chore(ai-review): the gateway review route moved #60

Merged
A-Guevara merged 1 commit from chore/ai-review-20260923 into main 2026-09-23 17:34:06 +00:00
Owner

The AI review gateway renamed its routes (nis/forgejo-stack ADR-0002) and kept no aliases, so the workflow this repo carries now gets a 404 and posts a could-not-review comment. This re-seeds the canonical ai/ai-review.yml, which calls the new route. Merge it to get AI review back on this repository. Advisory only, never a merge gate.

The AI review gateway renamed its routes (nis/forgejo-stack ADR-0002) and kept no aliases, so the workflow this repo carries now gets a 404 and posts a could-not-review comment. This re-seeds the canonical ai/ai-review.yml, which calls the new route. Merge it to get AI review back on this repository. Advisory only, never a merge gate.
chore(ai-review): the gateway review route moved (ADR-0002)
Some checks failed
scan / trivy-fs (push) Failing after 1m27s
baseline-security / baseline (push) Failing after 1m51s
scan / trivy-fs (pull_request) Failing after 1m22s
ai-review / review (pull_request) Successful in 1m36s
baseline-security / baseline (pull_request) Failing after 2m1s
3191b26afb

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
CVE-2026-63671 (HIGH) @nuxtjs/mdc 0.21.1 → 0.22.1 merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f
GHSA-j95f-988m-3j2f (HIGH) @tiptap/core 3.28.0 → 3.30.5 no fix PR yet — npm update core --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:3191b26afbc376cca547457415c689b1ed96ca86 --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | CVE-2026-63671 (HIGH) | `@nuxtjs/mdc` | 0.21.1 → 0.22.1 | merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f | | GHSA-j95f-988m-3j2f (HIGH) | `@tiptap/core` | 3.28.0 → 3.30.5 | no fix PR yet — `npm update core --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
ai-review-bot left a comment

AI review · advisory

Verdict: nothing confirmed — 1 single-reviewer observation in the debate digest below.

⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 0 confirmed, 1 below threshold, 2 refuted · web: not used · context: 1 files under review · 90 codebase · 6 standards chunks

Panel debate — how this review was reached

Grounding — context: 1 files under review · 90 codebase · 6 standards chunks

Round 1 — independent reviews

  • GPT-OSS 120B (0 findings, confidence 0.97 · thought 582 + wrote 60 of 16.0k tokens · 10 s): No issues detected in the changed lines; the route adjustment aligns with the updated API contract and maintains existing safeguards.
  • Gemma 4 31B (0 findings, confidence 1.0 · thought 1.9k + wrote 320 of 16.0k tokens · 58 s): The changes correctly migrate the AI review gateway route from a generic endpoint to a RESTful, Forgejo-shaped path as described in the PR title and comments, while maintaining consistency with the co
  • Devstral 2 123B (3 findings, confidence 0.85 · wrote 690 of 16.0k tokens · 35 s): The PR updates the AI review endpoint and request body structure, but lacks validation for the new endpoint's expected fields and hardcodes paths that may break if the gateway API changes.
  • Laguna S 2.1 (0 findings, confidence 0.95 · thought 10.1k + wrote 209 of 65.5k tokens · 254 s over 2 attempts): The diff correctly moves the BFF call to the Forgejo-shaped route POST /v1/repos/{o}/{r}/pulls/{n}/reviews: the header comment is updated, the now-redundant repo/pr body fields are dropped (they live

Round 2 — cross-examination

  • Devstral 2 123B#1 Removed fields from request body without validation · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 · support 0
  • Devstral 2 123B#2 Hardcoded endpoint path may break if gateway API changes · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 · support 0
  • Devstral 2 123B#3 Hardcoded transcript URL path may break if gateway API changes · confirmed: GPT-OSS 120B · refuted: Gemma 4 31B, Laguna S 2.1 · support 1

Not posted (support < 2, or contested at a severity where one refutation vetoes)

  • Devstral 2 123B#3 Hardcoded transcript URL path may break if gateway API changes (support 1)

Raised but refuted (left out of the review above)

  • Devstral 2 123B#1 Removed fields from request body without validation — The diff only shows that the repo and pr fields were removed from the request body. There is no evidence in the code or documentation that the new
  • Devstral 2 123B#2 Hardcoded endpoint path may break if gateway API changes — While the endpoint URL is indeed hard‑coded, the script already captures HTTP errors and reports the status code and details (`attempt X failed: HTTP

Synthesis — Laguna S 2.1 wrote the final review from 0 confirmed findings (+1 below threshold) · promotion: support ≥ 2, and no refutation at high severity.

Transcript rv-20260923172140-3c78c2 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript rv-20260923172140-3c78c2.

### AI review · advisory <!-- tti-rv:rv-20260923172140-3c78c2: --> **Verdict: nothing confirmed** — 1 single-reviewer observation in the debate digest below. <sub>⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 0 confirmed, 1 below threshold, 2 refuted · web: not used · context: 1 files under review · 90 codebase · 6 standards chunks</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files under review · 90 codebase · 6 standards chunks **Round 1 — independent reviews** - **GPT-OSS 120B** (0 findings, confidence 0.97 · thought 582 + wrote 60 of 16.0k tokens · 10 s): No issues detected in the changed lines; the route adjustment aligns with the updated API contract and maintains existing safeguards. - **Gemma 4 31B** (0 findings, confidence 1.0 · thought 1.9k + wrote 320 of 16.0k tokens · 58 s): The changes correctly migrate the AI review gateway route from a generic endpoint to a RESTful, Forgejo-shaped path as described in the PR title and comments, while maintaining consistency with the co - **Devstral 2 123B** (3 findings, confidence 0.85 · wrote 690 of 16.0k tokens · 35 s): The PR updates the AI review endpoint and request body structure, but lacks validation for the new endpoint's expected fields and hardcodes paths that may break if the gateway API changes. - **Laguna S 2.1** (0 findings, confidence 0.95 · thought 10.1k + wrote 209 of 65.5k tokens · 254 s over 2 attempts): The diff correctly moves the BFF call to the Forgejo-shaped route POST /v1/repos/{o}/{r}/pulls/{n}/reviews: the header comment is updated, the now-redundant repo/pr body fields are dropped (they live **Round 2 — cross-examination** - `Devstral 2 123B#1` Removed fields from request body without validation · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 · support 0 - `Devstral 2 123B#2` Hardcoded endpoint path may break if gateway API changes · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 · support 0 - `Devstral 2 123B#3` Hardcoded transcript URL path may break if gateway API changes · confirmed: GPT-OSS 120B · refuted: Gemma 4 31B, Laguna S 2.1 · support 1 **Not posted** (support < 2, or contested at a severity where one refutation vetoes) - `Devstral 2 123B#3` Hardcoded transcript URL path may break if gateway API changes (support 1) **Raised but refuted** (left out of the review above) - `Devstral 2 123B#1` Removed fields from request body without validation — The diff only shows that the `repo` and `pr` fields were removed from the request body. There is no evidence in the code or documentation that the new - `Devstral 2 123B#2` Hardcoded endpoint path may break if gateway API changes — While the endpoint URL is indeed hard‑coded, the script already captures HTTP errors and reports the status code and details (`attempt X failed: HTTP **Synthesis** — Laguna S 2.1 wrote the final review from 0 confirmed findings (+1 below threshold) · promotion: support ≥ 2, and no refutation at high severity. <sub>Transcript `rv-20260923172140-3c78c2` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript `rv-20260923172140-3c78c2`.</sub>
A-Guevara deleted branch chore/ai-review-20260923 2026-09-23 17:34:07 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!60
No description provided.