chore(ai-review): an empty or unfetchable diff posts no blank review comment #63
No reviewers
Labels
No labels
idea
points
1
points
13
points
2
points
3
points
5
points
8
priority
p0
priority
p1
priority
p2
priority
p3
state
blocked
state
done
state
in-progress
state
ready
state
review
state
triage
status
declined
status
in-progress
status
planned
status
proposed
status
shipped
status
under-review
type
bug
type
epic
type
feature
type
spike
type
story
type
task
No milestone
No project
No assignees
3 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
tti/tti-ux!63
Loading…
Reference in a new issue
No description provided.
Delete branch "chore/ai-review-20261002"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
A pull request merged before its AI review job ran got a review comment with a header and no verdict (nis/forgejo-stack#293): the job read the empty diff as an empty review. This re-seeds the canonical ai/ai-review.yml. An empty diff now posts nothing, a diff the job cannot fetch or compute posts one line saying why, and the header names the current review panel. Forgejo runs pull_request workflows from the base branch, so this takes effect on pull requests opened after it merges. Advisory only, never a merge gate.
AI review · advisory
Verdict: looks good — all four reviewers found nothing that needs fixing.
⚑ panel: Muse Glimmer 30B · Gemma 4 31B · Mistral Medium 3.5 128B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 below threshold, 0 refuted · web: not used · context: 1 files under review · 90 codebase · 6 standards chunks
Panel debate — how this review was reached
Grounding — context: 1 files under review · 90 codebase · 6 standards chunks
Round 1 — independent reviews
grep -q '[^[:space:]]') is rgrep -q '[^[:space:]]'(catching whitespace-only files that-swould miss), unfetchable diffs are routed through the `Synthesis — Laguna S 2.1 wrote the final review from 0 confirmed findings · promotion: support ≥ 2, and no refutation at high severity.
Transcript
rv-20261002211210-7fc9ce— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript
rv-20261002211210-7fc9ce.🔧 Security-gate fix map
The gate failed on these dependency findings — fastest path to green for each:
@nuxtjs/mdc@tiptap/corenpm update core --package-lock-onlybrace-expansionbrace-expansiondevaluenpm update devalue --package-lock-onlydevaluenpm update devalue --package-lock-onlydevaluenpm update devalue --package-lock-onlydevaluenpm update devalue --package-lock-onlyjs-yamlnpm update js-yaml --package-lock-onlynode-forgenpm update node-forge --package-lock-onlysharpnpm update sharp --package-lock-onlysvgonpm update svgo --package-lock-onlyundicinpm update undici --package-lock-onlyundicinpm update undici --package-lock-onlyundicinpm update undici --package-lock-onlyPosted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.
AI review · advisory
Verdict: nothing confirmed — 1 single-reviewer observation in the debate digest below.
⚑ panel: Muse Glimmer 30B · Gemma 4 31B · Mistral Medium 3.5 128B · Laguna S 2.1 — 1 distinct, 0 confirmed, 1 below threshold, 0 refuted · web: not used · context: 1 files under review · 90 codebase · 6 standards chunks
Panel debate — how this review was reached
Grounding — context: 1 files under review · 90 codebase · 6 standards chunks
Round 1 — independent reviews
Round 2 — cross-examination
Muse Glimmer 30B#1printf format-string injection via unreviewable message · confirmed: Mistral Medium 3.5 128B · refuted: Gemma 4 31B, Laguna S 2.1 · support 1Not posted (support < 2, or contested at a severity where one refutation vetoes)
Muse Glimmer 30B#1printf format-string injection via unreviewable message (support 1)Synthesis — Laguna S 2.1 wrote the final review from 0 confirmed findings (+1 below threshold) · promotion: support ≥ 2, and no refutation at high severity.
Transcript
rv-20261003010025-b12377— full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript
rv-20261003010025-b12377.Merging over a red check that this change does not cause. This PR changes only
.forgejo/workflows/ai-review.yml, and the failing check is baseline-security and trivy-fs, both already failing on main. Fix path: update the flagged dependencies (or fix the lint) on main. Advisories with no fixed release yet belong in.security-ignorewith a reason and an expiry, as nis/forgejo-stack#303 does for node-forge.