Commit graph

14 commits

Author SHA1 Message Date
dependabot[bot]
4caf4dbf80
Bump uvicorn from 0.50.2 to 0.51.0 (#5)
Bumps [uvicorn](https://github.com/Kludex/uvicorn) from 0.50.2 to 0.51.0.
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.50.2...0.51.0)

---
updated-dependencies:
- dependency-name: uvicorn
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 13:37:38 -04:00
dependabot[bot]
997a3e0870
Bump httpx2 from 2.5.0 to 2.7.0 (#6)
Bumps [httpx2](https://github.com/pydantic/httpx2) from 2.5.0 to 2.7.0.
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](https://github.com/pydantic/httpx2/compare/v2.5.0...v2.7.0)

---
updated-dependencies:
- dependency-name: httpx2
  dependency-version: 2.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-15 12:49:59 -04:00
dependabot[bot]
12bd7eb573
Bump uvicorn from 0.49.0 to 0.50.2 (#4)
Bumps [uvicorn](https://github.com/Kludex/uvicorn) from 0.49.0 to 0.50.2.
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](https://github.com/Kludex/uvicorn/compare/0.49.0...0.50.2)

---
updated-dependencies:
- dependency-name: uvicorn
  dependency-version: 0.50.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-07-08 10:49:50 -04:00
Adam Moussa
8b53da8f99
chore(ci): SHA-pin org reusable-workflow caller refs (INFRA-50) (#3) 2026-07-06 18:27:15 -04:00
Adam Moussa
c4d1827c50
docs: add README status badges (INFRA-137) (#2) 2026-07-06 17:41:12 -04:00
Adam Moussa
6500bc85aa
chore(ci): add org dependency-review caller (INFRA-125) (#1) 2026-07-06 17:40:57 -04:00
138d300048
Add sidebar quick buttons and Dependabot review rendering
Add Expand all / Collapse all controls and a Dependabot-only filter to the
top of the queue sidebar. Render the dependency-risk assessment in the
detail view (update-type and risk badges, packages, reasons, title and
description notes) reusing the post, revise, and auto-merge controls, and
show a risk chip on Dependabot rows in the queue. Reviews without a "_kind"
fall back to the code-review layout.
2026-07-01 19:46:15 -04:00
667afd73f9
Assess Dependabot PRs for merge risk instead of code review
Dependabot dependency-update PRs do not benefit from BLOCK/FIX/NIT/QUESTION
code notes. Route them to a dependency-risk assessment instead: the semver
update type, a safe/low_risk/risky/breaking call, the packages bumped, and
reasons, grounded in the Sea Haven Dependabot merge policy (patch/minor
generally safe; majors need changelog review; grouped PRs assessed at the
riskiest package). Feedback focuses on PR title/description quality.

review() dispatches on the author to a dependabot or code path, each
stamping a "_kind" so consumers can tell the shapes apart (missing "_kind"
reads as code, keeping older cached reviews valid). Enum fields are clamped
to allowlists with cautious defaults so a hallucinated or injected value
cannot reach the posted event. The handbook distillation also captures the
dependency policy, though the prompt carries it regardless.
2026-07-01 19:46:15 -04:00
d60efeca28
Bump pytest to 9.1.1 for CVE-2025-71176
The pre-push security scanner flagged pytest 8.3.4 (CVE-2025-71176).
Dev/test-only dependency, not shipped, but bump to the patched release.
Suite passes on 9.x unchanged.
2026-07-01 19:12:45 -04:00
26f0558589
Group PRs by repo in the sidebar and add auto-merge
Group the review queue into a collapsible section per repo (collapse
state persisted in localStorage), with PRs ordered oldest to newest by
creation date, so a large multi-repo queue is easier to scan.

Add an optional per-PR auto-merge control: a method choice (squash by
default per handbook, merge, or rebase) enables GitHub auto-merge via a
GraphQL mutation, so the PR merges once required checks pass. It only
fires when clicked; nothing merges automatically.

