Fix post-release WinGet automation - #61
Conversation
|
Warning Review limit reached
Next review available in: 20 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (7)
📝 WalkthroughWalkthroughChangesWorkflow automation
Estimated code review effort: 3 (Moderate) | ~20 minutes 🚥 Pre-merge checks | ✅ 8✅ Passed checks (8 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
PR Summary by QodoTrigger WinGet publish on successful Release workflow completion
AI Description
Diagram
High-Level Assessment
Files changed (10)
|
There was a problem hiding this comment.
Hey - I've found 1 issue, and left some high level feedback:
- The WinGet
publishjob gating logic assumes tags start withvand usesworkflow_run.head_branchas the tag, which may not cover alternative tag naming schemes or non-standard release flows; consider either documenting this constraint explicitly or relaxing thestartsWithcheck to support broader tag patterns. - In the WinGet workflow,
release-tagfalls back togithub.event.workflow_run.head_branchwheninputs.release_tagis omitted, which will be incorrect for manually dispatched runs on non-tag branches; you may want to makerelease_tagrequired forworkflow_dispatchor derive the tag more defensively for that case. - All updated GitHub Actions are pinned to version tags (e.g.,
actions/checkout@v7.0.1); for better supply-chain safety you might consider pinning to immutable commit SHAs instead of semver tags, especially for security-sensitive workflows like release and WinGet publishing.
Prompt for AI Agents
Please address the comments from this code review:
## Overall Comments
- The WinGet `publish` job gating logic assumes tags start with `v` and uses `workflow_run.head_branch` as the tag, which may not cover alternative tag naming schemes or non-standard release flows; consider either documenting this constraint explicitly or relaxing the `startsWith` check to support broader tag patterns.
- In the WinGet workflow, `release-tag` falls back to `github.event.workflow_run.head_branch` when `inputs.release_tag` is omitted, which will be incorrect for manually dispatched runs on non-tag branches; you may want to make `release_tag` required for `workflow_dispatch` or derive the tag more defensively for that case.
- All updated GitHub Actions are pinned to version tags (e.g., `actions/checkout@v7.0.1`); for better supply-chain safety you might consider pinning to immutable commit SHAs instead of semver tags, especially for security-sensitive workflows like release and WinGet publishing.
## Individual Comments
### Comment 1
<location path=".github/workflows/ci.yml" line_range="25" />
<code_context>
steps:
- name: Check out repository
- uses: actions/checkout@v4
+ uses: actions/checkout@v7.0.1
- name: Install Rust toolchain
</code_context>
<issue_to_address>
**issue (bug_risk):** actions/checkout@v7.0.1 does not currently exist and will fail at runtime
The latest published major version of `actions/checkout` is `v4`. Using `actions/checkout@v7.0.1` will fail because that tag does not exist. If you want to stay current, pin to `v4` (optionally with a specific minor/patch) until a `v7` release actually appears.
</issue_to_address>Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
Code Review by Qodo
Context used✅ Compliance rules (platform):
22 rules🟡 Remediation Recommended 1.
|
Qodo Fixer✅ Merged (0) · ☑ Fixed (0) Process
|
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/active-plugin-update-acceptance.yml:
- Around line 21-27: Replace every movable-tag uses reference with the
corresponding full immutable commit SHA across all listed workflow sites:
.github/workflows/active-plugin-update-acceptance.yml lines 21-27;
.github/workflows/ci.yml lines 25-27, 35-39, 46, 56-58, 65-67, 74, and 84-86;
.github/workflows/official-registry-acceptance.yml lines 17-23;
.github/workflows/claude-code-review.yml line 19; .github/workflows/claude.yml
line 29; .github/workflows/cline-pr-review.yml line 31; and
.github/workflows/release.yml lines 55-58, 69-73, 105, 124, 156, 167, 179, and
208. Preserve each action and its current version while pinning it to the
verified commit SHA.
