Add pr-bugbot agent and harden pr-babysit guidance#1167
Conversation
Introduce a dedicated Bugbot triage agent and align pr-babysit with Run PR guardrails: merge-from-main only, reply-then-resolve, no silent body edits, and ledger bookkeeping.
|
Warning Review limit reached
Next review available in: 41 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe PR adds a dedicated Bugbot triage agent, revises the PR babysitting workflow with stricter validation and authorization rules, and appends a review record to the branch ledger. ChangesPR maintenance agents
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
This pull request has been ignored for the connected project Preview Branches by Supabase. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 79ea8a42a6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: be85383a72
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
Actionable comments posted: 6
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.cursor/agents/pr-babysit.md:
- Line 23: Update the instruction in the review protocol step to require
appending a docs/branch-review-ledger.md row after every completed review or
sweep, including pure or no-op reviews, instead of only after the PR is touched.
- Line 16: Update the merge guidance in pr-babysit.md to fetch and verify the
latest origin/main immediately before evaluating whether to merge it into the
feature branch. Preserve the existing instruction to merge when behind or
conflicts are trivial, abort and ask when intents conflict, and never rebase.
- Around line 20-23: Update .cursor/agents/pr-babysit.md lines 20-23 to require
explicit user confirmation before GitHub/GitLab mutations and hosted-CI actions,
while documenting the standing Run PR sweep exception if supported by the
repository protocol. Update .cursor/agents/pr-bugbot.md lines 25-26 to gate
commit, push, reply, and thread-resolution operations, not only provider-backed
actions; preserve any explicitly authorized standing-sweep behavior.
In @.cursor/agents/pr-bugbot.md:
- Around line 23-24: Unify the trusted thread-disposition contract across the
Bugbot workflow: in .cursor/agents/pr-bugbot.md lines 23-24, require the
repository-approved marker and fallback behavior before closing threads; in
.cursor/agents/pr-babysit.md lines 18-19, specify that delegated Bugbot threads
use the same authorized closure path rather than restricting the trusted marker
to Codex.
- Around line 12-18: Update the PR validation workflow in the instructions for
PR number or URL invocations to resolve the target PR’s exact head SHA, check
out or otherwise inspect that commit, and validate findings against it instead
of the currently checked-out branch HEAD. Preserve the existing behavior for
branch invocations.
- Around line 14-16: Update the review-thread and issue-comment filtering
instructions in the agent guidance to authenticate findings using the exact
expected bot login and bot type before treating them as actionable. Reject
user-authored or otherwise unverified comments, while preserving the existing
exclusion of resolved and outdated findings unless the defect remains in the
current head.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: ded9114b-8139-427d-95af-9f26b17d6d4a
📒 Files selected for processing (2)
.cursor/agents/pr-babysit.md.cursor/agents/pr-bugbot.md
…ents - Fetch origin/main before merge decisions; never authorize live gates in sweeps - Pin bugbot validation to target PR head SHA with exact bot identity checks - Require explicit user authorization for pushes and external mutations - Append ledger row after every completed sweep; clarify thread closure paths Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
…6c52' into HEAD # Conflicts: # .cursor/agents/pr-babysit.md # .cursor/agents/pr-bugbot.md
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/branch-review-ledger.md`:
- Line 750: Update the ledger row’s date to the actual completion date: use
2026-07-24 if the documented checks were completed today; otherwise defer or
append the entry with 2026-07-25 only after those actions occur. Preserve the
existing branch, commit, summary, and verification details.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: 6d99e11d-98a4-402f-a513-a6e473157aeb
📒 Files selected for processing (3)
.cursor/agents/pr-babysit.md.cursor/agents/pr-bugbot.mddocs/branch-review-ledger.md
🚧 Files skipped from review as they are similar to previous changes (2)
- .cursor/agents/pr-bugbot.md
- .cursor/agents/pr-babysit.md
Keep hardened babysit guidance; retain main PR_POLICY_BODY / budget note as step 11. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
CI triageCI failed on this PR. Automated classification of the 2 failed job(s):
Compared with main CI run #4967 (success). Classification is evidence routing, not permission to ignore a failure. Exact quarantined Playwright identities remain governed by the flake ledger. |
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
* docs(ledger): record babysit sweep for PRs #1124 #1131 #1146 #1157 #1162 #1167 #1169 #1170 Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com> * docs(ledger): record open-PR conflict-resolution sweep and #1162 Bugbot Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com> * docs(ledger): record #1162 conflict resolution and Bugbot outcome Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com> * docs(ledger): record open-PR conflict sync (all mergeable) Merged origin/main into remaining behind/dirty PR heads so every open PR is MERGEABLE with behind=0. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com> * docs(ledger): drop exact duplicate #1170 review row Remove the second identical PR #1170 ledger record so check:branch-review-ledger passes. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com> * docs(ledger): record open-PR conflict sync for 22 PRs Merged origin/main into every open PR head so all are current with main. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com> * docs(ledger): drop exact duplicate review rows Remove duplicate ledger records so check:branch-review-ledger passes after the conflict sync. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com> * fix: auto-sync open PR branches and clear postcss audit Add a main-push workflow and local helper that update behind PR heads so GitHub stops falsely marking the queue CONFLICTING/DIRTY after each land. Bump postcss to a non-vulnerable release so Safety npm audit stays green. --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Summary
fields=index, differentials abort/debounce, universal documents typeahead soft-timeout (750ms), shared(search-app)shell to avoid composer remount, and Answer rate-limit in-memory fallback outside production./services→/dsm) syncssearchModeduring render (no stale-mode paint) even when the query string is unchanged; extracted ClinicalDashboard lazy imports to stay under the maintainability budget.RAG impact: no retrieval behaviour change — typeahead documents domain timeout and shell URL sync only; ranking formulas and full
/api/searchretrieval path unchanged.Verification
npm run verify:pr-local— focused Vitest on touched sources (362) plus api-rate-limit / search-shell / universal / route / site-map suites green;docs:check-indexOKverify:uinot required for this pass; mode-home smoke vianpm run ensurereturned HTTP 200 for/,/services,/dsm,/documents/search,/therapy-compass,/?mode=prescribing, and/api/answer/streamreturned 200 after the rate-limit fallback fixeval:retrieval:latency/ soak / live OpenAI canary — approval-gated provider work; not needed for timeout-only typeahead changeRisk and rollout
GlobalSearchShelllayouts and prior timeout/fallback behaviourClinical Governance Preflight
[REDACTED]([REDACTED])Notes
fields=indexremains for identity-only consumers (cross-mode links).