Skip to content

fix(observability): bind release identity and verify live Sentry deployments - #1610

Merged
jaywedgeworth22 merged 2 commits into
mainfrom
codex/sentry-live-deployment-20261006
Oct 6, 2026
Merged

jaywedgeworth22 merged 2 commits into
mainfrom
codex/sentry-live-deployment-20261006

Conversation

@jaywedgeworth22

@jaywedgeworth22 jaywedgeworth22 commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Treat green main CI as a trigger, never deployment evidence. Require two uncached healthy full-SHA observations, refreshed main ancestry, and a bounded observation window.
  • Report the actual live SHA when it supersedes the triggering revision; match Sentry/GitHub repositories by stable ID, require an existing matching release, and deduplicate by release/environment.
  • Explicitly bind Next.js build release.name to the source revision used by health. Pass SOURCE_COMMIT/GIT_COMMIT_SHA into the build stage, since Docker stages do not inherit the later runtime stage. Preserve observed-SHA seat/PR attribution within Sentry's 64-character name limit.
  • Fail visibly for missing tokens and reporting errors; never retry uncertain writes or manually trigger a deployment. No new credentials, sampling changes, or costs.

Verification

  • 22 dependency-free focused Node tests pass on current main, including release identity wiring and safety cases.
  • Independent review of reconstructed code and build wiring completed; no remaining code blockers identified.
  • Pinned GitHub Actions to the immutable versions already used by repository CI.
  • Full hosted repository checks remain required. Earlier broad local checks had environment/native-dependency limitations; they are not a claimed full pass. Actual produced bundle/source-map and live Sentry identity reconciliation remain rollout checks.

Task state

Owner-approved code/test publication with task notes here, excluding existing effort-log and other documentation uploads. SDK redaction/CSP work remains in a separate change. Draft pending hosted gates and review. Production is not yet verified; normal main webhook deployment only.

Verification update (2026-10-06)

Hosted checks on 0477a067443dd74da34d4e936ca2f0536ab83cde passed: required verify (2,953 tests passed, one skipped, 11 todo), gitleaks, focused reporter tests, CodeQL, smoke, and Docker build. Automated review is still running. Production rollout is not yet verified.

Corrected rollout state (2026-10-06)

Existing repository automation merged this PR at 12:25:59 UTC as 6a21cf4a4457a1c5d0ccb1fd2a4598fa798dbafc; the earlier pending/unmerged status above is superseded. The separately required named Codex review was quota-blocked, so this merge did not satisfy that gate.

Production verification confirmed the exact healthy revision. The initial Sentry lookup raced release visibility and failed closed. A reporter-only retry (no application redeploy) succeeded, and an independent Sentry read confirmed one production deployment receipt, ID 165610508, release/ref/lastCommit matching the live SHA, and name production seat:codex pr:#1610. Successful run: https://github.com/Simple-With-Us/Usage-Monitor/actions/runs/37463623620 . Bounded missing-release read retries are proposed separately in draft #1612.

@kody-ai

kody-ai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the @kody start-review command at the root of your PR.

  • Validate Business Logic: Ask Kody to validate your code against business rules by adding a comment with the @kody -v business-logic command.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

​

Comment thread scripts/sentry-report-deploy.mjs Fixed
@kody-ai

kody-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown

kody code-review Business Logic medium

Business Rules Validation

Task: 5718332261 — [Future] Fleet-wide daily model budgets and routing through Usage Monitor
Task Link: GitHub issue #1602
Related foundation: budget-status.ts

Status: Issues Found
Confidence: high

Findings

MUST_FIX: PR scope does not match the task

Requirement: “Keep this as future design/backlog work. Budget enforcement and a separate custom gateway are paused pending a later decision; this issue does not authorize implementation, deployment, credential changes, or paid model calls.” “Do not start implementation from this backlog issue without a new owner go-ahead.”

Missing in code: No evidence in this PR diff of design or implementation for Usage Monitor's fleet-wide model budgets, provider routing, admission control, or policy accounting.

