mirror of
https://github.com/Sea-Haven-Industries/pr-reviewer.git
synced 2026-09-30 09:13:15 +00:00
Dependabot dependency-update PRs do not benefit from BLOCK/FIX/NIT/QUESTION code notes. Route them to a dependency-risk assessment instead: the semver update type, a safe/low_risk/risky/breaking call, the packages bumped, and reasons, grounded in the Sea Haven Dependabot merge policy (patch/minor generally safe; majors need changelog review; grouped PRs assessed at the riskiest package). Feedback focuses on PR title/description quality. review() dispatches on the author to a dependabot or code path, each stamping a "_kind" so consumers can tell the shapes apart (missing "_kind" reads as code, keeping older cached reviews valid). Enum fields are clamped to allowlists with cautious defaults so a hallucinated or injected value cannot reach the posted event. The handbook distillation also captures the dependency policy, though the prompt carries it regardless. |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| config.py | ||
| github_client.py | ||
| handbook.py | ||
| main.py | ||
| reviewer.py | ||
| store.py | ||
| worker.py | ||