Conversation
ApprovabilityVerdict: Approved at Macroscope's review found this PR approvable — This is a localized fix to the existing pull-request watch watermark, adding optional edit-time propagation so rewritten bot comments are recognized as new activity. The change is backward-compatible and covered by focused watch, decoding, and provider tests, with no product-default or static-analysis changes. You can add or adjust custom eligibility rules. Learn more. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (2)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (8)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughGitHub pull-request comments and reviews now carry edit timestamps through decoding and provider activity results. Pull-request watch evaluation uses an edit timestamp, when present, to identify fresh remarks and advance its watermark. Tests cover one-time reporting and wake limits. ChangesEdited Pull Request Remarks
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to This change makes the pull-request watch wake the agent when a bot edits an existing review comment. Focused tests pass, and no merge-blocking risk was found. The disclosed limits are the first-100 cap on edit times and a possible stale snippet if an edit lands between reads. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Edited review comments can now trigger follow-up work. Self-comment filtering and the limit on consecutive comment-only updates remain in place. No new permission bypass was identified, but racing reads and downstream execution have not been verified end to end. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
watch_pull_requestonly treats a comment as new when itscreatedAtis past the watch's watermark. Bots like Greptile, CodeRabbit, and Macroscope re-review a push by editing their existing summary comment, which keeps the same id andcreatedAt, so the re-review never wakes the agent. If CI finishes first, the agent sees no review, ends its turn, and nothing wakes it again.Fixes #15282.
How I fixed it:
PullRequestComment(and thread comments) get an optionaleditedAt. GitHub fills it from GraphQLlastEditedAt. I usedlastEditedAtinstead ofupdatedAtbecause reactions also moveupdatedAt, which would cause comment-only wakes for nothing.gh pr view --json comments,reviewsdoes not exposelastEditedAt, so the existing GraphQL review-thread read also selects it for issue comments and reviews and merges it by node id, the same way reactions already arrive.editedAt ?? createdAtas each remark's activity time, keeping the same watermark and same-second id logic. Edits count toward the existing 10 comment-only wake limit, so a bot that keeps rewriting a progress comment cannot loop an agent. Hosts without an edit time keep today's behavior.Known limits:
Verification:
github-actions,macroscopeapp, andcoderabbitaiall have comments created around 06:11 to 06:26 and edited hours later (lastEditedAt09:53 to 10:03), so today none of those re-reviews wake a watching agent.lastEditedAtfor comments, reviews, and thread comments.vp test run src/orchestration-v2/pullRequestWatch.test.ts src/pullRequest/gitHubPullRequestJson.test.ts src/pullRequest/GitHubPullRequestProvider.test.tsinapps/server: 2 failed before the fix, 133 passed after.Reviewed with Codex (GPT-6-Astra, medium). Its two findings are the known limits above.
Created with Claude Opus 5.5 in Claude Code, with implementation by GPT-6-Astra (Codex) through T3 Code.