fix(cli): flows deploy --repo can target GitLab - #609
Conversation
…dence
The module comment still listed only the GitHub App installation and the
Slack/Linear/Jira/Shortcut connections as possible ingresses, which is now
wrong: a GitLab connection is one too.
Replace evidence/gitlab-deploy/ with captures that reproduce. The committed
full-suite.txt was a transcript from before check.sh pinned bun to 1.4.0 and
ended "41 failed | 172 failed" with no README, so a reviewer opening the
evidence for a passing change saw 172 failures. It is now the SDK suite
section of the current run, alongside:
- typecheck.txt tsc source + tests, exit=0
- targeted.txt the three touched files, 201/201
- mutation-host-propagation.txt revert the `host` spread -> 12 failures,
restore -> 100 pass; sha256 recorded
either side of the restore
- environment.txt the probes behind all 31 suite failures
- README.md what each file is, and what is NOT
covered (no live Cloud deploy)
The 31 remaining full-suite failures are environmental and unrelated: 24 need
a usable bubblewrap (apparmor_restrict_unprivileged_userns=1, and the sysctl
CI relaxes is refused by the sysbox FUSE /proc/sys), 7 need a checkout with no
CommonJS ancestor package.json. No test was skipped, weakened or edited.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Relayflow: the adversarial review did not pass. This branch is not approved: the flow stopped here and did not mark it ready to merge. Review of PR #609Reviewed head: Disposition: not clean. Two unresolved review concerns follow. No demonstrated R1 — P2: Cloud namespace-limit parity remains unverifiedLocation: The request explicitly requires namespace-depth validation matching Cloud. A stricter Cloud bound would let invalid targets reach the API; a more permissive I attempted to inspect cloud#3801; access failed: gh api repos/AgentWorkforce/cloud/pulls/3801 --jq '{state,merge_commit_sha}'Exit status: 1. R2 — P2: mutation evidence does not record reproducible restore commandsLocation: The committed report calls its procedure mutation verification “in the strict The command as printed is not executable shell syntax, and This does not establish that the mutation was never performed; it establishes Review coverageRead the PR diff, its test additions, deploy parsing/serialization, connection
Read all available PR conversation comments, inline comments and submitted gh api --paginate repos/AgentWorkforce/flows/issues/609/comments --jq '.[] | {id, author: .user.login, opening: (.body | split("\n") | .[0:8])}'Exit status: 0. gh api --paginate repos/AgentWorkforce/flows/pulls/609/commentsExit status: 0. gh api --paginate repos/AgentWorkforce/flows/pulls/609/reviewsExit status: 0. Verification performed for this reviewWorking directory for the following test/typecheck commands: npx vitest run tests/cloud-deploy.test.ts tests/relay-cli-surface.test.ts tests/flow-requirements.test.tsExit status: 0. npm run typecheck && npm run typecheck:testsExit status: 0. The full SDK suite was not rerun in this review. The committed The diff whitespace check also reports whitespace in committed test transcripts. git diff --check c88c3d0 HEADExit status: 2.
|
parseRepository now mirrors isValidFlowRepositoryCoordinates from AgentWorkforce/cloud packages/web/lib/flows/flow-repository.ts: at most 20 owner (namespace) segments, a 255-character owner, segments and project name led by a letter or digit, and no trailing ., .git or .atom. Boundary cases are pinned on both sides. The evidence/gitlab-deploy transcripts were working artifacts and are removed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
For the review's R1: Cloud's rule (AgentWorkforce/cloud |
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 02170be. Configure here.
|
Addressed the adversarial review (reviewed head 1345c39) in 02170be:
CI is green and Cursor Bugbot passed on 02170be. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Fixes #607.
flows deploy --repo gitlab:group/sub/projectand GitLab.com HTTP(S) URLs now send{ owner: "group/sub", name: "project", host: "gitlab" }, so Cloud selects GitLab instead of treating the target as GitHub.Behavior
owner/nameand GitHub URLs keep their existing wire shape, with nohostkey. Explicitgithub:/gitlab:prefixes are case-insensitive. Baregitlab/myrepoandgithub/docsremain GitHub repositories; barea/b/cremains refused.isValidFlowRepositoryCoordinates(AgentWorkforce/cloudpackages/web/lib/flows/flow-repository.ts) checks them: the owner is the namespace path, at most 255 characters and 20 segments (the root group counts; the project name does not); every owner segment and the project name match/^[A-Za-z0-9][A-Za-z0-9_.-]{0,99}$/and do not end in.,.gitor.atom. A trailing.giton the input is stripped as a URL suffix first, as Cloud'sgitlabProjectCoordinatesdoes.projectto a GitLab target; an unscoped GitHub source against a GitLab target requires an explicitrepository. Explicit scopes are preserved. The existing GitLab--flowupdate path is unchanged and has regression coverage.gitlab:owner/name; JSON repository objects includehost: "gitlab". Usage text anddocs/CLOUD.mddocument the forms, scoping and limits.Files
packages/sdk/src/{cloud-deploy.ts, cli/cloud-deploy.ts, cloud-versions.ts, flow-requirements.ts, cli-commands.ts, cli.ts, index.ts},packages/sdk/tests/{cloud-deploy.test.ts, relay-cli-surface.test.ts},docs/CLOUD.md. No evidence transcripts are committed.Verification
The Cloud-parity cases (
GitLab coordinates match Cloudintests/cloud-deploy.test.ts) were written first against the previous head and failed 10 of 19 (21 segments, 256-char owner,_-led segments, and each forbidden suffix on owner and name were accepted). After the change:The wire shape is unit-pinned against mocked Cloud; no live Cloud deployment was performed.
Note
Medium Risk
Changes hosted deploy wire format, integration preflight, and trigger scoping for GitLab targets; mistakes could mis-route listeners or block valid cross-host trigger combos, though behavior is heavily unit-tested against Cloud rules.
Overview
flows deploy --repocan target GitLab as well as GitHub:gitlab:group/sub/project,github:/gitlab:prefixes, andgithub.com/gitlab.comHTTP(S) URLs parse into a wire shape withhost: "gitlab"when appropriate, while bareowner/namestays GitHub-only (nohostkey).Validation for GitLab namespace paths mirrors Cloud (
isValidFlowRepositoryCoordinates): segment rules, 20 namespace segments, 255-character owner cap, and rejection of bad suffixes (.,.git,.atom) before any deploy HTTP call.Deploy behavior updates integration requirements and trigger scoping: the deploy target requires GitHub or GitLab depending on host; same-host
--onsources defaultrepository/projectto the target; a GitLab target with an unscoped GitHub trigger is refused unlessgithub:repository=…is explicit. Deploy/list output showsgitlab:owner/name;--flowversion updates on existing GitLab listeners do not re-require GitLab as a new deploy-target integration.CLI help,
docs/CLOUD.md, exports, and tests (including Cloud-parity coordinate cases) are updated accordingly.Reviewed by Cursor Bugbot for commit 02170be. Bugbot is set up for automated code reviews on this repo. Configure here.