In @.github/workflows/ci.yml:
- Line 27: Update each Swatinem/rust-cache step in the CI workflow to prevent
fork- or pull-request-controlled jobs from writing or restoring caches used by
trusted workflows. Gate cache usage or writes on trusted refs/conditions, while
preserving caching for trusted runs across all referenced jobs.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: e3999413-ef91-4223-907f-7e88aae31e65
📒 Files selected for processing (10)
.github/workflows/active-plugin-update-acceptance.yml.github/workflows/ci.yml.github/workflows/claude-code-review.yml.github/workflows/claude.yml.github/workflows/cline-pr-review.yml.github/workflows/official-registry-acceptance.yml.github/workflows/release.yml.github/workflows/winget.ymldocs/PACKAGING.mddocs/RELEASING.md
🔗 Linked repositories identified
CodeRabbit considers these linked repositories for cross-repo context during reviews:
Trackdubllc/Trackdub(manual)tonythethompson/QuickShell(manual)tonythethompson/numan(manual)tonythethompson/dependency-chain-substrate(manual)
📜 Review details
⏰ Context from checks skipped due to timeout. (4)
- GitHub Check: Sourcery review
- GitHub Check: Test (windows-latest)
- GitHub Check: Real-Nu acceptance (windows-latest)
- GitHub Check: Analyze (rust)
🧰 Additional context used
📓 Path-based instructions (2)
**/*.{rs,md}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when changing structure, conventions, or user-visible behavior, using
AGENTS.md,docs/, or command help as appropriate.
Files:
docs/RELEASING.mddocs/PACKAGING.md
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Redact secrets when reporting relevant logs or lockfile excerpts in issues.
Files:
docs/RELEASING.mddocs/PACKAGING.md
🪛 LanguageTool
docs/RELEASING.md
[style] ~52-~52: Three successive sentences begin with the same word. Consider rewording the sentence or use a thesaurus to find a synonym.
Context: ...CRATES_IO_TOKEN repository secret). 9. Confirm the [Publish to WinGet`](../.github/wo...
(ENGLISH_WORD_REPEAT_BEGINNING_RULE)
[uncategorized] ~52-~52: The official name of this software platform is spelled with a capital “H”.
Context: ...KEN repository secret). 9. Confirm the [Publish to WinGet`](../.github/workflows/winget.yml) workflow opens th...
(GITHUB)
docs/PACKAGING.md
[uncategorized] ~10-~10: The official name of this software platform is spelled with a capital “H”.
Context: ...riggered Release workflow succeeds, the Publish to WinGet workflow generate...
(GITHUB)
🪛 zizmor (1.28.0)
.github/workflows/claude.yml
[error] 29-29: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
.github/workflows/active-plugin-update-acceptance.yml
[error] 21-21: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 24-24: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 27-27: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[info] 24-24: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
.github/workflows/cline-pr-review.yml
[error] 31-31: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
.github/workflows/official-registry-acceptance.yml
[error] 17-17: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 23-23: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[info] 20-20: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
.github/workflows/claude-code-review.yml
[error] 19-19: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
.github/workflows/release.yml
[error] 55-55: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[warning] 69-69: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 69-69: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 70-70: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 73-73: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 73-73: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[info] 70-70: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[warning] 105-105: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 105-105: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 124-124: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 124-124: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[error] 156-156: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[warning] 167-167: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 167-167: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 179-179: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[warning] 208-208: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 208-208: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
.github/workflows/ci.yml
[warning] 25-25: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 35-35: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 46-46: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 25-25: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 26-26: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 27-27: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 35-35: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 36-36: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 39-39: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 46-46: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 27-27: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[error] 39-39: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[info] 26-26: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[info] 36-36: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[warning] 56-56: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 65-65: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 74-74: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 56-56: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 57-57: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 58-58: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 65-65: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 66-66: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 67-67: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 74-74: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 58-58: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[error] 67-67: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[info] 57-57: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[info] 66-66: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[warning] 84-84: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 84-84: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 85-85: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 86-86: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 86-86: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[info] 85-85: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
🔍 Remote MCP GitHub Copilot
Relevant review context
lewagon/wait-on-check-actiononly requiresrefandrepo-token; itsaction.ymlhas norepoinput, so removing that input matches upstream docs. Its README also points toworkflow_runas the native alternative for default-branch-only workflows.- The PR’s pinned action versions match current upstream releases:
actions/checkoutv7.0.1,Swatinem/rust-cachev2.9.1,lewagon/wait-on-check-actionv1.9.0,actions/upload-artifactv7.0.1, andactions/download-artifactv8.0.1. actions/checkoutv7 adds safer fork PR handling viaallow-unsafe-pr-checkout, plus ESM/dependency updates.
