Release 0.4.0: diff scan, PR action, Close removal - #13
Conversation
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Devin Review found 1 potential issue.
1 flag not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)
| git fetch --no-tags --quiet origin "${base#origin/}" || true | ||
| diff="$(git diff --merge-base "$base" HEAD || git diff "$base" HEAD)" |
There was a problem hiding this comment.
🟡 Explicit branch bases abort scans
When base names a branch like main, git fetch leaves it in FETCH_HEAD; both diff commands reject the unresolved branch. The action exits without scanning.
Prompt for agents
The composite action's base input accepts a Git ref, but action checkouts are normally detached. In action.yml, `git fetch origin main` writes the commit to FETCH_HEAD without creating a local `main` ref, while both subsequent `git diff` commands still resolve the original string `main`. The same ref-materialization problem affects the default `origin/<base>` in shallow checkouts. Fetch the requested revision into a deterministic temporary ref or resolve and retain FETCH_HEAD, then diff that resolved commit. Preserve support for branch names, remote-tracking names, tags, and commit SHAs, and add an end-to-end test using a detached shallow checkout where the base branch is initially absent.
Was this helpful? React with 👍 or 👎 to provide feedback.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 65ead2845b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| git fetch --no-tags --quiet origin "${base#origin/}" || true | ||
| diff="$(git diff --merge-base "$base" HEAD || git diff "$base" HEAD)" |
There was a problem hiding this comment.
Resolve bare base refs after fetching
When the advertised base input is a bare branch such as main, this fetch updates refs/remotes/origin/main but does not create a local main branch in the detached checkout, so both diff commands fail with ambiguous argument 'main' and the scan job exits instead of producing findings. The new workflow's default origin/<base> avoids this, but explicit branch inputs do not; normalize bare branch names to the fetched remote-tracking ref or diff FETCH_HEAD. (git diff -h documents this positional argument as <commit>, so the supplied name must resolve locally.)
Useful? React with 👍 / 👎.
Co-authored-by: Cursor <cursoragent@cursor.com>
…DME at offcut-evidence Co-authored-by: Cursor <cursoragent@cursor.com>
Move sealed benchmark runs to skelvar/offcut-evidence
Co-authored-by: Cursor <cursoragent@cursor.com>
Summary
offcut scan,--format github, composite Action) gated on measured recall.Commits since 4e7e910
Test plan
offcut-scanworkflow runs on this PR; annotations or "No Offcut findings." visibletestmatrix green on Ubuntu/Windows/macOS