chore(ai-review): an empty or unfetchable diff posts no blank review comment #63

Merged
A-Guevara merged 1 commit from chore/ai-review-20261002 into main 2026-10-03 02:21:42 +00:00
Owner

A pull request merged before its AI review job ran got a review comment with a header and no verdict (nis/forgejo-stack#293): the job read the empty diff as an empty review. This re-seeds the canonical ai/ai-review.yml. An empty diff now posts nothing, a diff the job cannot fetch or compute posts one line saying why, and the header names the current review panel. Forgejo runs pull_request workflows from the base branch, so this takes effect on pull requests opened after it merges. Advisory only, never a merge gate.

A pull request merged before its AI review job ran got a review comment with a header and no verdict (nis/forgejo-stack#293): the job read the empty diff as an empty review. This re-seeds the canonical ai/ai-review.yml. An empty diff now posts nothing, a diff the job cannot fetch or compute posts one line saying why, and the header names the current review panel. Forgejo runs pull_request workflows from the base branch, so this takes effect on pull requests opened after it merges. Advisory only, never a merge gate.
chore(ai-review): an empty or unfetchable diff posts no blank review comment
Some checks failed
baseline-security / baseline (push) Failing after 2m15s
scan / trivy-fs (push) Failing after 1m39s
ai-review / review (pull_request) Successful in 1m54s
baseline-security / baseline (pull_request) Failing after 2m31s
scan / trivy-fs (pull_request) Failing after 1m32s
2b44bb6065
ai-review-bot left a comment

AI review · advisory

Verdict: looks good — all four reviewers found nothing that needs fixing.

⚑ panel: Muse Glimmer 30B · Gemma 4 31B · Mistral Medium 3.5 128B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 below threshold, 0 refuted · web: not used · context: 1 files under review · 90 codebase · 6 standards chunks

Panel debate — how this review was reached

Grounding — context: 1 files under review · 90 codebase · 6 standards chunks

Round 1 — independent reviews

  • Muse Glimmer 30B (0 findings, confidence 0.85 · thought 4.4k + wrote 73 of 32.8k tokens · 54 s): The workflow changes correctly suppress blank AI review comments for unfetchable or empty diffs, propagate unreviewable reasons, and avoid double-posting; no correctness, security, or best-practice de
  • Gemma 4 31B (0 findings, confidence 1.0 · thought 1.6k + wrote 67 of 16.0k tokens · 47 s): The changes correctly implement the requested logic to prevent blank review comments and add robust handling for unfetchable or uncomputable diffs, while maintaining the advisory nature of the workflo
  • Mistral Medium 3.5 128B (0 findings, confidence 1.0 · wrote 112 of 16.0k tokens · 25 s): The changes in the diff are consistent with the PR’s goal: no blank/whitespace-only review comments will be posted for empty or unfetchable diffs. The new guard pattern (grep -q '[^[:space:]]') is r
  • Laguna S 2.1 (0 findings, confidence 1.0 · wrote 11.9k of 65.5k tokens · 71 s): The PR correctly fixes the blank-comment issue: empty diffs are detected with grep -q '[^[:space:]]' (catching whitespace-only files that -s would miss), unfetchable diffs are routed through the `

Synthesis — Laguna S 2.1 wrote the final review from 0 confirmed findings · promotion: support ≥ 2, and no refutation at high severity.

Transcript rv-20261002211210-7fc9ce — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript rv-20261002211210-7fc9ce.

### AI review · advisory <!-- tti-rv:rv-20261002211210-7fc9ce: --> **Verdict: looks good** — all four reviewers found nothing that needs fixing. <sub>⚑ panel: Muse Glimmer 30B · Gemma 4 31B · Mistral Medium 3.5 128B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 below threshold, 0 refuted · web: not used · context: 1 files under review · 90 codebase · 6 standards chunks</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files under review · 90 codebase · 6 standards chunks **Round 1 — independent reviews** - **Muse Glimmer 30B** (0 findings, confidence 0.85 · thought 4.4k + wrote 73 of 32.8k tokens · 54 s): The workflow changes correctly suppress blank AI review comments for unfetchable or empty diffs, propagate unreviewable reasons, and avoid double-posting; no correctness, security, or best-practice de - **Gemma 4 31B** (0 findings, confidence 1.0 · thought 1.6k + wrote 67 of 16.0k tokens · 47 s): The changes correctly implement the requested logic to prevent blank review comments and add robust handling for unfetchable or uncomputable diffs, while maintaining the advisory nature of the workflo - **Mistral Medium 3.5 128B** (0 findings, confidence 1.0 · wrote 112 of 16.0k tokens · 25 s): The changes in the diff are consistent with the PR’s goal: no blank/whitespace-only review comments will be posted for empty or unfetchable diffs. The new guard pattern (`grep -q '[^[:space:]]'`) is r - **Laguna S 2.1** (0 findings, confidence 1.0 · wrote 11.9k of 65.5k tokens · 71 s): The PR correctly fixes the blank-comment issue: empty diffs are detected with `grep -q '[^[:space:]]'` (catching whitespace-only files that `-s` would miss), unfetchable diffs are routed through the ` **Synthesis** — Laguna S 2.1 wrote the final review from 0 confirmed findings · promotion: support ≥ 2, and no refutation at high severity. <sub>Transcript `rv-20261002211210-7fc9ce` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript `rv-20261002211210-7fc9ce`.</sub>

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
CVE-2026-63671 (HIGH) @nuxtjs/mdc 0.21.1 → 0.22.1 merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f
GHSA-j95f-988m-3j2f (HIGH) @tiptap/core 3.28.0 → 3.30.5 no fix PR yet — npm update core --package-lock-only
CVE-2026-102276 (HIGH) brace-expansion 5.0.9 → 5.0.10, 3.0.7, 2.1.5, 1.1.19 merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s
CVE-2026-102278 (HIGH) brace-expansion 5.0.9 → 5.0.11, 3.0.8, 2.1.6, 1.1.20 merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s
CVE-2026-92708 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-mcm9-63f2-9j32 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-r9w8-h9r3-54w4 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-x5rw-q4pp-hg5g (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
CVE-2026-85393 (HIGH) node-forge 1.4.0 → ? no fix PR yet — npm update node-forge --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only
CVE-2026-19534 (HIGH) undici 8.10.0 → 6.28.1, 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-84961 (HIGH) undici 8.10.0 → 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-85152 (HIGH) undici 8.10.0 → 8.10.2 no fix PR yet — npm update undici --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:2b44bb6065e3802316c3aca8447e71209b851e2c --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | CVE-2026-63671 (HIGH) | `@nuxtjs/mdc` | 0.21.1 → 0.22.1 | merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f | | GHSA-j95f-988m-3j2f (HIGH) | `@tiptap/core` | 3.28.0 → 3.30.5 | no fix PR yet — `npm update core --package-lock-only` | | CVE-2026-102276 (HIGH) | `brace-expansion` | 5.0.9 → 5.0.10, 3.0.7, 2.1.5, 1.1.19 | merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s | | CVE-2026-102278 (HIGH) | `brace-expansion` | 5.0.9 → 5.0.11, 3.0.8, 2.1.6, 1.1.20 | merge #62 — chore(deps): update dependency brace-expansion to v5.0.12 [s | | CVE-2026-92708 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-mcm9-63f2-9j32 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-r9w8-h9r3-54w4 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-x5rw-q4pp-hg5g (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | CVE-2026-85393 (HIGH) | `node-forge` | 1.4.0 → ? | no fix PR yet — `npm update node-forge --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | | CVE-2026-19534 (HIGH) | `undici` | 8.10.0 → 6.28.1, 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-84961 (HIGH) | `undici` | 8.10.0 → 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-85152 (HIGH) | `undici` | 8.10.0 → 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
ai-review-bot left a comment

AI review · advisory

Verdict: nothing confirmed — 1 single-reviewer observation in the debate digest below.

⚑ panel: Muse Glimmer 30B · Gemma 4 31B · Mistral Medium 3.5 128B · Laguna S 2.1 — 1 distinct, 0 confirmed, 1 below threshold, 0 refuted · web: not used · context: 1 files under review · 90 codebase · 6 standards chunks

Panel debate — how this review was reached

Grounding — context: 1 files under review · 90 codebase · 6 standards chunks

Round 1 — independent reviews

  • Muse Glimmer 30B (1 finding, confidence 0.78 · thought 3.9k + wrote 288 of 32.8k tokens · 53 s): No correctness or security defects were introduced by the empty-diff guard changes; the only actionable issue is the printf format-string use when rendering the unreviewable notice.
  • Gemma 4 31B (0 findings, confidence 1.0 · thought 1.7k + wrote 64 of 16.0k tokens · 50 s): The changes correctly implement the fix for blank review comments by ensuring diffs and review bodies contain non-whitespace characters before posting, and add defensive cleanup for reused runners.
  • Mistral Medium 3.5 128B (0 findings, confidence 1.0 · wrote 90 of 16.0k tokens · 24 s): The diff is well-conceived: it correctly guards empty/unfetchable diffs, adds defensive cleanup, avoids posting whitespace-only comments (fixing nis/forgejo-stack#293), and propagates panel-model meta
  • Laguna S 2.1 (0 findings, confidence 0.92 · wrote 101 of 65.5k tokens · 4 s): The PR correctly fixes the empty-diff blank-comment bug by writing no body in the empty-diff path and adding a robust non-empty test in the post step, and it consistently treats unfetchable/unreviewab