🔇 Additional comments (4)
.github/workflows/claude-code-review.yml (1)
33-33: LGTM!.github/workflows/winget.yml (1)
20-25: 🗄️ Data Integrity & IntegrationProve that the triggering ref is a tag, not merely
v-prefixed.This guard accepts any successful
pushrun whosehead_branchstarts withv. If theReleaseworkflow can run for a branch namedv..., WinGet publication will proceed from a non-tag run, violating the stated boundary. Make the Release trigger tag-only or validate that the triggeringhead_shais actually referenced byrefs/tags/v...before invokingwinget-releaser. GitHub exposes the triggering workflow-run payload to downstreamworkflow_runworkflows, so this validation should be explicit rather than inferred from a prefix. (docs.github.com)docs/PACKAGING.md (1)
10-10: LGTM!docs/RELEASING.md (1)
52-52: LGTM!
|
Code review by qodo was updated up to the latest commit feb21b4 |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/ci.yml:
- Line 26: Replace every dtolnay/rust-toolchain reference at
.github/workflows/ci.yml lines 26-26, 36-36, 57-57, 66-66, and 85-85,
.github/workflows/official-registry-acceptance.yml line 20-20, and
.github/workflows/release.yml line 70-70 with the full commit SHA for its
existing Rust channel, preserving whether each reference uses stable or 1.88.
In @.github/workflows/cline-pr-review.yml:
- Line 31: Update the actions/setup-node step in the workflow to use
actions/setup-node@v5 and pin it to the corresponding commit SHA, completing the
job’s Node 24 migration while preserving the existing setup configuration.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: b1882797-ca59-4010-bac0-e589f050e0db
📒 Files selected for processing (7)
.github/workflows/active-plugin-update-acceptance.yml.github/workflows/ci.yml.github/workflows/claude-code-review.yml.github/workflows/claude.yml.github/workflows/cline-pr-review.yml.github/workflows/official-registry-acceptance.yml.github/workflows/release.yml
🔗 Linked repositories identified
CodeRabbit considers these linked repositories for cross-repo context during reviews:
Trackdubllc/Trackdub(manual)tonythethompson/QuickShell(manual)tonythethompson/numan(manual)tonythethompson/dependency-chain-substrate(manual)
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
- GitHub Check: Real-Nu acceptance (windows-latest)
- GitHub Check: Test (windows-latest)
- GitHub Check: Analyze (rust)
🧰 Additional context used
🪛 zizmor (1.28.0)
.github/workflows/official-registry-acceptance.yml
[error] 20-20: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[info] 20-20: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
.github/workflows/active-plugin-update-acceptance.yml
[error] 24-24: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[info] 24-24: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
.github/workflows/ci.yml
[warning] 25-25: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 35-35: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 46-46: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 26-26: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 36-36: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 27-27: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[error] 39-39: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[info] 26-26: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[info] 36-36: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[warning] 56-56: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 65-65: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 74-74: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 57-57: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 66-66: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 58-58: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[error] 67-67: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[info] 57-57: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[info] 66-66: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[warning] 84-84: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 85-85: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 86-86: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[info] 85-85: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
.github/workflows/release.yml
[warning] 69-69: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 70-70: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
[error] 73-73: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[info] 70-70: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[warning] 105-105: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 124-124: runtime artifacts potentially vulnerable to a cache poisoning attack (cache-poisoning): enables caching by default
(cache-poisoning)
[warning] 167-167: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[warning] 208-208: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
🔍 Remote MCP DeepWiki, GitHub Copilot
Relevant review context
- The current repository’s
Releaseworkflow is triggered by semantic-version tag pushes (v*.*.*) and manual dispatch. Its release job creates the GitHub Release and attaches platform archives plusSHA256SUMS; the Windows artifact is a.zip. - The current
Publish to WinGetworkflow still usesrelease: publishedand derivesrelease-tagfromgithub.event.release.tag_namewhen not manually dispatched. This confirms the PR is changing the existing release-to-WinGet handoff rather than introducing a new packaging path. - Repository documentation states that WinGet automation uses the Windows
.zip, theWINGET_TOKENsecret, and the existingtonythethompson/winget-pkgsfork. - DeepWiki’s indexed release documentation is stale relative to the checked repository files: it claims WinGet publishing is manual and lists no automated workflow. Review the PR’s actual workflow diff and current GitHub Actions behavior rather than relying on that architectural summary.