Evidence (Code): The changed files concern Sentry deployment reporting and release identity: .github/workflows/sentry-deploy.yml, scripts/sentry-report-deploy.mjs, scripts/sentry-report-deploy.node-test.mjs, scripts/sentry-build-release.cjs, Dockerfile, and next.config.js. The diff does not change src/lib/budget-status.ts, budget persistence, provider admission, model routing, cost accounting, or related API/UI code.

Suggested action: Relink or re-scope this PR to the Sentry deployment task it actually addresses. Keep this task limited to reviewed design work unless separate owner approval authorizes implementation.

MUST_FIX: No organization-wide policy ledger or routing policy is defined

Requirements:

Missing in code: No evidence in this PR diff of an organization-scoped daily ledger, the $0.50 routing transition, the $1.50 DeepSeek admission cap, MiniMax's zero policy accounting, separate actual-cost records, or America/Chicago reset logic.

Evidence (Code): The PR diff contains no budget-ledger schema, policy-window calculation, provider-cost calculation, or DeepSeek/MiniMax decision logic.

Suggested action: In a design document, define the organization scope, ledger entities, policy-spend calculation, MiniMax accounting separation, threshold state machine, and DST-safe America/Chicago window boundaries.

MUST_FIX: Atomic admission, reservations, and reconciliation are absent

Requirements:

Missing in code: No evidence in this PR diff of an atomic admission operation, reservation lifecycle, durable model-request identity, reconciliation state machine, pricing validation, or fail-closed DeepSeek behavior.

Evidence (Code): The idempotency and failure handling added in scripts/sentry-report-deploy.mjs apply exclusively to Sentry deployment reporting. No evidence connects them to model-cost reservations or usage reconciliation.

Suggested action: Specify the smallest transactional admission API, reservation data model, conservative cost-bound calculation, durable request state transitions, reconciliation rules, and fail-closed conditions. Keep activation blocked until separately approved.

MUST_FIX: Shared routing authority and distinguishable cost reporting are not defined

Requirements:

Missing in code: No evidence in this PR diff of a provider-decision response, routing reason, central-authority enforcement, workflow integration inventory, separate accounting fields, or corresponding UI.

Evidence (Code): The diff does not change application APIs, persistence models, provider routing integrations, usage telemetry, or UI components.

Suggested action: Define an explicit routing decision schema with provider, reason, policy state, reservation state, and trustedness; define separate API/UI fields for policy spend, cash cost, estimates, and outstanding reservations; document how every workflow uses the single authority.

MUST_FIX: Task-specific verification and rollout governance are absent

Requirements:

Missing in code: No evidence in this PR diff of budget threshold tests, 19-workflow concurrency tests, reservation reconciliation tests, or timezone/DST tests. No reviewed budget-activation rollout and rollback plan is included.

Evidence (Code): scripts/sentry-report-deploy.node-test.mjs tests Sentry release identity, production observation, deployment reporting, pagination, and attribution only. Those tests do not exercise the task's budget or routing scenarios.

Suggested action: Add a task-specific test matrix covering every required boundary and failure mode, plus a reviewed rollout/rollback plan. Do not activate the policy until both artifacts receive the required review and separate implementation approval.

MUST_FIX: All required design questions remain unanswered

Requirements:

Missing in code: No evidence in this PR diff of an ADR, design proposal, API contract, cross-midnight reservation semantics, authenticated workflow identity, or model-usage reconciliation design.

Evidence (Code): None of the changed files addresses these questions; the documentation and code shown are limited to Sentry deployment behavior.

Suggested action: Resolve all three questions in a reviewed design artifact before authorizing implementation, including explicit cross-midnight attribution, client authentication, replay protection, and credential-separation rules.

Intent Comparison

  • Task intent: Design a future shared authority for organization-wide daily model budgets, DeepSeek/MiniMax routing, reservations, reconciliation, and policy accounting.
  • PR intent: Improve Sentry production deployment evidence, release identity, deployment attribution, and reporting safety.
  • Alignment: scope mismatch

Acceptance Criterion Assessment

Criterion Classification Evidence in this PR diff
AC #1 MISSING No organization-wide shared policy ledger.
AC #2 MISSING No DeepSeek-primary rule through $0.50.
AC #3 MISSING No MiniMax-primary and DeepSeek-fallback transition.
AC #4 MISSING No stop rule for new DeepSeek calls at $1.50.
AC #5 MISSING No zero policy accounting for MiniMax or separate cash-cost tracking.
AC #6 MISSING No America/Chicago midnight reset or DST handling.
AC #7 MISSING No atomic shared admission ledger or reservation accounting.
AC #8 MISSING No conservative pre-call DeepSeek reservation or cap enforcement.
AC #9 MISSING No model-request reconciliation, idempotency, or ambiguity handling.
AC #10 MISSING No pricing provenance, usage trust rules, or paid-admission fail-closed path.
AC #11 MISSING No explicit routing decision/reason or common authority.
AC #12 MISSING No API/UI separation of policy spend, cash costs, estimates, and reservations.
AC #13 MISSING Tests cover Sentry deployment behavior, not the required budget scenarios.
AC #14 MISSING No reviewed task-specific rollout and rollback plan.
AC #15 MISSING The smallest admission API question is unanswered.
AC #16 MISSING Reservation transition and cross-midnight attribution are unanswered.
AC #17 MISSING Client identity, reconciliation, and credential-separation design is unanswered.

💡 This validation runs automatically only on the first review of a pull request. To run it again, comment @kody -v business-logic.

Comment thread .github/workflows/sentry-deploy.yml
Comment thread scripts/sentry-build-release.cjs
Comment thread scripts/sentry-report-deploy.mjs
Comment thread scripts/sentry-report-deploy.mjs Outdated
Comment thread scripts/sentry-report-deploy.mjs

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review current head ca8dc66e67b244ca538f3ff8b1fa23b7dfc10ac2 before merge. This includes the verified-live deployment reporter, explicit build release identity, bounded retries for transient git execution failures, and safe static job summaries. The prior head passed hosted application/security checks; this corrective head has fresh focused tests and independent local review, with new hosted checks running. The named current-head review is a separate required gate, so this PR will remain unmerged if code-review quota prevents completion.

@kody-ai

kody-ai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the @kody start-review command at the root of your PR.

  • Validate Business Logic: Ask Kody to validate your code against business rules by adding a comment with the @kody -v business-logic command.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

​

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@jaywedgeworth22
jaywedgeworth22 enabled auto-merge (squash) October 6, 2026 12:22
@jaywedgeworth22
jaywedgeworth22 merged commit 6a21cf4 into main Oct 6, 2026
13 checks passed
@jaywedgeworth22
jaywedgeworth22 deleted the codex/sentry-live-deployment-20261006 branch October 6, 2026 12:26
@kody-ai

kody-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown

kody code-review Kody Rules medium

Rule [2] applies to the new exported helpers in scripts/sentry-report-deploy.mjs and scripts/sentry-build-release.cjs. They are imported directly by a node:test file, no src/index.ts export is added, and the parsing edge cases are not covered by Vitest. Either expose the supported utilities through src/index.ts and add Vitest specs that import that public surface, including empty and wrong-type parser cases, or keep workflow-only helpers private and test the CLI through Vitest without creating a parallel direct-import surface.

Kody rule violation: Every exported schema or utility ships with tests and must typecheck

@kody-ai

kody-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown

kody code-review Business Logic medium

Business Rules Validation

Task: 5718332261 — [Future] Fleet-wide daily model budgets and routing through Usage Monitor
Task Link: #1602
Status: Issues Found
Confidence: high

Intent Comparison

  • Task intent: Define a future Usage Monitor-owned authority for organization-wide daily model budgets, DeepSeek/MiniMax routing, atomic admission, reservations, and reconciliation.
  • PR intent: Improve production deployment verification, Sentry release identity, deployment reporting, and deployment-reporter tests.
  • Alignment: scope_mismatch

Findings

MUST_FIX: PR scope does not match the task scope

Requirement: "Keep this as future design/backlog work. Budget enforcement and a separate custom gateway are paused pending a later decision; this issue does not authorize implementation, deployment, credential changes, or paid model calls."
Requirement: "Do not start implementation from this backlog issue without a new owner go-ahead."
Missing in code: No evidence in this PR diff of implementing or designing the Usage Monitor model-budget domain. The changes instead concern Sentry deployment automation and release attribution.
Evidence (Code): The changed paths are .github/workflows/sentry-deploy.yml, Dockerfile, next.config.js, scripts/sentry-build-release.cjs, scripts/sentry-report-deploy.mjs, and scripts/sentry-report-deploy.node-test.mjs. No budget ledger, provider-routing, admission, reservation, reconciliation, API, UI, or usage-monitor persistence path is changed.
Suggested action: Re-link this Sentry deployment PR to its appropriate task. Keep issue #1602 as backlog work unless a new owner go-ahead is documented, then use a separately scoped PR for the authorized design or implementation.

MUST_FIX: AC #1 — MISSING: organization-wide daily policy ledger

Requirement: "One organization-wide daily policy ledger shared by all participating workflows, rather than a separate allowance per repository or runner."
Missing in code: No evidence in this PR diff of an organization-scoped ledger or enforcement shared across model-calling workflows.
Evidence (Code): The diff contains Sentry deployment workflow and reporter logic only; no budget entity, organization scope, workflow participation, repository, or runner allowance is present.
Suggested action: In separately authorized work, define one atomic organization-wide daily ledger and specify how every participating workflow is bound to it.

MUST_FIX: AC #2 — MISSING: DeepSeek primary below $0.50

Requirement: "DeepSeek is primary until the daily policy spend reaches $0.50 USD."
Missing in code: No evidence in this PR diff of a $0.50 routing threshold or DeepSeek-primary provider decision.
Evidence (Code): The changed files do not reference DeepSeek, MiniMax, model-provider selection, or policy spend.
Suggested action: In authorized future work, implement the $0.50 transition using the reservation treatment resolved by the task's design questions.

MUST_FIX: AC #3 — MISSING: MiniMax routing after $0.50

Requirement: "After that, MiniMax is primary and DeepSeek is fallback."
Missing in code: No evidence in this PR diff of switching provider priority after the daily threshold.
Evidence (Code): The Sentry reporter's returned values concern deployment revisions and receipt IDs, not provider routing.
Suggested action: In authorized future work, make the shared admission authority return MiniMax as primary and DeepSeek as fallback after the defined threshold.

MUST_FIX: AC #4 — MISSING: DeepSeek hard cap at $1.50

Requirement: "At $1.50 USD of daily policy spend, stop new DeepSeek calls; MiniMax can continue."
Missing in code: No evidence in this PR diff of a $1.50 cap or enforcement preventing new DeepSeek admission.
Evidence (Code): No provider admission or daily-spend enforcement code is changed.
Suggested action: In authorized future work, reject new DeepSeek admission at the cap while preserving the required MiniMax fallback behavior.

MUST_FIX: AC #5 — MISSING: MiniMax policy accounting and separate cash costs

Requirement: "Count MiniMax as $0 in this routing-policy ledger. This is a policy accounting choice, not a claim that the provider is free. Preserve actual billed/estimated costs separately."
Missing in code: No evidence in this PR diff of separate routing-policy, billed-cost, or estimated-cost accounting.
Evidence (Code): No MiniMax cost records or distinction between policy and actual accounting appears in the diff.
Suggested action: In authorized future work, persist MiniMax as zero for policy-ledger purposes while retaining actual billed and estimated amounts in separate fields or records.

MUST_FIX: AC #6 — MISSING: America/Chicago daily reset and DST handling

Requirement: "Reset the daily policy window at midnight in America/Chicago, including daylight-saving transitions."
Missing in code: No evidence in this PR diff of a daily window, timezone handling, or daylight-saving transition logic.
Evidence (Code): The deployment reporter uses absolute timestamps for rollout observation, but contains no organization policy-window implementation.
Suggested action: In authorized future work, calculate policy-window boundaries explicitly in America/Chicago and test daylight-saving transitions.

MUST_FIX: AC #7 — MISSING: atomic admission contract and shared reservations

Requirement: "Define a Usage Monitor-owned admission contract and atomic shared ledger; account for settled spend plus outstanding reservations across concurrent callers."
Missing in code: No evidence in this PR diff of a Usage Monitor admission API, atomic ledger mutation, or settled-plus-reserved balance calculation.
Evidence (Code): No budget persistence, admission endpoint, database transaction, or concurrent model-request path is changed.
Suggested action: In separately authorized work, define the admission contract and implement an atomic shared update that includes settled spend and outstanding reservations.

MUST_FIX: AC #8 — MISSING: bounded DeepSeek reservations

Requirement: "Reserve a conservative upper bound before each DeepSeek request, using validated pricing and bounded input/output. Never admit a reservation that could exceed the $1.50 daily cap."
Missing in code: No evidence in this PR diff of pre-request reservation, pricing validation, input/output bounds, or cap-safe admission.
Evidence (Code): The diff's idempotence logic applies to Sentry deployment receipts and does not reserve model-request cost.
Suggested action: In authorized future work, calculate and atomically reserve a conservative request bound before DeepSeek admission, rejecting any bound that could exceed the cap.

MUST_FIX: AC #9 — MISSING: reservation reconciliation and ambiguous outcomes

Requirement: "Reconcile reservations with reported usage/cost, with durable request IDs, idempotent retries, and clear handling for cancellation, timeout, missing usage, late responses, and crashed callers. An ambiguous outcome must not silently release potential spend."
Missing in code: No evidence in this PR diff of durable model-request IDs, reservation reconciliation, or handling for the listed failure modes.
Evidence (Code): Sentry deployment writes are deduplicated by release and environment, but no provider-request reservation or usage reconciliation state is implemented.
Suggested action: In authorized future work, implement durable idempotent reconciliation and explicit failure-state handling; retain potentially consumed spend until the outcome is resolved.

MUST_FIX: AC #10 — MISSING: pricing provenance and trusted-cost fail-closed behavior

Requirement: "Specify pricing provenance, freshness, token/cache/reasoning accounting, and safe behavior for unknown models or missing/stale usage. Fail closed for new paid DeepSeek admission when the cost bound or ledger cannot be trusted."
Missing in code: No evidence in this PR diff of model pricing metadata, freshness rules, token accounting, unknown-model handling, or model-admission fail-closed behavior.
Evidence (Code): The reporter's deployment identity checks do not establish a trusted DeepSeek cost bound or ledger state.
Suggested action: In authorized future work, document pricing provenance and accounting rules and reject new paid DeepSeek admission whenever trustworthy cost or ledger data is unavailable.

MUST_FIX: AC #11 — MISSING: explicit and centralized routing decisions

Requirement: "Return an explicit provider/routing decision and reason; ensure all participating workflows use the same authority and cannot accidentally multiply the budget."
Missing in code: No evidence in this PR diff of a provider-routing result, decision reason, or shared model-budget authority used by workflows.
Evidence (Code): The reporter returns deployment evidence such as revision and deploy ID, not a provider decision, and does not modify model-calling workflows.
Suggested action: In authorized future work, return a typed provider and reason from the shared authority and require all participating workflows to use that authority.

MUST_FIX: AC #12 — MISSING: distinct policy, cash, estimate, and reservation reporting

Requirement: "Keep routing-policy spend, actual cash costs, estimates, and outstanding reservations distinguishable in API responses and the UI."
Missing in code: No evidence in this PR diff of API or UI fields distinguishing the four required accounting categories.
Evidence (Code): No application API, budget response schema, or UI file is changed.
Suggested action: In authorized future work, expose each accounting category as a distinct response concept and represent the distinctions in the UI.

MUST_FIX: AC #13 — MISSING: required budget-policy test coverage

Requirement: "Test threshold boundaries, concurrent callers (at least 19 workflows), duplicate requests, retries, reconciliation failures, midnight rollover, and daylight-saving changes."
Missing in code: No evidence in this PR diff of any of the required model-budget boundary, 19-workflow concurrency, reconciliation, rollover, or DST tests.
Evidence (Code): scripts/sentry-report-deploy.node-test.mjs tests deployment revision verification, Sentry writes, pagination, and attribution. It does not exercise model providers, policy thresholds, reservations, midnight, or daylight saving.
Suggested action: In separately authorized work, add the complete required test matrix for this domain, including at least 19 concurrent workflow callers.

MUST_FIX: AC #14 — MISSING: reviewed budget-policy rollout and rollback plan

Requirement: "Document a reviewed rollout and rollback plan before activation."
Missing in code: No evidence in this PR diff of a reviewed rollout or rollback plan for the daily model-budget policy.
Evidence (Code): The diff changes deployment-reporting implementation and tests but adds no budget-policy rollout documentation or activation controls.
Suggested action: Before any authorized activation, document and review a staged rollout, verification criteria, rollback triggers, and rollback procedure.

SUGGESTION: AC #15 — MISSING: smallest admission API design remains unanswered

Requirement: "What is the smallest admission API that fits Usage Monitor's existing persistence and usage-telemetry contract?"
Missing in code: No evidence in this PR diff of a design answer for an admission API compatible with Usage Monitor persistence and telemetry.
Evidence (Code): No application API, persistence model, or telemetry contract is modified or documented.
Suggested action: In future authorized design work, document the minimum request, decision, reservation, and reconciliation contract that fits the existing persistence and telemetry capabilities.

SUGGESTION: AC #16 — MISSING: reservation-transition and cross-midnight attribution remain unanswered

Requirement: "How should reservations affect the $0.50 routing transition, and how should in-flight work be attributed across midnight?"
Missing in code: No evidence in this PR diff of a documented rule for reservations at the transition or in-flight requests crossing the daily boundary.
Evidence (Code): No daily policy window or outstanding-reservation behavior is present in the changed files.
Suggested action: In future authorized design work, decide and document how outstanding reservations affect provider choice and which daily window owns in-flight work.

SUGGESTION: AC #17 — MISSING: authenticated client and reconciliation design remains unanswered

Requirement: "What authenticated client identity and reconciliation mechanism prevent double-counting or bypass while keeping provider credentials out of the ledger?"
Missing in code: No evidence in this PR diff of a model-client identity, authorization design, ledger reconciliation mechanism, or provider-credential separation.
Evidence (Code): GitHub and Sentry deployment credentials are unrelated to the required model-budget ledger and do not answer this design question.
Suggested action: In future authorized design work, define authenticated client identity, durable idempotency, reconciliation authorization, and the prohibition on storing provider credentials in the ledger.

Additional Task-Context Check

The description's statement that the existing reader "is not an atomic pre-call reservation/admission contract" is addressed by AC #7 but is not implemented in this diff. The three later design questions are covered by AC #15–#17. The explicit constraint "Do not start implementation from this backlog issue without a new owner go-ahead" reinforces the leading scope-mismatch finding.


Analysis performed by Kodus AI Business Rules Validator


💡 This validation runs automatically only on the first review of a pull request. To run it again, comment @kody -v business-logic.

Comment thread next.config.js
org: process.env.SENTRY_ORG,
project: process.env.SENTRY_SELF_PROJECT || "usage-monitor",
authToken: process.env.SENTRY_AUTH_TOKEN,
release: { name: sentryBuildRelease() },

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Bug high

Revises an earlier Kody suggestion on .github/workflows/sentry-deploy.yml:60 (2026-10-06 12:11 UTC).

release: { name: sentryBuildRelease() } is passed unconditionally, so every build where sentryBuildRelease() returns undefined hands withSentryConfig an explicitly present release object with no name instead of an omitted option. sentryBuildRelease returns undefined for an unset build arg (Dockerfile:23-25 defaults SOURCE_COMMIT/GIT_COMMIT_SHA to ""), for the repo's own unknown/short-SHA values, and for any local/CI build — and per the @sentry/nextjs contract release detection is tied to the name being omitted, so the present-but-undefined option can suppress the plugin's own detection (leaving the build with no usable release name instead of the inferred one), which is the exact opposite of the comment at scripts/sentry-build-release.cjs:6. add the key only when a name was resolved. Note the guard regex at scripts/sentry-report-deploy.node-test.mjs:94 asserts the literal release: { name: sentryBuildRelease() } text, so that assertion must be relaxed alongside this change.

Prompt for LLM

File next.config.js:

Line 72:

**Revises an earlier Kody suggestion** on `.github/workflows/sentry-deploy.yml:60` (2026-10-06 12:11 UTC).

`release: { name: sentryBuildRelease() }` is passed unconditionally, so every build where `sentryBuildRelease()` returns `undefined` hands `withSentryConfig` an explicitly present release object with no name instead of an omitted option. `sentryBuildRelease` returns undefined for an unset build arg (`Dockerfile:23-25` defaults `SOURCE_COMMIT`/`GIT_COMMIT_SHA` to `""`), for the repo's own `unknown`/short-SHA values, and for any local/CI build — and per the @sentry/nextjs contract release detection is tied to the name being *omitted*, so the present-but-undefined option can suppress the plugin's own detection (leaving the build with no usable release name instead of the inferred one), which is the exact opposite of the comment at `scripts/sentry-build-release.cjs:6`. add the key only when a name was resolved. Note the guard regex at `scripts/sentry-report-deploy.node-test.mjs:94` asserts the literal `release: { name: sentryBuildRelease() }` text, so that assertion must be relaxed alongside this change.

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

import { resolve } from 'node:path';
import { fileURLToPath } from 'node:url';

export const CONFIG = Object.freeze({"project": "usage-monitor", "health": "https://usage.jays.services/api/health", "repositoryId": "1284098482", "repository": "Simple-With-Us/Usage-Monitor"});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules critical

This commits environment-specific health and repository configuration in shared source. Read these values through a validated runtime configuration factory instead of embedding deployment-specific literals.

Also found in:

  • scripts/sentry-report-deploy.mjs:8-8

Kody rule violation: Never hardcode credentials or secrets in shared code

const requiredEnv = (name) => {
  const value = process.env[name]?.trim();
  if (!value) throw new Error(`${name} is required`);
  return value;
};

export const CONFIG = Object.freeze({
  project: "usage-monitor",
  health: requiredEnv("PRODUCTION_HEALTH_URL"),
  repositoryId: requiredEnv("GITHUB_REPOSITORY_ID"),
  repository: requiredEnv("GITHUB_REPOSITORY"),
});
Prompt for LLM

File scripts/sentry-report-deploy.mjs:

Line 7:

This commits environment-specific health and repository configuration in shared source. Read these values through a validated runtime configuration factory instead of embedding deployment-specific literals.

**Also found in:**
- `scripts/sentry-report-deploy.mjs:8-8`

Suggested Code:

const requiredEnv = (name) => {
  const value = process.env[name]?.trim();
  if (!value) throw new Error(`${name} is required`);
  return value;
};

export const CONFIG = Object.freeze({
  project: "usage-monitor",
  health: requiredEnv("PRODUCTION_HEALTH_URL"),
  repositoryId: requiredEnv("GITHUB_REPOSITORY_ID"),
  repository: requiredEnv("GITHUB_REPOSITORY"),
});

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

import { resolve } from 'node:path';
import { fileURLToPath } from 'node:url';

export const CONFIG = Object.freeze({"project": "usage-monitor", "health": "https://usage.jays.services/api/health", "repositoryId": "1284098482", "repository": "Simple-With-Us/Usage-Monitor"});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules critical

The committed script exposes the production health hostname and route as deployment inventory. Keep the endpoint outside public source and read a validated runtime value instead.

Kody rule violation: Keep credentials out of public source and verify UI changes with automated screenshots

const requiredEnv = (name) => {
  const value = process.env[name]?.trim();
  if (!value) throw new Error(`${name} is required`);
  return value;
};

export const CONFIG = Object.freeze({
  project: "usage-monitor",
  health: requiredEnv("PRODUCTION_HEALTH_URL"),
  repositoryId: requiredEnv("GITHUB_REPOSITORY_ID"),
  repository: requiredEnv("GITHUB_REPOSITORY"),
});
Prompt for LLM

File scripts/sentry-report-deploy.mjs:

Line 7:

The committed script exposes the production health hostname and route as deployment inventory. Keep the endpoint outside public source and read a validated runtime value instead.

