docs: point the README at action.yml and the logged remedy #34
Loading…
Reference in a new issue
No description provided.
Delete branch "docs/readme-input-and-remedy-pointers"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Replaces the action input table and the recovery table with pointers to
action.ymland the remedy on the failure log line, as the review of #32 asked (claims01M44DMTYMV2XX9RFN5A2MCZCPand01M44DNK5MWG0DWZ49QPQ50Q54).🤖 Generated with Claude Code
Review
01M44EGC4KRKD9TTZRKSQTATG0— head5a6debdac2ed2bbc24f0486148fddbaccf046af0Review — j4k-oss/review-wrapper @
b6f65f5ce7Scope: diff against base tree
e69943819640Status: dispatched — coverage complete (5/5 slots terminal)
Facts: current review-wide projection
Computed under:
Findings (6)
medium — Outcome table duplicates the code-defined outcome set and exit map
01M44ER8R4WSMZGXPXSBXDM0ZNREADME.md(snippet)01M44EYYY88QXSWAJX4VDVC1GR· valid: The exact grounded README table enumerates the outcomes and exit values. The reviewer reports that src/contract/types.ts defines OUTCOMES and OUTCOME_EXIT with the same outcome members and values; superseded is separately labeled a flag. This is a second, currently matching copy of a code-defined set and map, so it can silently stale. Point to the definitions and retain behavior details without a complete member list or row numbering. Medium severity fits because no current disagreement is shown.medium — Required environment variable list duplicates the code reads
01M44ERZV3461Q6CTWXGBKQ621README.md(snippet)01M44EYYY88QXSWAJX4VDVC1GR· valid: The exact grounded paragraph presents the always-required environment variables as a complete list. The reviewer's specific trace names the reads in src/credentials.ts, src/wrapper/event-context.ts, and src/main.ts and says the code-defined members currently agree, including the two variables abbreviated by GITHUB_EVENT_*. The paragraph therefore restates that set. Point to those reads while retaining the fork-gate and failure behavior. Medium severity fits the matching copy.medium — Composition paragraph restates the reconciler set
01M44ESFQDXQ48MJPBXF6AWNQ8README.md(snippet)01M44EYYY88QXSWAJX4VDVC1GR· valid: The exact grounded architecture paragraph counts and names all three reconcilers. The reviewer reports that WrapperDeps in src/contract/types.ts defines exactly summary, inline, and dispositions and that src/main.ts supplies them. That is a complete copy of the contract-defined reconciler set; the useful wiring explanation can instead point to WrapperDeps. No member difference is reported, so medium severity fits.medium — Fork-gate text overstates when credentials are read
01M44EV6MF7NQX2DJET42P268AREADME.md(snippet)01M44EYYY88QXSWAJX4VDVC1GR· valid: The exact grounded README sentence says the fork gate precedes any call to the credentials module. The reviewer's concrete call trace says main.ts invokes forgeCredentials() before deriving isFork, while reviewCredentials() is deferred through openSession and bypassed on the fork branch. Thus the broad sentence is false even though the capability-token isolation it seeks to explain holds. Naming reviewCredentials() is the precise correction.low — Service URL rule omits the rejected trailing-slash form
01M44EVPVQHRSTQHN71HRTHTSKREADME.md(snippet)01M44EYYY88QXSWAJX4VDVC1GR· valid: The exact grounded README rule excludes a URL ending in /v1 but does not describe /v1/. The reviewer reports that serviceOrigin in src/credentials.ts checks the parsed pathname with a regex matching both suffixes and rejects either before opening a session. A plausible workflow author can supply the omitted trailing-slash form and get a configuration failure. State that /v1 cannot be the final path segment with or without a trailing slash.low — Environment table overstates which PR inputs come from the payload
01M44EX41M27Y04WKDRRFP5MMHREADME.md(snippet)01M44EYYY88QXSWAJX4VDVC1GR· valid: The exact grounded table row says the wrapper's PR inputs come from the event payload without limiting the event type. The reviewer's branch trace says workflow_dispatch obtains only pr_number there and fetches head, branches, repository identity, and state through forge.getPull, while pull_request_target uses payload details. The later README note about dispatch does not make this row accurate; scope the payload statement to event-triggered PRs and describe the dispatch source.Other claims
Coverage
Coverage pass: 01M44EGC7WHKVPV9866S8AKJ9J
Accounting: complete
Slot health: healthy
All six findings are summary-only, and none of them is about the two spots this PR changes, so each goes to the PR that owns that text.
01M44ER8R4WSMZGXPXSBXDM0ZN("Outcome table duplicates the code-defined outcome set and exit map") is valid. #30 already replaces the table with a pointer toOUTCOMESandOUTCOME_EXITinsrc/contract/types.ts.01M44ERZV3461Q6CTWXGBKQ621("Required environment variable list duplicates the code reads") and01M44ESFQDXQ48MJPBXF6AWNQ8("Composition paragraph restates the reconciler set") are valid. #32 already replaces both lists: the variables with a pointer toforgeCredentials,readWrapperInputsandsrc/main.ts, and the reconcilers with a pointer toWrapperDeps. It is stacked on #30.01M44EV6MF7NQX2DJET42P268A("Fork-gate text overstates when credentials are read") is valid. #33 already corrects it: the gate guards onlyreviewCredentials(), andFORGEJO_TOKENis read first on every path.01M44EVPVQHRSTQHN71HRTHTSK("Service URL rule omits the rejected trailing-slash form") and01M44EX41M27Y04WKDRRFP5MMH("Environment table overstates which PR inputs come from the payload") are valid.serviceOriginrejects a path ending in/v1or/v1/, and theworkflow_dispatcharm ofreadWrapperInputsreads onlypr_numberfrom the payload. Tracked in #37, which corrects both rows. It targetsmain.