- The repository’s release pipeline has explicit CI gating before building and publishing release artifacts, so the new
workflow_runcondition should preserve the intended dependency on a successful tag-basedReleaserun.
🔀 Multi-repo context tonythethompson/QuickShell, Trackdubllc/Trackdub, tonythethompson/dependency-chain-substrate
Linked repositories findings
tonythethompson/QuickShell
- QuickShell documents that releases created with
GITHUB_TOKENdo not trigger downstream workflows, so it explicitly dispatches Store publishing from the release workflow usinggh workflow run. This supports the PR’s rationale for avoiding release-event recursion suppression.[::tonythethompson/QuickShell::].github/workflows/release-extension.yml:205-245,docs/release-packages.md:13-16 - Its release workflow accepts
v*tag pushes and manual dispatch, matching the PR’s tag-based/manual recovery model.[::tonythethompson/QuickShell::].github/workflows/release-extension.yml:3-22 - QuickShell’s WinGet automation runs as a dependent job after a successful build and uses a PAT (
WINGET_PAT) for manifest submission. This is a different secret and submission model from the PR’sWINGET_TOKEN/fork-based flow; no shared contract was found.[::tonythethompson/QuickShell::].github/workflows/release-extension.yml:236-245,:291-320 - QuickShell still uses
actions/checkout@v4in its release workflow, so it provides no evidence that the PR’scheckout@v7.0.1pin is required by a linked consumer.[::tonythethompson/QuickShell::].github/workflows/release-extension.yml:47-50,:248-252
Trackdubllc/Trackdub
- Trackdub uses
actions/checkout@v7andactions/upload-artifact@v7in CI, showing compatible action-major usage in another linked repository, but its references are tags rather than the PR’s commit pins.[::Trackdubllc/Trackdub::].github/workflows/ci.yml:24-25,.github/workflows/code-coverage.yml:95-100 - No WinGet publishing workflow,
workflow_run,wait-on-check-action, orWINGET_TOKENreference was found.
tonythethompson/dependency-chain-substrate
- Its release workflow is independently triggered by
v*tags or manual dispatch and validates that the requested/tagged version matches the project version before publishing. This is consistent with the PR’s tag-oriented release model, but it has no WinGet or downstreamworkflow_runconsumer.[::tonythethompson/dependency-chain-substrate::].github/workflows/release.yml:3-16,:24-43 - No WinGet publishing workflow,
workflow_run, orwait-on-check-actionreference was found.
🔇 Additional comments (7)
.github/workflows/active-plugin-update-acceptance.yml (2)
24-24: 🔒 Security & PrivacySecurity Misconfiguration (CWE-829): Inclusion of Functionality from Untrusted Control Sphere
Reachability: External
The existing mutable Rust-toolchain action finding remains unresolved.
Line 24 still uses the movable
stabletag. Pin the action implementation to a verified full commit SHA, as requested in the prior review.Source: Linters/SAST tools
21-21: LGTM!Also applies to: 27-27, 51-51
.github/workflows/ci.yml (1)
25-25: LGTM!Also applies to: 35-35, 46-46, 56-56, 65-65, 74-74, 84-84
.github/workflows/official-registry-acceptance.yml (1)
17-17: LGTM!Also applies to: 23-23, 48-48
.github/workflows/claude-code-review.yml (1)
19-19: LGTM!Also applies to: 33-33
.github/workflows/claude.yml (1)
29-29: LGTM!.github/workflows/release.yml (1)
55-61: LGTM!Also applies to: 69-69, 71-73, 105-105, 124-124, 156-156, 167-167, 179-179, 208-208
|
Code review by qodo was updated up to the latest commit 048a989 |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/winget.yml:
- Around line 22-23: Update the workflow_run conclusion condition in the WinGet
job to allow execution only when github.event.workflow_run.conclusion is
success; remove the failure alternative while preserving the surrounding event
and permission checks.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 312b00f2-02b7-432d-b60c-ca5f004b9552
📒 Files selected for processing (4)
.github/workflows/ci.yml.github/workflows/winget.ymldocs/PACKAGING.mddocs/RELEASING.md
🔗 Linked repositories identified
CodeRabbit considers these linked repositories for cross-repo context during reviews:
Trackdubllc/Trackdub(manual)tonythethompson/QuickShell(manual)tonythethompson/numan(manual)tonythethompson/dependency-chain-substrate(manual)
📜 Review details
🧰 Additional context used
📓 Path-based instructions (2)
**/*.{rs,md}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when changing structure, conventions, or user-visible behavior, using
AGENTS.md,docs/, or command help as appropriate.
