Skip to content

ci(ai-review): grant checks: read so reviewers see SonarQube findings - #3958

Merged
ryanmelt merged 1 commit into
mainfrom
ai-review-checks-read
Sep 29, 2026
Merged

ryanmelt merged 1 commit into
mainfrom
ai-review-checks-read

Conversation

@ryanmelt

Copy link
Copy Markdown
Member

Why

The AI review of #3942 missed the two SonarQube findings that failed the quality gate. The shared gate only read GitHub Actions runs, and SonarQube reports as a check run from its own GitHub App. OpenC3/.github#14 makes the gate collect SonarQube findings and has the reviewers fix them.

What changes

Adds checks: read to the permissions this workflow grants the shared AI review workflow. A called workflow can't get more permission than its caller gives it, so without this the gate can't read the SonarQube check run. It then only warns and leaves the findings out.

This is safe to merge before or after OpenC3/.github#14. The extra permission is read-only and does nothing until the shared workflow uses it.

🤖 Generated with Claude Code

The shared AI review gate now reads the SonarQube check run on the PR
head (OpenC3/.github#14). A called workflow cannot exceed its caller's
permissions, so the caller must grant checks: read.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@codecov

codecov Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 80.12%. Comparing base (2ad8e7b) to head (d07b76e).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #3958   +/-   ##
=======================================
  Coverage   80.11%   80.12%           
=======================================
  Files         901      901           
  Lines       68370    68370           
  Branches     2699     2699           
=======================================
+ Hits        54773    54779    +6     
+ Misses      12929    12926    -3     
+ Partials      668      665    -3     
Flag Coverage Δ
frontend 66.98% <ø> (-0.05%) ⬇️
python 80.13% <ø> (+<0.01%) ⬆️
ruby-api 82.40% <ø> (+0.18%) ⬆️
ruby-backend 85.66% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@sonarqubecloud

Copy link
Copy Markdown

@ryanmelt
ryanmelt merged commit bf2a5f0 into main Sep 29, 2026
38 of 40 checks passed
@ryanmelt
ryanmelt deleted the ai-review-checks-read branch September 29, 2026 03:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant