Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
The account paying for this security review has reached its Codex usage limits. The payer can check the Codex usage dashboard. For personal accounts, using credits requires enabling “Use credits for security reviews” in Code review settings. If you do not manage the paying account, contact this repository's admins. |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No unresolved review issues remain.
Review effort: Lite
Findings: None
What changed in this PR
Updates PR automation to compare public APIs using rustdoc artifacts generated with each revision’s locked dependencies.
Changes:
- Builds baseline and head rustdoc JSON with
cargo rustdoc --locked. - Compares artifacts using the pinned semver checker.
- Documents the locked-dependency workflow.
| File | Summary |
|---|---|
.github/workflows/pr-automation.yml |
Builds and compares locked rustdoc artifacts. |
.github/PR_AUTOMATION.md |
Documents the updated compatibility check. |
The public API compatibility job currently fails before comparing APIs because cargo-semver-checks resolves a fresh dependency graph in its placeholder crate. This selects
picky-krb 0.12.5, whose newGssApiMessageErrorvariant breakssspi 0.21.3; ordinary CI succeeds using the committed lockfile'spicky-krb 0.12.4.Build baseline and head rustdoc JSON with
cargo rustdoc --locked, then compare those artifacts with the existing pinned cargo-semver-checks binary. Both revisions retain their own locked dependencies. The existing unprivilegednobodyexecution, cleared environment, tool checksum, feature selection, and compatibility exit-code handling remain in place.This fixes a shared automation failure affecting #2009, #2010, #2012, #2013, #2014 and #2016. Example failed job: https://github.com/Devolutions/IronRDP/actions/runs/36972417921/job/110729084933. Because this is a
pull_request_targetworkflow, the repair takes effect for other PRs after it lands on the base branch.Validation:
cargo rustdoc --lockedbuild with the full workflow feature set passed; the pinned comparator parsed and compared the resulting JSON.git diff --checkpassed.nobodyboundary was inspected rather than executed locally.The comparator's existing inability to detect some changes through dependency re-exports reproduces with both its placeholder mode and this JSON mode; that separate limitation is unchanged.