Files:
docs/RELEASING.mddocs/PACKAGING.md
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Redact secrets when reporting relevant logs or lockfile excerpts in issues.
Files:
docs/RELEASING.mddocs/PACKAGING.md
🪛 LanguageTool
docs/RELEASING.md
[style] ~52-~52: Three successive sentences begin with the same word. Consider rewording the sentence or use a thesaurus to find a synonym.
Context: ...CRATES_IO_TOKEN repository secret). 9. Confirm the [Publish to WinGet`](../.github/wo...
(ENGLISH_WORD_REPEAT_BEGINNING_RULE)
[uncategorized] ~52-~52: The official name of this software platform is spelled with a capital “H”.
Context: ...KEN repository secret). 9. Confirm the [Publish to WinGet`](../.github/workflows/winget.yml) workflow verifies...
(GITHUB)
docs/PACKAGING.md
[uncategorized] ~10-~10: The official name of this software platform is spelled with a capital “H”.
Context: ...iggered Release workflow completes, the Publish to WinGet workflow verifies...
(GITHUB)
🔍 Remote MCP Context7, DeepWiki, GitHub Copilot
Additional review context
- GitHub documents
workflow_runas suitable for chaining workflows; the downstream workflow can access secrets and write tokens. This supports the PR’s stated workaround forGITHUB_TOKENevent-recursion suppression. - A
workflow_runjob can gate execution ongithub.event.workflow_run.conclusion, includingsuccessorfailure. - GitHub documents branch filters for
workflow_run, but the retrieved documentation does not establish thathead_branchreliably represents a pushed tag or that branch filters match tag refs. This remains an important point to verify in the actual workflow/event payload. - DeepWiki and GitHub repository lookups failed because
mta1124-1629472/Babel-Playerwas not accessible/indexed, so no additional repository-specific facts were obtained.,
🔀 Multi-repo context tonythethompson/QuickShell, Trackdubllc/Trackdub, tonythethompson/dependency-chain-substrate
Linked repositories findings
tonythethompson/QuickShell
- Release automation explicitly avoids downstream workflow suppression by dispatching publishing from the release workflow; this supports the PR’s
workflow_runrationale.[::tonythethompson/QuickShell::] - Its WinGet flow uses a PAT and dependent release job, not the PR’s
WINGET_TOKEN/fork-based contract. No shared interface was found.[::tonythethompson/QuickShell::]
Trackdubllc/Trackdub
- CI uses
actions/checkout@v7andactions/upload-artifact@v7, providing evidence that these action majors are used in a linked repository. It does not use the PR’s commit pinning scheme.[::Trackdubllc/Trackdub::] - No WinGet,
workflow_run, orWINGET_TOKENreferences were found.[::Trackdubllc/Trackdub::]
tonythethompson/dependency-chain-substrate
- Its release workflow supports
v*tags and manual dispatch, consistent with the PR’s tag/manual recovery model. No WinGet or downstream workflow consumer was found.[::tonythethompson/dependency-chain-substrate::]
🔇 Additional comments (5)
.github/workflows/ci.yml (1)
25-29: Pin the remainingdtolnay/rust-toolchainreferences.The checkout and cache actions are now pinned, but
dtolnay/rust-toolchain@stable/@1.88remain mutable in these jobs. Replace them with full commit SHAs while preserving their existing channels; this is the same unresolved supply-chain issue reported previously.#!/bin/bash set -euo pipefail rg -n 'dtolnay/rust-toolchain@(stable|1\.88)' .github/workflowsAlso applies to: 37-43, 60-64, 71-75, 92-96
Source: Linters/SAST tools
.github/workflows/winget.yml (2)
4-6: LGTM!Also applies to: 31-49
24-29: 🎯 Functional Correctness
head_branchis the tag here, so this gate andRELEASE_TAGfallback are fine.> Likely an incorrect or invalid review comment.docs/PACKAGING.md (1)
10-10: LGTM!docs/RELEASING.md (1)
52-52: LGTM!