Back this with created_at and node_id from the PR search, two new
nullable store columns added via an idempotent PRAGMA-guarded migration,
and a cheap-gate metadata backfill so already-cached PRs gain node_id
without being re-reviewed. New endpoint POST /api/automerge.
2026-07-01 19:11:09 -04:00
c07e4397aa
Harden review JSON parsing against reasoning models
Some Fireworks models emit chain-of-thought before the JSON review, and
that preamble can contain stray "{". The old first-"{"-to-last-"}" span
then grabbed reasoning braces and failed to parse (seen live on a real
PR). Scan each "{" and return the first substring that actually decodes
to an object instead, so a preamble or trailing prose no longer breaks
the review.
2026-07-01 19:11:09 -04:00
89494c1710
Ground reviews in the engineering-handbook
Feed the reviewer a distilled digest of the Sea Haven engineering-handbook
so findings reflect our naming, commit, PR, secrets, and IaC conventions
instead of generic code-review judgment.

A new handbook module keeps an app-managed shallow clone of the (private)
handbook, distills the review-relevant pages into a compact conventions
checklist via the Fireworks model once a day, caches it under ~/.cache,
and hands it to the reviewer to inject into every review's system prompt.
The refresh runs in-process at the start of each worker cycle; failures
keep the last good digest and back off, so a handbook outage never blocks
reviews. Set HANDBOOK_ENABLED=false to disable.

Extract a shared fireworks_complete helper used by both the reviewer and
the distiller, so the handbook provider needs no reviewer reference and
the guidance callable is set once at construction. Clone auth uses a
Basic http.extraHeader (GitHub git-over-HTTPS rejects Bearer), and the
distiller wraps its answer in delimiters to strip a reasoning model's
chain-of-thought preamble. Adds GET /api/handbook and a header status
line. Stdlib-only, no new dependencies.
2026-07-01 17:08:21 -04:00
15a52bff40
Add background auto-review worker with SQLite cache
Pre-compute PR reviews so they are ready the moment a PR is opened in
the queue, instead of waiting on an on-demand Fireworks call each time.

A daemon worker polls the queue every POLL_INTERVAL and reviews new or
changed non-draft PRs into a local SQLite cache (gitignored). Change
detection is two-level: skip when the PR's updated_at is unchanged, and
even when it moved, skip the model call when the diff's SHA-256 matches,
so comment-only bumps do not burn tokens. Failed reviews retry up to
MAX_REVIEW_ATTEMPTS with 429 backoff; departed PRs are closed with a
grace window before purge.

Singletons are initialized eagerly in the FastAPI lifespan before the
worker thread starts to avoid an init race; all cache writes are
serialized. New endpoints GET /api/reviews and POST /api/refresh back a
dashboard that polls for status (reviewing/ready/error) and opens a
ready review instantly. Nothing is posted automatically; the human
still decides. Stdlib-only, so no new runtime or test dependencies.
2026-07-01 14:28:11 -04:00
46cd856fb3
Add pr-reviewer local PR review tool
A single-user local dashboard that pulls open PRs from the
Sea-Haven-Industries org, reviews each with a Fireworks model in the
BLOCK/FIX/NIT/QUESTION format, and posts the review to GitHub as the
token owner. Runs only on localhost; secrets stay in a gitignored .env
and never reach the browser.

Structured as an app/ package plus a static/ frontend so the module
imports and static mount resolve. HTTP uses httpx2 (the runtime lib
starlette's TestClient now prefers), pinned in requirements.txt.

Includes a stdlib-only pytest suite (network mocked, no extra test
deps so CI needs only pytest) with a skip-by-default live Fireworks
test, and CI wired to the org ci-python-app reusable workflow to lint
app and tests and run the mocked suite fully offline. Dependabot covers
pip and github-actions.
2026-07-01 13:48:10 -04:00