Round 2 — cross-examination

  • Muse Glimmer 30B#1 printf format-string injection via unreviewable message · confirmed: Mistral Medium 3.5 128B · refuted: Gemma 4 31B, Laguna S 2.1 · support 1

Not posted (support < 2, or contested at a severity where one refutation vetoes)

  • Muse Glimmer 30B#1 printf format-string injection via unreviewable message (support 1)

Synthesis — Laguna S 2.1 wrote the final review from 0 confirmed findings (+1 below threshold) · promotion: support ≥ 2, and no refutation at high severity.

Transcript rv-20261003010025-b12377 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript rv-20261003010025-b12377.

### AI review · advisory <!-- tti-rv:rv-20261003010025-b12377: --> **Verdict: nothing confirmed** — 1 single-reviewer observation in the debate digest below. <sub>⚑ panel: Muse Glimmer 30B · Gemma 4 31B · Mistral Medium 3.5 128B · Laguna S 2.1 — 1 distinct, 0 confirmed, 1 below threshold, 0 refuted · web: not used · context: 1 files under review · 90 codebase · 6 standards chunks</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 1 files under review · 90 codebase · 6 standards chunks **Round 1 — independent reviews** - **Muse Glimmer 30B** (1 finding, confidence 0.78 · thought 3.9k + wrote 288 of 32.8k tokens · 53 s): No correctness or security defects were introduced by the empty-diff guard changes; the only actionable issue is the printf format-string use when rendering the unreviewable notice. - **Gemma 4 31B** (0 findings, confidence 1.0 · thought 1.7k + wrote 64 of 16.0k tokens · 50 s): The changes correctly implement the fix for blank review comments by ensuring diffs and review bodies contain non-whitespace characters before posting, and add defensive cleanup for reused runners. - **Mistral Medium 3.5 128B** (0 findings, confidence 1.0 · wrote 90 of 16.0k tokens · 24 s): The diff is well-conceived: it correctly guards empty/unfetchable diffs, adds defensive cleanup, avoids posting whitespace-only comments (fixing nis/forgejo-stack#293), and propagates panel-model meta - **Laguna S 2.1** (0 findings, confidence 0.92 · wrote 101 of 65.5k tokens · 4 s): The PR correctly fixes the empty-diff blank-comment bug by writing no body in the empty-diff path and adding a robust non-empty test in the post step, and it consistently treats unfetchable/unreviewab **Round 2 — cross-examination** - `Muse Glimmer 30B#1` printf format-string injection via unreviewable message · confirmed: Mistral Medium 3.5 128B · refuted: Gemma 4 31B, Laguna S 2.1 · support 1 **Not posted** (support < 2, or contested at a severity where one refutation vetoes) - `Muse Glimmer 30B#1` printf format-string injection via unreviewable message (support 1) **Synthesis** — Laguna S 2.1 wrote the final review from 0 confirmed findings (+1 below threshold) · promotion: support ≥ 2, and no refutation at high severity. <sub>Transcript `rv-20261003010025-b12377` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript `rv-20261003010025-b12377`.</sub>
Author
Owner

Merging over a red check that this change does not cause. This PR changes only .forgejo/workflows/ai-review.yml, and the failing check is baseline-security and trivy-fs, both already failing on main. Fix path: update the flagged dependencies (or fix the lint) on main. Advisories with no fixed release yet belong in .security-ignore with a reason and an expiry, as nis/forgejo-stack#303 does for node-forge.

Merging over a red check that this change does not cause. This PR changes only `.forgejo/workflows/ai-review.yml`, and the failing check is baseline-security and trivy-fs, both already failing on main. Fix path: update the flagged dependencies (or fix the lint) on main. Advisories with no fixed release yet belong in `.security-ignore` with a reason and an expiry, as nis/forgejo-stack#303 does for node-forge.
A-Guevara deleted branch chore/ai-review-20261002 2026-10-03 02:21:45 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!63
No description provided.