|
Code review by qodo was updated up to the latest commit 5c4b408 |
|
Code review by qodo was updated up to the latest commit 4c2724a |
|
Code review by qodo was updated up to the latest commit 836fea3 |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/winget.yml:
- Around line 46-48: Update the WinGet release-gating check in the workflow to
stop matching the release job’s display name. Use a stable release marker or
artifact produced by the release workflow, and ensure the producer/consumer
contract remains enforced so successful releases continue to unblock WinGet even
if the job is renamed.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: ebcc4bff-f3df-4200-9499-2b8e38266130
📒 Files selected for processing (10)
.github/workflows/active-plugin-update-acceptance.yml.github/workflows/ci.yml.github/workflows/cline-pr-review.yml.github/workflows/official-registry-acceptance.yml.github/workflows/release.yml.github/workflows/winget.ymlREADME.mddocs/PACKAGING.mddocs/RELEASING.mddocs/plans/2026-07-29-remaining-roadmap.md
🔗 Linked repositories identified
CodeRabbit considers these linked repositories for cross-repo context during reviews:
Trackdubllc/Trackdub(manual)tonythethompson/QuickShell(manual)tonythethompson/numan(manual)tonythethompson/dependency-chain-substrate(manual)
📜 Review details
⏰ Context from checks skipped due to timeout. (3)
- GitHub Check: Test (windows-latest)
- GitHub Check: Real-Nu acceptance (windows-latest)
- GitHub Check: Analyze (rust)
🧰 Additional context used
📓 Path-based instructions (2)
**/*.{rs,md}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when changing structure, conventions, or user-visible behavior, using
AGENTS.md,docs/, or command help as appropriate.
Files:
docs/plans/2026-07-29-remaining-roadmap.mdREADME.mddocs/PACKAGING.mddocs/RELEASING.md
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Redact secrets when reporting relevant logs or lockfile excerpts in issues.
Files:
docs/plans/2026-07-29-remaining-roadmap.mdREADME.mddocs/PACKAGING.mddocs/RELEASING.md
🪛 LanguageTool
docs/PACKAGING.md
[uncategorized] ~10-~10: The official name of this software platform is spelled with a capital “H”.
Context: ...iggered Release workflow completes, the Publish to WinGet workflow verifies...
(GITHUB)
docs/RELEASING.md
[style] ~52-~52: Three successive sentences begin with the same word. Consider rewording the sentence or use a thesaurus to find a synonym.
Context: ...CRATES_IO_TOKEN repository secret). 9. Confirm the [Publish to WinGet`](../.github/wo...
(ENGLISH_WORD_REPEAT_BEGINNING_RULE)
[uncategorized] ~52-~52: The official name of this software platform is spelled with a capital “H”.
Context: ...KEN repository secret). 9. Confirm the [Publish to WinGet`](../.github/workflows/winget.yml) workflow verifies...
(GITHUB)
🪛 zizmor (1.28.0)
.github/workflows/active-plugin-update-acceptance.yml
[info] 24-24: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
.github/workflows/winget.yml
[warning] 15-15: permissions without explanatory comments (undocumented-permissions): needs an explanatory comment
(undocumented-permissions)
.github/workflows/official-registry-acceptance.yml
[info] 20-20: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
.github/workflows/ci.yml
[info] 26-26: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[info] 40-40: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[info] 54-54: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[info] 65-65: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[info] 78-78: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[info] 101-101: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
.github/workflows/release.yml
[info] 70-70: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[info] 121-121: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
[info] 211-211: action functionality is already included by the runner (superfluous-actions): use rustup and/or cargo in a script step
(superfluous-actions)
🔍 Remote MCP DeepWiki, GitHub Copilot
Relevant review context
- PR
#61changes WinGet automation to trigger from completedReleaseworkflow runs and gates automatic execution on a push, same repository,v*branch, and workflow conclusionsuccessorfailure. It then verifies thePublish GitHub Releasejob and the expected non-draft Windows ZIP asset before submission. - The current PR checks show Rust tests, Clippy, MSRV, formatting, packaging, and macOS acceptance passing; Windows and some CodeQL/Rust analysis checks were still in progress when retrieved.
