name-only,
which lists only a renamed file's new path, so a fork could move a workflow
out of.github/workflows/(deleting it) and pass. The guard in
examples/gatehouse.ymland in this repo now reads bothfilenameand
previous_filenamefrom the pull-request files API. Found by Gatehouse
reviewing its own fleet rollout (RT #1507); repos that copied the example
should re-copy it. - A reply could clear a failed workflow guard. The guard ran only on
pull_request_target, so on apull_request_review_commentrun it reported
skipped, and a required check countsskippedas passing. It now runs on
both events, and posts its explanation only once.
v0.9.0
Changed
- Gatehouse calls OpenRouter, not the Gemini API. The default model is
openai/gpt-6-luna, withgoogle/gemini-3.1-flash-liteas an automatic
fallback when it is rate-limited or down. On a 33-diff replay of real
crunchtools changes, judged blind by two models from other vendors, Luna
caught as many reintroduced bugs asgemini-2.5-flashwhile nearly all of
2.5 Flash's findings on clean PRs were noise, at about a sixth of the cost
per review (RT #1505). - Every request requires zero data retention and forbids training on prompts.
--modeltakes an OpenRouter slug.- A reply wrapped as
{"findings": [...]}is unwrapped instead of dropped.
Added
OPENROUTER_API_KEY_FILE: read the key from a file (wins over the
variable; warns when the file is group- or world-readable).
Removed
- Breaking:
GEMINI_API_KEYis no longer read. Replace it with
OPENROUTER_API_KEYin~/.config/mcp-env/gatehouse.envand in the
GitHub secret passed toreview.yml. gatehouse exits 2 with a pointer
when only the old key is set.