Skip to content

Release 0.4.0: diff scan, PR action, Close removal - #13

Merged
balwahidi merged 16 commits into
mainfrom
release/0.4.0
Sep 2, 2026
Merged

balwahidi merged 16 commits into
mainfrom
release/0.4.0

Conversation

@balwahidi

@balwahidi balwahidi commented Sep 2, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Repositions Offcut around a deterministic diff scan (offcut scan, --format github, composite Action) gated on measured recall.
  • Records and removes the rejected Close prototype; ships README evidence limits and version 0.4.0.

Commits since 4e7e910

  • 97ec7e4 research: Offcut Close one-task experiment (rejected)
  • 3e52e8b merge: archive Offcut Close research before removal
  • 39238cd docs: record Offcut Close negative result and decision
  • 2f5b5d0 chore: remove Offcut Close prototype per audit no-go rule
  • 27482d4 bench: labeled corpus of agent-authored PR diffs for scanner recall
  • bd61c61 bench: measure scanner recall on real agent diffs
  • 56b4e44 feat(scan): add --format github for PR annotations
  • d355b92 feat(cli): add offcut scan subcommand
  • 21401cd feat: composite GitHub Action that annotates PRs with Offcut findings
  • bc608b6 fix(bench): store recall results as UTF-8 with provenance header
  • 29ae135 docs: lead with the diff scan and PR action; state evidence limits
  • 65ead28 chore: release 0.4.0

Test plan

  • offcut-scan workflow runs on this PR; annotations or "No Offcut findings." visible
  • test matrix green on Ubuntu/Windows/macOS
  • Do not merge until review item 10 is recorded

Devin Review

balwahidi and others added 12 commits September 2, 2026 15:32
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-02T13:28:58.038608Z 65ead28 PR opened
🔒 Security Review ✅ Completed 2026-09-02T13:34:03.857548Z 65ead28 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

1 flag not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)

Devin Review

Comment thread action.yml Outdated
Comment on lines +27 to +28
git fetch --no-tags --quiet origin "${base#origin/}" || true
diff="$(git diff --merge-base "$base" HEAD || git diff "$base" HEAD)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Explicit branch bases abort scans

When base names a branch like main, git fetch leaves it in FETCH_HEAD; both diff commands reject the unresolved branch. The action exits without scanning.

Prompt for agents
The composite action's base input accepts a Git ref, but action checkouts are normally detached. In action.yml, `git fetch origin main` writes the commit to FETCH_HEAD without creating a local `main` ref, while both subsequent `git diff` commands still resolve the original string `main`. The same ref-materialization problem affects the default `origin/<base>` in shallow checkouts. Fetch the requested revision into a deterministic temporary ref or resolve and retain FETCH_HEAD, then diff that resolved commit. Preserve support for branch names, remote-tracking names, tags, and commit SHAs, and add an end-to-end test using a detached shallow checkout where the base branch is initially absent.
Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 65ead2845b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread action.yml Outdated
Comment on lines +27 to +28
git fetch --no-tags --quiet origin "${base#origin/}" || true
diff="$(git diff --merge-base "$base" HEAD || git diff "$base" HEAD)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Resolve bare base refs after fetching

When the advertised base input is a bare branch such as main, this fetch updates refs/remotes/origin/main but does not create a local main branch in the detached checkout, so both diff commands fail with ambiguous argument 'main' and the scan job exits instead of producing findings. The new workflow's default origin/<base> avoids this, but explicit branch inputs do not; normalize bare branch names to the fetched remote-tracking ref or diff FETCH_HEAD. (git diff -h documents this positional argument as <commit>, so the supplied name must resolve locally.)

Useful? React with 👍 / 👎.

balwahidi and others added 4 commits September 2, 2026 16:48
Co-authored-by: Cursor <cursoragent@cursor.com>
…DME at offcut-evidence

Co-authored-by: Cursor <cursoragent@cursor.com>
Move sealed benchmark runs to skelvar/offcut-evidence
@balwahidi
balwahidi merged commit d9d7d4c into main Sep 2, 2026
7 of 8 checks passed
@balwahidi
balwahidi deleted the release/0.4.0 branch September 2, 2026 14:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant