Skip to content

chore: pin self-review workflow to the canonical dotCMS repo - #4

Merged
wezell merged 6 commits into
mainfrom
chore/pin-self-review-to-canonical
Sep 29, 2026
Merged

wezell merged 6 commits into
mainfrom
chore/pin-self-review-to-canonical

Conversation

@wezell

@wezell wezell commented Sep 4, 2026 •

Copy link
Copy Markdown
Member

What

This repo is no longer a fork of wezell/openrouter-code-review-action — it is the canonical home. Point the self-review workflow's trusted-ref pin at itself instead of the upstream fork.

Changes

  • .github/workflows/dotbot-review.yml — uses: dotCMS/openrouter-code-review-action@a716ed1… (the v1.0.3 tag SHA), replacing the wezell@d68edbb… pin.
  • tests/test_module_coverage.py — the review-workflow assertion now checks dotCMS/openrouter-code-review-action@; the act-workflow assertion still checks wezell@ (act mode is unchanged).

Notes

🤖 Generated with Zed

This repo is no longer a fork of wezell/openrouter-code-review-action —
it is the canonical home. Point the self-review workflow's trusted-ref
pin at itself (v1.0.3 tag SHA) and update the coverage test to assert
the canonical owner for the review workflow. The act workflow still
pins the wezell ref; update it separately if desired.
Auto Release on Merge cut v1.1.0 from the merged main; follow the
'update the pin on each release' convention and point the self-review
workflow at the latest release SHA.
Comment thread .github/workflows/dotbot-review.yml Outdated
v1.1.0 is an annotated tag, so the tag ref returns the tag object SHA
(a2b9517), which does not resolve as a uses: ref. Peel it to the commit
SHA (aa372f5) the tag points at.
wezell added a commit that referenced this pull request Sep 29, 2026
wezell/openrouter-code-review-action is no longer the source of releases: its
main/v1/latest sit at 34ee169 (v1.0.0-era, no github_approval_token input), and
it has no release carrying that input. So after the previous two commits the run
died earlier still:

  ##[error]Unable to resolve action
  `wezell/openrouter-code-review-action@bbe2345...`

This repo is canonical and cuts its own releases (auto-release.yml), so point
both workflows at bbe2345... (v1.2.0 / v1 /
latest), which declares every input the workflows pass, and require the canonical
owner in tests. Supersedes the still-open PR #4, which pinned the review workflow
to v1.1.0 and left act on wezell.
Updated the action reference to use the latest version.
Both dotbot workflows now use dotCMS/openrouter-code-review-action@latest
instead of a frozen SHA: dotCMS owns this repo and cuts every release here
(auto-release.yml), so the moving tag is as trusted as a SHA and can never
lag an input the workflows pass.

- fix the broken `:latest` ref (Actions refs use `@`, not `:`)
- point dotbot-act.yml at @latest too, kept in lockstep with the review workflow
- restore the coverage/guard tests this branch had deleted and assert the
  shared @latest pin again
- revert the merge-artifact review model change back to deepseek-v4-pro-0813
- teach the actionlint CI step to ignore its unknown-`queue` false positive:
  concurrency `queue` is valid GitHub syntax, actionlint 1.7.12 predates it
@github-actions

Copy link
Copy Markdown

dotbot code review:

  • Reviewer: meta/muse-spark-1.3 (medium)
  • Overall: patch is correct
  • New findings this run: 0
  • Prior unresolved dotbot findings still relevant: 0
  • Active findings total: 0

Change intentionally floats both self-hosted workflows on the canonical @latest tag owned by this repo with test enforcement, and narrowly ignores only the actionlint queue diagnostic. No correctness, security, or atomicity regression introduced by this patch.

Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads.

reviewed by dotbot · meta/muse-spark-1.3 · medium

@github-actions

Copy link
Copy Markdown

dotbot code review:

  • Reviewer: ~z-ai/glm-latest (medium)
  • Overall: patch is correct
  • New findings this run: 0
  • Prior unresolved dotbot findings still relevant: 0
  • Active findings total: 0

The change intentionally floats both self-hosted workflows on the repo-owned @latest tag, keeps the test pin assertion in lockstep, and adds a narrowly-scoped actionlint ignore for the concurrency.queue diagnostic matching the actual actionlint message format. No correctness, security, or atomicity issue is introduced by this patch.

Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads.

reviewed by dotbot · ~z-ai/glm-latest · medium

@dotCMS-Machine-User dotCMS-Machine-User left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ dotbot review: all reviewer models (meta/muse-spark-1.3, ~z-ai/glm-latest) agree — patch is correct.

approved automatically by dotbot

@wezell
wezell merged commit 0172411 into main Sep 29, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants