chore(ai-review): the gateway review route moved #60
No reviewers
Labels
No labels
idea
points
1
points
13
points
2
points
3
points
5
points
8
priority
p0
priority
p1
priority
p2
priority
p3
state
blocked
state
done
state
in-progress
state
ready
state
review
state
triage
status
declined
status
in-progress
status
planned
status
proposed
status
shipped
status
under-review
type
bug
type
epic
type
feature
type
spike
type
story
type
task
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
tti/tti-ux!60
Loading…
Reference in a new issue
No description provided.
Delete branch "chore/ai-review-20260923"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The AI review gateway renamed its routes (nis/forgejo-stack ADR-0002) and kept no aliases, so the workflow this repo carries now gets a 404 and posts a could-not-review comment. This re-seeds the canonical ai/ai-review.yml, which calls the new route. Merge it to get AI review back on this repository. Advisory only, never a merge gate.
🔧 Security-gate fix map
The gate failed on these dependency findings — fastest path to green for each:
@nuxtjs/mdc@tiptap/corenpm update core --package-lock-onlyjs-yamlnpm update js-yaml --package-lock-onlysharpnpm update sharp --package-lock-onlysvgonpm update svgo --package-lock-onlyPosted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.
AI review · advisory
Verdict: nothing confirmed — 1 single-reviewer observation in the debate digest below.
⚑ panel: GPT-OSS 120B · Gemma 4 31B · Devstral 2 123B · Laguna S 2.1 — 3 distinct, 0 confirmed, 1 below threshold, 2 refuted · web: not used · context: 1 files under review · 90 codebase · 6 standards chunks
Panel debate — how this review was reached
Grounding — context: 1 files under review · 90 codebase · 6 standards chunks
Round 1 — independent reviews
Round 2 — cross-examination
Devstral 2 123B#1Removed fields from request body without validation · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 · support 0Devstral 2 123B#2Hardcoded endpoint path may break if gateway API changes · confirmed: — · refuted: GPT-OSS 120B, Gemma 4 31B, Laguna S 2.1 · support 0Devstral 2 123B#3Hardcoded transcript URL path may break if gateway API changes · confirmed: GPT-OSS 120B · refuted: Gemma 4 31B, Laguna S 2.1 · support 1Not posted (support < 2, or contested at a severity where one refutation vetoes)
Devstral 2 123B#3Hardcoded transcript URL path may break if gateway API changes (support 1)Raised but refuted (left out of the review above)
Devstral 2 123B#1Removed fields from request body without validation — The diff only shows that therepoandprfields were removed from the request body. There is no evidence in the code or documentation that the newDevstral 2 123B#2Hardcoded endpoint path may break if gateway API changes — While the endpoint URL is indeed hard‑coded, the script already captures HTTP errors and reports the status code and details (`attempt X failed: HTTPSynthesis — Laguna S 2.1 wrote the final review from 0 confirmed findings (+1 below threshold) · promotion: support ≥ 2, and no refutation at high severity.
Transcript
rv-20260923172140-3c78c2— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript
rv-20260923172140-3c78c2.