Skip to content

v1.18.0

Choose a tag to compare

@github-actions github-actions released this 12 Sep 13:32
· 370 commits to main since this release

Added

  • --max-reviews N caps how many reviews one loop runs, however large the
    expanded --reviews/set schedule is. The cut happens after the seeded
    per-loop shuffle, so --seed replays exactly which N ran and different
    loops sample different reviews; a review scheduled twice fills two of the
    N slots when both land inside the cut. With --stacked-prs the single
    ordered pass is truncated to its first N entries. 0 (the default) is
    unlimited, and --dry-run reports the capped count.
  • Three reviews for Kubernetes and GitOps repos: k8s-review (manifests,
    cross-resource reference integrity, API deprecations, and kustomize
    structure, components included), gitops-review (the Argo CD / Flux
    delivery layer: source pinning, sync and prune posture, ordering and
    health, secrets delivery, environment promotion), and helm-review
    (chart authoring: template correctness, the values contract, hooks, CRD
    lifecycle). Each gates on evidence in the tree and reviews
    tool-agnostically when the delivery tool leaves no markers. A new
    gitops set schedules them together with container-review,
    infra-review, sec-review, and dr-review.
  • --paths LIST scopes every review to the named files, directories, or
    globs, relative to the reviewed directory (comma-separated, repeatable).
    The agent still works from the whole repository for context; the composed
    review prompt tells it to report findings on and modify only the listed
    paths, so the scope is prompt-enforced, not mechanical. Without the flag,
    prompts are byte-identical to before. Suggest, commit, and conflict
    prompts are unchanged, and an explicit empty --paths is refused.
  • Stacked-PR bodies open with an overview of what the change is about: the
    PATH: lines a review prints are matched against the layer's own commit,
    deduplicated, and joined into one short paragraph under ## Summary; the
    ## Changes file list stays bare paths. Notes naming files the commit
    never touched are dropped. The overview is flattened, length-bounded, and
    backtick-neutralized like every other untrusted value in the body, and the
    whole body is now capped as well.

Changed

  • container-review and infra-review split Kubernetes workload
    ownership more sharply now that k8s-review and helm-review exist:
    manifest structure, probes, security context, and resource limits stay
    with those reviews; infra-review keeps compose, CI/CD, and IaC wiring.
    container-review will use dockle, kubeconform, and conftest when
    they are on PATH. lint-review names the project linters it should run.
  • Stack branches are named review/<NN>-<review>-<topic> (e.g.
    review/03-sec-review-input-validation) instead of
    gauntlet/stack/<tip>/<NN>-<review>: the 1-based layer number keeps merge
    order sortable and the topic is a slug cut from the commit subject. Each
    layer starts under a deterministic provisional name
    (review/<NN>-<review>-wip-<base>) and is renamed once its commit exists,
    before the push. A resumed run finds published layers by listing the
    deterministic review/<NN>-<review> prefix and verifying candidates by
    commit graph -- a layer must be a one-commit child of the previous layer's
    tip -- so a same-named branch from an older stack is rejected by ancestry;
    when it occupies the topic name, the new layer appends the stack's short
    base commit. The preflight dry-run probe moved to the same review/
    namespace, and review/ branches are no longer offered as merge targets,
    matching gauntlet/.

Fixed

  • Streamed runs (--stream, the default) lost every commit subject and
    per-file note: the report parsers read the output tail, which held the raw
    JSON event lines, and SUBJECT:/PATH: sit inside one escaped string
    there, where the parsers' line anchors match nothing. Commits fell back to
    the generated chore: update <file> subject every time. The tail now keeps
    each stream event's decoded text, so subjects, per-file notes, and the
    branch topics cut from subjects come from what the agent actually printed.