feat(digest): surface standards-check warnings in the digest - #182
Merged
Merged
Conversation
Add a "Standards warnings" section to the daily digest issue. For each
repository the owner's app installation can read, standards.sh finds the
latest standards-check run that vetted the default branch and lists its
warning- and notice-level annotations (repo, file, message).
Fleet callers trigger standards-check on pull_request only, so a squash
merge leaves the default-branch head with no run. standards.sh checks the
head commit first, then follows commits/{sha}/pulls to the merged PR that
produced it and reads the run on that PR's head commit. Only the Checks,
Contents and Pull requests permissions the app already holds are used.
Every repository yields one record. A refused read, a nulled check-run
list, an annotation count short of the run's own count, a repo with no
run, a head with no merged PR, and an unlistable owner each render by
name under "Not checked", so "no warnings" can never stand in for "could
not check". Standards failures do not block the queue report.
Closes #179
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a Standards warnings section to the daily Dependabot digest issue. For every repository each owner's app installation can read, the new
scripts/dependabot-digest/standards.shfinds the lateststandards-checkrun that vetted the default branch and lists its warning- and notice-level annotations (repo, file, message). Repos that could not be checked are listed by name with the reason, so "no warnings" can never stand in for "not checked".Precondition from the issue: the first scheduled App-auth digest run (2026-10-02 18:49 UTC, run 37050060143) completed with
success.How the latest default-branch run is found
Every fleet caller triggers
standards-checkonpull_requestonly (standards/caller-stub.ymlin github-workflows; confirmed on dotfiles, claude-config, dev-env, tensegrity). A squash merge writes a new commit on the default branch, and that commit has no run. So per repo:GET installation/repositories(--paginate --slurp) gives the repo list, default branch and archived flag. This is exactly the set the token can read.GET repos/{o}/{r}/commits/{default_branch}gives the head SHA.GET repos/{o}/{r}/commits/{head}/check-runs. If a run exists here (a push-triggered caller), use it.GET repos/{o}/{r}/commits/{head}/pullsand select the PR whosemerge_commit_sha == headandmerged_at != null: the PR whose merge produced that commit.GET repos/{o}/{r}/commits/{pr.head.sha}/check-runs. The run is the one fromapp.slug == github-actionswhose name isrun-standards-checkor ends with/ run-standards-check. Callers can name their job differently. If re-runs leave several runs, the highest id wins.GET repos/{o}/{r}/check-runs/{id}/annotations(--paginate --slurp). Keepwarningandnotice. Dropfailure, because a failure already makes the check red.This uses only the permissions the app already holds: Checks, Contents, Pull requests (plus Metadata). It does not need Actions. I verified steps 3 to 6 live on this repo with the shell token, because dev-env is public:
commits/9bc08fb/pullsreturns #181 withmerge_commit_shaequal to the main head. The check run name isstandards-check / run-standards-check, and its 4 notice annotations came back. Budget: about 5 calls per repo × about 41 repos, well within installation rate limits.Scope caveat, stated in the section itself: a PR run lints only the files that PR changed. Node-floor always checks the whole repo. So "no warnings" means the run was clean, not that the whole repo is clean.
Per-repo states and how each renders
okno-runno standards-check run: …no-prno run, no merged PR: …in-progressrun in progress: …unreadabletotal_count> entries, or an entry with no id/name), or fewer annotations than the run'soutput.annotations_countUNREADABLE: <reason>archivedunlisted(repo null)all of <owner> | OWNER NOT LISTED: <reason>Section-level guards:
--standards: existing render callers are unchanged.run-digest.shalways passes--standards.A standards failure never blocks the Dependabot queue report: it renders as "not checked". Collection failures still abort the digest exactly as before.
Sample (from
tests/fixtures/standards)GitHub files annotations that name no file under the path
.github, with the log line as the line number, so these render as—.Expected noise (follows from the locked design)
no standards-check run. Most of these are twistedmelonman forks. The design forbids dropping them.no shell files/no YAML files/no workflowsnotices fromrun-standards.sh, and runner notices such as the ubuntu-latest migration notice, appear on most runs. The design is to list every notice. Filtering any of them would be a design change.Tests
tests/test-standards.shcovers fixture-drivenghstubs. Cases: warnings across two owners and two levels, failure-level excluded, latest re-run chosen, push-triggered run on the head, no run, no merged PR, nulled check-run list, short annotation pages, HTTP 403 with its reason kept, an archived repo, an unlistable owner, an all-clean survey with explicit "No warnings", clean next to unreadable, all unreadable, empty output and malformed output.tests/test-run-digest.shasserts the section appears end to end, and that an owner whose listing fails renders as not checked.origin/maincopy,test-run-digest.shfails its 2 new assertions andtest-standards.shfails 32.bash scripts/dependabot-digest/tests/run-tests.shpasses all five suites.shellcheck -S infois clean on every script.Not verified here
installation/repositoriesand annotations reads under the real App installation token. Local probes used the shell token on a public repo. The first scheduled run after merge will show this. A refused read renders loudly as not checked.gh api --paginate --slurpon the ubuntu-latest runner needs gh ≥ 2.48. An older gh would fail the call, which renders as not checked rather than clean.|escaping in table cells is not exercised by a test.No workflow or permission change. The runbook is unchanged: no stated fact changed, and the same four read permissions cover the new calls.
Closes #179