Add audit-ci read-only CI right-sizing report#299
Conversation
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Warning Review limit reached
More reviews will be available in 30 minutes and 14 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
What
Roadmap #25 (ADR 0002):
ub-review audit-ci— the read-only adoption wedge. Deterministic-only v0; every recommendation isjudgment: deterministic.<out>/ci-audit/:inventory.json,history.json,costs.json,correlation.json,recommendations.json,audit-report.md(schemasub-review.ci_{inventory,history,costs,correlation,recommendations}.v1).correlation.jsonand the report.flag-for-humanalways — overmatch is deliberate, ambiguity resolves to human; survivorship caps confidence atlowwhen absence-of-failures is the only signal; thin history (<20 runs) never right-sizes; nothing right-sizes belowadaptive.GITHUB_TOKENpickup is intentional (adoption wedge); dropped API items are counted as evidence gaps, never silently shrunk.Validation
docker-push/tf-apply/upload-sarif/compliance-check, correlation rule, survivorship cap, tokenless degradation, report receipts/no-boilerplate, repo-slug parsing); fmt/check/clippy/doc/policy-check clean after rebase onto Add gate verdict surface with fail-on-gate contract #298.Known gaps
required_checkisnull/unknown, recorded as a gap.permissions/uses_secrets/matrix_sizenot extracted from YAML (line-scan scope), recorded as a gap; security flagging is name/uses-based,run:step contents are not scanned.unknown-workflowmarker).run_curl_json_getparallels the existing POST helper (~55 shared lines); dedup deferred to the modularization phase.