Skip to content
Merged
Show file tree
Hide file tree
Changes from 49 commits
Commits
Show all changes
80 commits
Select commit Hold shift + click to select a range
dc6ee9f
fix: close compact wordmark delivery tail
safal207 Jul 5, 2026
7c9b80d
test: bind reviewed compact wordmark visuals
safal207 Jul 5, 2026
58486ed
ci: apply wordmark review fixes once
safal207 Jul 5, 2026
6893392
chore: remove inactive temporary workflow
safal207 Jul 5, 2026
44dec66
fix: make wordmark stylesheet injection idempotent
safal207 Jul 5, 2026
d1be792
refactor: consume shared wordmark layout tokens
safal207 Jul 5, 2026
90cdf63
fix: precache exact wordmark stylesheet revision
safal207 Jul 5, 2026
a5aaf94
fix: restore approved wordmark sizing
safal207 Jul 5, 2026
7a62adc
test: assert wordmark stylesheet behavior
safal207 Jul 5, 2026
d9e2777
ci: regenerate wordmark integrity once
safal207 Jul 5, 2026
f4fe2fe
ci: run wordmark integrity regeneration on PR
safal207 Jul 5, 2026
8b536a4
ci: capture focused wordmark contract result
safal207 Jul 5, 2026
e028de1
test: match standalone CSS rules exactly
safal207 Jul 5, 2026
96758b3
ci: generate verified wordmark integrity artifact
safal207 Jul 5, 2026
780fc7e
ci: retain wordmark contract diagnostics
safal207 Jul 5, 2026
2a37d3b
test: parse exact CSS selector rules
safal207 Jul 5, 2026
9b1dcaf
ci: rerun wordmark integrity artifact generation
safal207 Jul 5, 2026
e23d182
chore: regenerate wordmark integrity manifest
safal207 Jul 5, 2026
2861def
chore: remove one-time wordmark integrity workflow
safal207 Jul 5, 2026
7e8bff1
ci: diagnose exact wordmark build once
safal207 Jul 5, 2026
254e6d0
chore: remove one-time wordmark build diagnostic
safal207 Jul 5, 2026
f5c4420
fix: restore revisioned service-worker cache marker
safal207 Jul 5, 2026
a390a37
ci: regenerate corrected wordmark manifest once
safal207 Jul 5, 2026
581c2d0
chore: regenerate integrity after cache marker fix
safal207 Jul 5, 2026
4724de4
chore: remove one-time manifest workflow
safal207 Jul 5, 2026
0d393f6
test: protect offline wordmark cache revisioning
safal207 Jul 5, 2026
70bebcf
test: decouple poster cache gate from release label
safal207 Jul 5, 2026
263ab1a
qa: bind visual evidence to current guard
safal207 Jul 5, 2026
223673f
ci: capture poster gate result once
safal207 Jul 5, 2026
d1f53a4
test: restore escaped poster source assertion
safal207 Jul 5, 2026
6a4222d
chore: remove one-time poster diagnostic
safal207 Jul 5, 2026
f2ca546
ci: recapture poster gate result
safal207 Jul 5, 2026
20d2b97
test: decouple PR140 cache gate from release label
safal207 Jul 5, 2026
d03d3f1
chore: remove poster diagnostic workflow
safal207 Jul 5, 2026
00d7c68
test: require exact standalone wordmark CSS rules
safal207 Jul 5, 2026
d092a6e
ci: accept durable exact-head AI evidence surfaces
safal207 Jul 5, 2026
efa0a16
ci: model AI review provenance honestly
safal207 Jul 5, 2026
f529969
ci: require native exact-head AI identities
safal207 Jul 5, 2026
f74a887
ci: require exact-head CodeRabbit review objects
safal207 Jul 5, 2026
6f96c58
ci: model available AI reviewer capabilities
safal207 Jul 5, 2026
22da4ba
docs: require exact-head AI review requests
safal207 Jul 5, 2026
4ac0c85
docs: align AI cooperation policy with reviewer capabilities
safal207 Jul 5, 2026
f791edd
ci: bind AI request freshness to PR update run
safal207 Jul 5, 2026
1a8fa64
ci: document AI review actions permission
safal207 Jul 5, 2026
99a2d92
ci: trim AI review permissions
safal207 Jul 5, 2026
3758d4f
ci: accept exact-head CodeRabbit clean summaries
safal207 Jul 5, 2026
aff736a
fix: align wordmark with production brand reference
github-actions[bot] Jul 5, 2026
f512013
fix: add exact-head AI review verifier
safal207 Jul 5, 2026
b39d405
fix: run exact-head AI review verifier
safal207 Jul 5, 2026
4ae00a4
fix: verify native exact-head review without checkout
safal207 Jul 5, 2026
dab408e
fix: load Discover wordmark CSS before offline runtime
safal207 Jul 5, 2026
4c21687
chore: refresh integrity after Discover delivery fix
safal207 Jul 5, 2026
842e215
chore: attach canonical CI integrity manifest
safal207 Jul 6, 2026
95ba509
test: update visual binding
safal207 Jul 6, 2026
391b90e
fix: align wordmark with production brand reference
github-actions[bot] Jul 6, 2026
cfb48b9
fix: require active exact-head review evidence
safal207 Jul 6, 2026
dc3996d
fix: finalize active exact-head review gate
safal207 Jul 6, 2026
561c368
fix: retry transient review API failures
safal207 Jul 6, 2026
77d1667
fix: prevent 320px menu header overflow
safal207 Jul 6, 2026
86be346
test: bind 320px menu overflow fix
safal207 Jul 6, 2026
cc4bff5
fix: close 412px menu header breakpoint gap
safal207 Jul 6, 2026
8a2fa02
test: bind 412px menu overflow fix
safal207 Jul 6, 2026
5993c24
chore: attach canonical final wordmark manifest
safal207 Jul 6, 2026
2a47c1f
chore: preserve canonical manifest newline
safal207 Jul 6, 2026
366d030
fix: bind review evidence to fresh exact-head request
safal207 Jul 6, 2026
eebb512
fix: require submitted exact-head review evidence
safal207 Jul 6, 2026
ed2d879
fix: support native exact-head CodeRabbit status evidence
safal207 Jul 6, 2026
48d43e7
fix: run capability-aware exact-head verifier
safal207 Jul 6, 2026
fb6724e
fix: bind CodeRabbit status to fresh request
safal207 Jul 6, 2026
4851d4d
fix: checkout exact pull-request head
safal207 Jul 6, 2026
28ddd0f
fix: match CodeRabbit status context
safal207 Jul 6, 2026
ab77d19
test: inspect delegated AI review verifier
safal207 Jul 6, 2026
41fe7fe
test: inspect delegated AI review contract
safal207 Jul 6, 2026
9ae0f7f
fix: use observed CodeRabbit status context
safal207 Jul 6, 2026
6b9aa79
fix: bind automatic status to head update
safal207 Jul 6, 2026
dceea1f
ci: align verifier with trusted main
safal207 Jul 6, 2026
1acd301
ci: execute verifier from immutable base
safal207 Jul 6, 2026
d9ed128
ci: pin trusted verifier bootstrap
safal207 Jul 6, 2026
e0d18de
ci: align verifier with trusted timestamp patch
safal207 Jul 6, 2026
ed9b736
ci: pin trusted timestamp verifier
safal207 Jul 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 34 additions & 21 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,45 +8,58 @@ Link screenshots, logs, artifacts, or reproducible checks.

## AI review

After the latest PR open or head update, add two separate top-level comments:
After every PR head update, freeze the branch and post a fresh top-level request for the mandatory independent reviewer. The request must include the full 40-character current head SHA:

`@codex review`
```text
@coderabbitai review

`@jules review`
Exact head: <full 40-character current head SHA>
```

The AI review contract requires official Codex evidence tied to the current head:
either a matching `Reviewed commit` value or the Codex bot's thumbs-up reaction on
the fresh post-head request. AI review remains complementary to required CI and
human approval.
CodeRabbit evidence is valid only when the configured bot publishes a pull-request review object whose `commit_id` equals that exact head. A reaction, progress/status comment, maintainer-authored review, proxy marker, or response for an older SHA does not satisfy the gate.

For an optional independent Chinese-model review after the latest head update, add:
The Codex lane is supplemental on connector surfaces where no native Codex bot review object is available. It may be requested with the same exact-head format:

`/deepseek review`
```text
@codex review

Use `/deepseek deep-review` only when a slower reasoning-oriented pass is useful.
DeepSeek evidence is advisory and must show the current reviewed commit SHA.
Exact head: <full 40-character current head SHA>
```

Codex counts as independent evidence only when the configured Codex bot itself publishes a review object bound to the exact head. Output written through the repository owner identity remains advisory and cannot satisfy an independent-review gate.

A new commit invalidates every earlier request and review result. Post fresh requests with the new full SHA.

Optional advisory reviewers may also be requested after the latest head update:

```text
@jules review
/deepseek review
```

Use `/deepseek deep-review` only when a slower reasoning-oriented pass is useful. Advisory evidence must identify the current reviewed commit SHA before it can be treated as exact-head evidence.

## Solo maintainer decision

When no independent human reviewer is available, finish all checks and review
findings, then post a top-level comment with the full current head SHA:
When no independent human reviewer is available, finish all required checks and bot-review dispositions, then post a top-level comment with the full current head SHA:

`/merge-ready <full 40-character current head SHA>`

To revoke the decision, post:

`/merge-hold <full 40-character current head SHA>`

This is explicit maintainer intent, not independent human approval.
This is explicit maintainer intent, not independent human or bot approval.

## Checklist

- [ ] Latest CI is green.
- [ ] Latest exact-head CI is green.
- [ ] Generated files are current.
- [ ] Visual changes include evidence.
- [ ] Official Codex evidence is verified for the current head.
- [ ] Jules review was requested after the latest head update.
- [ ] Optional DeepSeek findings are resolved or documented when requested.
- [ ] Visual changes include exact-head evidence.
- [ ] A fresh CodeRabbit request contains the full current head SHA.
- [ ] A CodeRabbit-authored PR review object is bound to that exact head.
- [ ] Codex is recorded as supplemental unless a native exact-head bot review exists.
- [ ] Optional reviewer findings are resolved or explicitly dispositioned when requested.
- [ ] Required independent human approval exists for the exact current head when enforcement is enabled.
- [ ] Solo maintainer attestation is green for the exact current head when no independent reviewer is available.
- [ ] Actionable findings are resolved or documented.
- [ ] Solo maintainer attestation is green for the exact current head when no independent human reviewer is available.
- [ ] Every actionable finding is resolved or documented on the current head.
136 changes: 9 additions & 127 deletions .github/workflows/ai-review-contract.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,141 +5,23 @@ on:
types: [opened, synchronize]

permissions:
contents: read
# actions: read is required for the immutable workflow-run freshness anchor.
actions: read
# issues: read is required for the exact-head review request comment.
issues: read
# pull-requests: read is required for native PR review evidence.
pull-requests: read
Comment thread
qodo-code-review[bot] marked this conversation as resolved.
Outdated

jobs:
verify:
runs-on: ubuntu-latest
timeout-minutes: 12
steps:
- name: Wait for current-head AI review evidence
- name: Check out exact head verifier
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated
- name: Wait for native exact-head CodeRabbit review
uses: actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7.1.0
with:
script: |
const owner = context.repo.owner;
const repo = context.repo.repo;
const pr = context.payload.pull_request;
const trusted = new Set(['OWNER', 'MEMBER', 'COLLABORATOR']);
const codexLogins = new Set([
'chatgpt-codex-connector[bot]',
'chatgpt-codex-connector',
]);
const codeRabbitLogins = new Set([
'coderabbitai[bot]',
'coderabbitai',
]);
const sleep = (ms) => new Promise((resolve) => setTimeout(resolve, ms));

const evidenceAfter = Date.parse(pr.updated_at);
const currentHead = pr.head.sha.toLowerCase();
const timeOf = (item) => Math.max(
0,
...[item.submitted_at, item.created_at, item.updated_at]
.map((value) => Date.parse(value ?? 0))
.filter(Number.isFinite),
);
const bodyOf = (item) => (item.body ?? '').trim();
const commandLinesOf = (item) => bodyOf(item)
.toLowerCase()
.split(/\r?\n/)
.map((line) => line.trim())
.filter(Boolean);
const isCommand = (item, value) => (
trusted.has(item.author_association) &&
timeOf(item) >= evidenceAfter &&
commandLinesOf(item).includes(value)
);
const latestRequestAt = (requests) => requests.reduce(
(latest, request) => Math.max(latest, timeOf(request)),
0,
);
const nativeReviewMatchesHead = (review) => (
review.commit_id?.toLowerCase() === currentHead
);

for (let attempt = 1; attempt <= 30; attempt += 1) {
const [comments, reviews] = await Promise.all([
github.paginate(
github.rest.issues.listComments,
{ owner, repo, issue_number: pr.number, per_page: 100 },
),
github.paginate(
github.rest.pulls.listReviews,
{ owner, repo, pull_number: pr.number, per_page: 100 },
),
]);

const codexRequests = comments.filter((item) => isCommand(item, '@codex review'));
const codeRabbitRequests = comments.filter((item) => isCommand(item, '@coderabbitai review'));
const latestCodexRequestAt = latestRequestAt(codexRequests);
const latestCodeRabbitRequestAt = latestRequestAt(codeRabbitRequests);

const codexReview = reviews.find((review) => (
codexLogins.has(review.user?.login) &&
nativeReviewMatchesHead(review) &&
timeOf(review) >= latestCodexRequestAt
));
const currentHeadCodeRabbitReview = reviews.find((review) => (
codeRabbitLogins.has(review.user?.login) &&
nativeReviewMatchesHead(review)
));
const codeRabbitReview = reviews.find((review) => (
codeRabbitLogins.has(review.user?.login) &&
nativeReviewMatchesHead(review) &&
timeOf(review) >= latestCodeRabbitRequestAt
));
const codeRabbitStatusComment = comments.find((item) => {
const body = bodyOf(item);
const statusTime = timeOf(item);
return (
Boolean(currentHeadCodeRabbitReview) &&
latestCodeRabbitRequestAt > 0 &&
codeRabbitLogins.has(item.user?.login) &&
statusTime >= latestCodeRabbitRequestAt &&
body.includes('<!-- This is an auto-generated comment: summarize by coderabbit.ai -->') &&
body.includes('No new commits to review since the last review.')
);
});

const hasCodexRequest = latestCodexRequestAt > 0;
const hasCodeRabbitRequest = latestCodeRabbitRequestAt > 0;
const hasCodexEvidence = Boolean(codexReview);
const hasCodeRabbitEvidence = Boolean(codeRabbitReview || codeRabbitStatusComment);

if (
hasCodexRequest &&
hasCodeRabbitRequest &&
hasCodexEvidence &&
hasCodeRabbitEvidence
) {
await core.summary
.addHeading('AI review contract')
.addTable([
[
{ data: 'Reviewer', header: true },
{ data: 'Fresh request', header: true },
{ data: 'Exact-head evidence after request', header: true },
],
['Codex', 'yes', 'yes'],
['CodeRabbit', 'yes', 'yes'],
])
.write();
core.notice(
`Exact-head AI evidence verified for ${pr.head.sha}: Codex and CodeRabbit complete after their latest requests.`,
);
return;
}

core.info(
`Waiting for latest-request exact-head AI evidence (attempt ${attempt}/30): ` +
`Codex=${hasCodexRequest}/${hasCodexEvidence}, ` +
`CodeRabbit=${hasCodeRabbitRequest}/${hasCodeRabbitEvidence}`,
);
if (attempt < 30) await sleep(20_000);
}

core.setFailed(
'Post fresh @codex review and @coderabbitai review commands after the latest head update, then require exact-head evidence newer than each latest request.',
);
const verify = require('./scripts/verify-ai-review-contract.cjs');
await verify({ github, context, core });
Comment thread
coderabbitai[bot] marked this conversation as resolved.
10 changes: 10 additions & 0 deletions discover-weather-guard.js
Original file line number Diff line number Diff line change
@@ -1,2 +1,12 @@
// Compatibility placeholder: the Discover interaction guard is bundled into
// discover-journeys-v2.js, which is already part of the service-worker precache.
const WORDMARK_STYLESHEET_ID = "robys-wordmark-responsive";
const WORDMARK_STYLESHEET_HREF = "wordmark-responsive.css?v=20260704-1";
Comment thread
safal207 marked this conversation as resolved.

if (!document.getElementById(WORDMARK_STYLESHEET_ID)) {
const wordmarkStylesheet = document.createElement("link");
wordmarkStylesheet.id = WORDMARK_STYLESHEET_ID;
wordmarkStylesheet.rel = "stylesheet";
wordmarkStylesheet.href = WORDMARK_STYLESHEET_HREF;
document.head.appendChild(wordmarkStylesheet);
Comment thread
qodo-code-review[bot] marked this conversation as resolved.
}
Loading
Loading