You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
--max-reviews N caps how many reviews one loop runs, however large the
expanded --reviews/set schedule is. The cut happens after the seeded
per-loop shuffle, so --seed replays exactly which N ran and different
loops sample different reviews; a review scheduled twice fills two of the
N slots when both land inside the cut. With --stacked-prs the single
ordered pass is truncated to its first N entries. 0 (the default) is
unlimited, and --dry-run reports the capped count.
Three reviews for Kubernetes and GitOps repos: k8s-review (manifests,
cross-resource reference integrity, API deprecations, and kustomize
structure, components included), gitops-review (the Argo CD / Flux
delivery layer: source pinning, sync and prune posture, ordering and
health, secrets delivery, environment promotion), and helm-review
(chart authoring: template correctness, the values contract, hooks, CRD
lifecycle). Each gates on evidence in the tree and reviews
tool-agnostically when the delivery tool leaves no markers. A new gitops set schedules them together with container-review, infra-review, sec-review, and dr-review.
--paths LIST scopes every review to the named files, directories, or
globs, relative to the reviewed directory (comma-separated, repeatable).
The agent still works from the whole repository for context; the composed
review prompt tells it to report findings on and modify only the listed
paths, so the scope is prompt-enforced, not mechanical. Without the flag,
prompts are byte-identical to before. Suggest, commit, and conflict
prompts are unchanged, and an explicit empty --paths is refused.
Stacked-PR bodies open with an overview of what the change is about: the PATH: lines a review prints are matched against the layer's own commit,
deduplicated, and joined into one short paragraph under ## Summary; the ## Changes file list stays bare paths. Notes naming files the commit
never touched are dropped. The overview is flattened, length-bounded, and
backtick-neutralized like every other untrusted value in the body, and the
whole body is now capped as well.
Changed
container-review and infra-review split Kubernetes workload
ownership more sharply now that k8s-review and helm-review exist:
manifest structure, probes, security context, and resource limits stay
with those reviews; infra-review keeps compose, CI/CD, and IaC wiring. container-review will use dockle, kubeconform, and conftest when
they are on PATH. lint-review names the project linters it should run.
Stack branches are named review/<NN>-<review>-<topic> (e.g. review/03-sec-review-input-validation) instead of gauntlet/stack/<tip>/<NN>-<review>: the 1-based layer number keeps merge
order sortable and the topic is a slug cut from the commit subject. Each
layer starts under a deterministic provisional name
(review/<NN>-<review>-wip-<base>) and is renamed once its commit exists,
before the push. A resumed run finds published layers by listing the
deterministic review/<NN>-<review> prefix and verifying candidates by
commit graph -- a layer must be a one-commit child of the previous layer's
tip -- so a same-named branch from an older stack is rejected by ancestry;
when it occupies the topic name, the new layer appends the stack's short
base commit. The preflight dry-run probe moved to the same review/
namespace, and review/ branches are no longer offered as merge targets,
matching gauntlet/.
Fixed
Streamed runs (--stream, the default) lost every commit subject and
per-file note: the report parsers read the output tail, which held the raw
JSON event lines, and SUBJECT:/PATH: sit inside one escaped string
there, where the parsers' line anchors match nothing. Commits fell back to
the generated chore: update <file> subject every time. The tail now keeps
each stream event's decoded text, so subjects, per-file notes, and the
branch topics cut from subjects come from what the agent actually printed.