- A review identified remaining brittleness:
winget.ymlmatches the mutable display name"Publish GitHub Release"rather than a stable job identifier. Renaming that job would block automation. - DeepWiki’s repository information appears stale: it describes WinGet publishing as manual and says no
winget.ymlexists, conflicting with the current PR diff. It should not be relied on for validating this workflow change. - The PR’s related context confirms the Release workflow creates the GitHub Release before the independent
publish-cratejob; therefore allowing a completed workflow with conclusionfailureis intentional, provided the release-job and asset checks pass.
🔀 Multi-repo context tonythethompson/QuickShell, Trackdubllc/Trackdub, tonythethompson/dependency-chain-substrate
Linked repositories findings
tonythethompson/QuickShell
- Release automation explicitly avoids downstream workflow suppression by dispatching publishing from the release workflow; this supports the PR’s
workflow_runrationale.[::tonythethompson/QuickShell::] - Its WinGet flow uses a PAT and dependent release job, not the PR’s
WINGET_TOKEN/fork-based contract. No shared interface was found.[::tonythethompson/QuickShell::]
Trackdubllc/Trackdub
- CI uses
actions/checkout@v7andactions/upload-artifact@v7, providing evidence that these action majors are used in a linked repository. It does not use the PR’s commit pinning scheme.[::Trackdubllc/Trackdub::] - No WinGet,
workflow_run, orWINGET_TOKENreferences were found.[::Trackdubllc/Trackdub::]
tonythethompson/dependency-chain-substrate
- Its release workflow supports
v*tags and manual dispatch, consistent with the PR’s tag/manual recovery model. No WinGet or downstream workflow consumer was found.[::tonythethompson/dependency-chain-substrate::]
🔇 Additional comments (10)
README.md (1)
412-415: LGTM!docs/plans/2026-07-29-remaining-roadmap.md (1)
1-134: LGTM!.github/workflows/active-plugin-update-acceptance.yml (1)
24-29: LGTM!Also applies to: 53-53
.github/workflows/ci.yml (1)
25-59: LGTM!Also applies to: 60-85, 86-92, 100-106
.github/workflows/official-registry-acceptance.yml (1)
17-25: LGTM!Also applies to: 50-50
.github/workflows/cline-pr-review.yml (1)
31-36: LGTM!.github/workflows/release.yml (1)
55-58: LGTM!Also applies to: 69-74, 106-126, 158-158, 169-169, 181-181, 210-213
.github/workflows/winget.yml (1)
4-6: LGTM!Also applies to: 15-15, 21-30, 32-45, 50-69
docs/PACKAGING.md (1)
10-10: LGTM!docs/RELEASING.md (1)
52-52: LGTM!
Stop matching the mutable Publish GitHub Release job display name. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Code review by qodo was updated up to the latest commit 117c9c2 |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/release.yml:
- Around line 204-208: Update the WinGet marker, tag resolver, and changelog
steps to pass steps.meta.outputs.tag through an environment variable or
equivalent shell-safe handoff, then reference that variable inside each run
script instead of interpolating the workflow expression directly. Preserve the
existing tag and artifact behavior while preventing crafted dispatch input from
being interpreted as shell syntax.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 91573732-8cd4-4298-8685-45bb6bc84928
📒 Files selected for processing (5)
.github/workflows/release.yml.github/workflows/winget.ymlREADME.mddocs/PACKAGING.mddocs/RELEASING.md
🔗 Linked repositories identified
CodeRabbit considers these linked repositories for cross-repo context during reviews:
Trackdubllc/Trackdub(manual)tonythethompson/QuickShell(manual)tonythethompson/numan(manual)tonythethompson/dependency-chain-substrate(manual)
📜 Review details
⏰ Context from checks skipped due to timeout. (4)
- GitHub Check: Analyze (rust)
- GitHub Check: Test (macos-latest)
- GitHub Check: Real-Nu acceptance (windows-latest)
- GitHub Check: Test (windows-latest)
🧰 Additional context used
📓 Path-based instructions (2)
**/*.{rs,md}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Update documentation when changing structure, conventions, or user-visible behavior, using
AGENTS.md,docs/, or command help as appropriate.
Files:
README.mddocs/PACKAGING.mddocs/RELEASING.md
**/*
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Redact secrets when reporting relevant logs or lockfile excerpts in issues.
Files:
README.mddocs/PACKAGING.mddocs/RELEASING.md
🪛 LanguageTool
docs/PACKAGING.md
[uncategorized] ~10-~10: The official name of this software platform is spelled with a capital “H”.
Context: ...iggered Release workflow completes, the Publish to WinGet workflow verifies...
(GITHUB)
docs/RELEASING.md
[style] ~52-~52: Three successive sentences begin with the same word. Consider rewording the sentence or use a thesaurus to find a synonym.
Context: ...CRATES_IO_TOKEN repository secret). 9. Confirm the [Publish to WinGet`](../.github/wo...
(ENGLISH_WORD_REPEAT_BEGINNING_RULE)
[uncategorized] ~52-~52: The official name of this software platform is spelled with a capital “H”.
Context: ...KEN repository secret). 9. Confirm the [Publish to WinGet`](../.github/workflows/winget.yml) workflow verifies...
(GITHUB)
🪛 zizmor (1.28.0)
.github/workflows/release.yml
[info] 208-208: code injection via template expansion (template-injection): may expand into attacker-controllable code
(template-injection)
🔀 Multi-repo context tonythethompson/QuickShell, Trackdubllc/Trackdub, tonythethompson/dependency-chain-substrate
Linked repositories findings
tonythethompson/QuickShell
- Release automation explicitly avoids downstream workflow suppression by dispatching publishing from the release workflow; this supports the PR’s
workflow_runrationale.[::tonythethompson/QuickShell::] - Its WinGet flow uses a PAT and dependent release job, not the PR’s
WINGET_TOKEN/fork-based contract. No shared interface was found.[::tonythethompson/QuickShell::]
Trackdubllc/Trackdub
- CI uses
actions/checkout@v7andactions/upload-artifact@v7, providing evidence that these action majors are used in a linked repository. It does not use the PR’s commit pinning scheme.[::Trackdubllc/Trackdub::] - No WinGet,
workflow_run, orWINGET_TOKENreferences were found.[::Trackdubllc/Trackdub::]
tonythethompson/dependency-chain-substrate
- Its release workflow supports
v*tags and manual dispatch, consistent with the PR’s tag/manual recovery model. No WinGet or downstream workflow consumer was found.[::tonythethompson/dependency-chain-substrate::]
🔇 Additional comments (5)
README.md (1)
412-414: LGTM!.github/workflows/release.yml (1)
55-58: LGTM!Also applies to: 69-74, 106-106, 121-126, 158-158, 169-169, 181-181
.github/workflows/winget.yml (1)
4-6: LGTM!Also applies to: 15-40, 41-49, 50-62, 64-70
docs/PACKAGING.md (1)
10-10: LGTM!docs/RELEASING.md (1)
52-52: LGTM!
Make dispatch tag selection event-explicit and reject malformed tags. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Code review by qodo was updated up to the latest commit 62b295a |
Fold plugins, registry, and client remaining plans into one ordered critical path, and point the prior draft at the new authority. Co-authored-by: Cursor <cursoragent@cursor.com>
Keep the consolidated roadmap prior-draft link because that file still exists on this branch. Co-authored-by: Cursor <cursoragent@cursor.com>
Pass dispatch/release tags through env vars instead of expanding them into run scripts, and tighten WinGet tag validation to real SemVer. Co-authored-by: Cursor <cursoragent@cursor.com>
Code Review by QodoSorry, something went wrongWe weren't able to complete the code review on our side. Please try again manually by commenting/agentic_review on this PR.
Powered by Qodo |
Summary
Releaseworkflow completion, avoiding GitHub'sGITHUB_TOKENevent-recursion suppressionrepoinput fromwait-on-check-actionEvidence
The v0.1.5 Release run reported:
event=pushhead_branch=v0.1.5head_repository=tonythethompson/numanconclusion=successThose fields satisfy the new gate. The prior
release.publishedtrigger did not run because the GitHub Release was created withGITHUB_TOKEN; manual dispatch was required for v0.1.5.Validation
actionlint1.7.12: passed for all workflowscargo fmt --all -- --check: passedcargo test --locked: passed (407 unit tests plus integration suites; ignored real-Nu/live tests unchanged)git diff --check: passed