Suggested Code:

const requiredEnv = (name) => {
  const value = process.env[name]?.trim();
  if (!value) throw new Error(`${name} is required`);
  return value;
};

export const CONFIG = Object.freeze({
  project: "usage-monitor",
  health: requiredEnv("PRODUCTION_HEALTH_URL"),
  repositoryId: requiredEnv("GITHUB_REPOSITORY_ID"),
  repository: requiredEnv("GITHUB_REPOSITORY"),
});

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

import { resolve } from 'node:path';
import { fileURLToPath } from 'node:url';

export const CONFIG = Object.freeze({"project": "usage-monitor", "health": "https://usage.jays.services/api/health", "repositoryId": "1284098482", "repository": "Simple-With-Us/Usage-Monitor"});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules critical

The source string publishes a hosting and routing endpoint. Supply the deployment URL through validated runtime configuration rather than committing the private infrastructure link.

Kody rule violation: Never edit in the owner's integration tree — work only in your agent lane worktree

const requiredEnv = (name) => {
  const value = process.env[name]?.trim();
  if (!value) throw new Error(`${name} is required`);
  return value;
};

export const CONFIG = Object.freeze({
  project: "usage-monitor",
  health: requiredEnv("PRODUCTION_HEALTH_URL"),
  repositoryId: requiredEnv("GITHUB_REPOSITORY_ID"),
  repository: requiredEnv("GITHUB_REPOSITORY"),
});
Prompt for LLM

File scripts/sentry-report-deploy.mjs:

Line 7:

The source string publishes a hosting and routing endpoint. Supply the deployment URL through validated runtime configuration rather than committing the private infrastructure link.

Suggested Code:

const requiredEnv = (name) => {
  const value = process.env[name]?.trim();
  if (!value) throw new Error(`${name} is required`);
  return value;
};

export const CONFIG = Object.freeze({
  project: "usage-monitor",
  health: requiredEnv("PRODUCTION_HEALTH_URL"),
  repositoryId: requiredEnv("GITHUB_REPOSITORY_ID"),
  repository: requiredEnv("GITHUB_REPOSITORY"),
});

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

import { resolve } from 'node:path';
import { fileURLToPath } from 'node:url';

export const CONFIG = Object.freeze({"project": "usage-monitor", "health": "https://usage.jays.services/api/health", "repositoryId": "1284098482", "repository": "Simple-With-Us/Usage-Monitor"});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kody code-review Kody Rules critical

Private infrastructure endpoints must not be committed even when they are not credentials. Replace the literal endpoint and deployment identifiers with validated runtime configuration.

Kody rule violation: Never expose secrets or private infrastructure values; reuse existing fleet env vars

const requiredEnv = (name) => {
  const value = process.env[name]?.trim();
  if (!value) throw new Error(`${name} is required`);
  return value;
};

export const CONFIG = Object.freeze({
  project: "usage-monitor",
  health: requiredEnv("PRODUCTION_HEALTH_URL"),
  repositoryId: requiredEnv("GITHUB_REPOSITORY_ID"),
  repository: requiredEnv("GITHUB_REPOSITORY"),
});
Prompt for LLM

File scripts/sentry-report-deploy.mjs:

Line 7:

Private infrastructure endpoints must not be committed even when they are not credentials. Replace the literal endpoint and deployment identifiers with validated runtime configuration.

Suggested Code:

const requiredEnv = (name) => {
  const value = process.env[name]?.trim();
  if (!value) throw new Error(`${name} is required`);
  return value;
};

export const CONFIG = Object.freeze({
  project: "usage-monitor",
  health: requiredEnv("PRODUCTION_HEALTH_URL"),
  repositoryId: requiredEnv("GITHUB_REPOSITORY_ID"),
  repository: requiredEnv("GITHUB_REPOSITORY"),
});

Talk to Kody by mentioning @kody

Was this suggestion helpful? React with 👍 or 👎 to help Kody learn from this interaction.

​

​

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants