Repository navigation
Conversation
CodeRabbit has been reviewing pull requests here with its defaults. This gives it the repository's own rules: per-path security instructions for the EQL SQL, the Rust crates and the customer skills; four advisory pre-merge checks for the rules no CI job enforces (changeset, customer skills, layout docs, public text hygiene); scanners CI does not already run; and fewer reviews per pull request (no drafts, pause after three reviewed commits, skip bot and Version Packages PRs). The settings a pull request must not be able to change for its own review live in the organisation's Global Overrides, not in this file, because CodeRabbit reads this file from the PR's own branch. The header lists them.
|
|
@coderabbitai review |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📜 Recent review details⏰ Context from checks skipped due to timeout. (6)
📝 WalkthroughWalkthroughThe ChangesReview configuration
Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to No actionable issue is established; the configuration is ready to merge after normal checks. 🚥 Pre-merge checks | ✅ 6✅ Passed checks (6 passed)
Comment |
✅ Action performedReview finished.
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 11662b082e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| high_level_summary: false # PR bodies are written by hand; don't rewrite them | ||
| high_level_summary_in_walkthrough: true |
There was a problem hiding this comment.
Keep the high-level summary enabled
Setting high_level_summary to false disables the summary that line 25 attempts to place in the walkthrough, so normal PRs will receive no high-level summary at all. CodeRabbit’s summary documentation states that this setting stops summary generation, while high_level_summary_in_walkthrough: true alone moves an enabled summary out of the PR description; keep the former enabled to get the intended walkthrough-only summary.
Useful? React with 👍 / 👎.
| custom_checks: | ||
| - name: Changeset | ||
| mode: warning | ||
| instructions: "Fail if files under languages/typescript/packages/*/src, packages/eql/packages/eql, or skills/ changed and no .changeset/*.md file was added. A skills-only change needs a 'stash' patch changeset. Fail if any .changeset file ends in .md.deferred. Pass for changes that only touch tests, scripts/, docs/ or .github/." |
There was a problem hiding this comment.
Cover native FFI changes in the changeset check
A PR that changes only languages/typescript/packages/protect-ffi/crates/**/*.rs can alter the published native module without touching any path listed here, so this check passes without requiring a changeset. Include the FFI Cargo sources and other release-relevant non-src package surfaces in the trigger; the repository explicitly requires normal changesets for the seven protect-ffi packages.
AGENTS.md reference: AGENTS.md:L165-L167
Useful? React with 👍 / 👎.
| instructions: "Fail if files under languages/typescript/packages/*/src, packages/eql/packages/eql, or skills/ changed and no .changeset/*.md file was added. A skills-only change needs a 'stash' patch changeset. Fail if any .changeset file ends in .md.deferred. Pass for changes that only touch tests, scripts/, docs/ or .github/." | ||
| - name: Customer skills | ||
| mode: warning | ||
| instructions: "If the CLI command registry, CLI flags, or a public export of @cipherstash/stack, stack-drizzle, stack-supabase, stack-prisma or the dynamodb entry changed, fail unless the matching skills/*/SKILL.md (per the table in AGENTS.md 'Agent Skills') also changed, or the PR description explains why no skill is affected." |
There was a problem hiding this comment.
Apply the skills check to every mapped public surface
This trigger covers CLI changes and export-list changes in a few packages, but misses mapped changes such as languages/typescript/packages/migrate lifecycle behavior, EQL operators, deployment workflows, auth strategy behavior, and ordinary API behavior changes that leave exports unchanged. Those PRs can therefore pass the dedicated check while shipping stale customer instructions; trigger it for every public API or user-facing workflow covered by the AGENTS skill map.
AGENTS.md reference: AGENTS.md:L780-L782
Useful? React with 👍 / 👎.
auxesis
left a comment
There was a problem hiding this comment.
What are the success and failure metrics for this experiment?
Or to put another way:
- What is the hypothesis we are testing with @coderabbitai?
- Why are we doing that?
- How do we measure the impact of this @coderabbitai configuration?
- What measurements falsify the hypothesis?
Summary
CodeRabbit is an AI code reviewer that runs as a GitHub App. It is already installed here and reviews every pull request to
main, but with its default settings. This adds.coderabbit.yamlso the review knows this repository's rules: the encryption library must not leak plaintext, customer-facing skills must stay accurate, and published changes need a changeset. It also cuts how often CodeRabbit reviews a pull request.This is the CodeRabbit replacement for the four-lens Claude review in #1005. That workflow ran on GitHub Actions runners and waited five minutes per lens before every review. CodeRabbit runs on its own servers and uses no runner time.
Changes
Review content
packages/eql/**/*.sql), the Rust crates, andskills/**/SKILL.md, which ship to customers in thestashpackage.warningmode so none blocks a merge: changeset present, customer skills updated with the API or CLI they describe,AGENTS.mdlayout andSECURITY.mdupdated when a package is added or removed, and no Linear IDs or workflows under a package. Each shows as pass or fail in CodeRabbit's walkthrough comment.SKILL.mdfiles). Scanners CI already runs (osv-scanner, golangci-lint) are off, as are ESLint and Oxc because the repo uses Biome. SQLFluff, markdownlint and LanguageTool are off as noise.Fewer reviews and less noise
@coderabbitai reviewasks for another.github-actions[bot],changeset-bot[bot], Version Packages andWIPPRs are skipped.docs/plans/, snapshots and changelogs are excluded.main(stacked PRs) are now reviewed too.What is not in this file, on purpose
CodeRabbit reviews a pull request using the
.coderabbit.yamlon that PR's own branch, so a PR can change its own review. The settings that must not be changeable that way are set in CodeRabbit's organisation Global Overrides, which win over this file. The file header lists them:.github/**and the TypeScript package sources;Verification
cr config validate .coderabbit.yaml: valid against the current CodeRabbit schema.schema.v2.jsonwith jsonschema: 0 errors. The schema accepts unknown keys, so a separate check confirmed every key in the file exists in the schema.@coderabbitai configurationon ci(claude-review): run Anthropic's code-review plugin, on open or on request #1005 reports all 11 override keys asSource: Global overrides.Related
Refs #1005, #997
Review notes
.coderabbit.yamlfrom the PR branch, so its review here is the first live test. It is a draft, and drafts are skipped, so I'll trigger the review with@coderabbitai review. Check that the walkthrough's run configuration names the repository file rather than "Organization UI" or "defaults", and that the review details list the guideline files used.AGENTS.mdandCLAUDE.md, and everyskills/*/SKILL.md, as review criteria. The skills are customer guidance, not review rules. They can only be excluded in the CodeRabbit UI, not in this file. That is a separate step.maindoes not require code-owner review, and*is already owned by@cipherstash/developers, so a.coderabbit.yamlentry would change nothing.review_details: trueis for the rollout. Turn it off once the guideline and tool choices are settled.