FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

CI: bound dependency comments and retain complete reports by youknowdot · Pull Request #8958 · RustPython/RustPython · GitHub

Repository navigation

CI: bound dependency comments and retain complete reports - #8958

Draft
youknowdot wants to merge 1 commit into
RustPython:mainfrom
youknowdot:fix-lib-deps-comment-size
Draft

youknowdot wants to merge 1 commit into
RustPython:mainfrom
youknowdot:fix-lib-deps-comment-size

Conversation

Copy link
Copy Markdown
Contributor

Large standard-library updates generate a dependency report that is too large for the comment action's environment input. On #8954, the 157,859-byte report prevents Node from starting with Argument list too long.

Write the report to a temporary file and pass its path to the existing pinned comment action. Short reports remain in the comment; longer reports link to the complete run summary. Reports above the summary's 1 MiB limit use an artifact with the repository's existing pinned upload action.

This is independent of the Python 3.15 migration and applies directly to current 3.14 main. The trigger, token permissions, checkout/trust boundary, existing action versions and no-Lib-change removal behavior are retained. Because this is a pull_request_target workflow, the correction must reach trusted main before the mega PR can use it.

Validation:

  • Exact inline workflow code passes empty, small, 160 KB Unicode, recorded-failure and comment/summary boundary fixtures
  • Report-capture shell preserves tolerated command failures and treats report text as data
  • YAML parsing, patch checks and normal configured commit hooks pass
  • Zizmor 1.30.1 reports the same inherited high-severity dangerous-triggers finding on unchanged main and this change, with no new findings. This is not a clean local scan; no suppression or trigger/permission change was added
  • No live comment/artifact posting or new workflow execution has been claimed

The existing failed run supplies the current failure evidence. Main CI approval is a separate issue.

AI assistance: prepared and validated with Codex at the user's direction. Exact model metadata is unavailable; the commit records Assisted-by: Codex:model-version-unavailable.

Send the dependency report through a file instead of the comment action's
large environment input. Keep short reports in the comment and retain
complete longer reports in the job summary, with an artifact fallback
above the summary size limit.

Preserve the existing trigger, permissions, action pins and trust boundary.
Fixtures cover the recorded E2BIG report, UTF-8 size limits, empty reports
and the summary/artifact boundary. Zizmor reports the same inherited
pull_request_target finding on main and this change, with no new finding.

Assisted-by: Codex:model-version-unavailable

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant


Back | FazBrowse Home | New Git URL