Repository navigation
🐝 Hive Advisory Report #170
Description
Activity
hivecommons-hive commented
on Sep 25, 2026 ContributorAuthorMore actions🐝 Advisory Digest — 2026-10-11 15:20 EDT
Automated code review findings from Hive agents. Each finding includes a file reference and suggested fix. This comment is updated periodically.
Advice
Frozen for governor mode
IDLEuntil 2026-10-18 (next review in 7 day(s)). The list of recommendations is frozen; their numbers, items and links are recomputed on every digest.Counts quoted: governor actionable queue 1 PRs / 2 issues (what mode and cadence key on; excludes held, draft, in-review and human-gated items) — Overview chart 2 open PRs / 2 open issues (every open or held item across repo cards; the queue-health advice counts these).
- Give idle agents a cadence — At least one enabled agent has no governor cadence, so it cannot be kicked automatically while the hive is quiet. (signals: mode=IDLE, no_cadence_agents=1)
Findings: 10
💡 Showing top 10 findings (by severity). 182 more exist. Set
governor.advisory.show_all: trueto see all.Severity Count 🟠 high 10 🟠 HIGH (10)
- [ci-failure] push-repacked-dist job fails on Dependabot PRs: REPACK_APP_ID/REPACK_APP_PRIVATE_KEY are Actions secrets, not exposed to dependabot-actor pull_request runs (file path not found at analyzed commit — finding may be outdated) ci-maintainer
The [quality] dependabot PRs bumping ncc-bundled deps always fail the dist/ gate — add a repack-dist job to test.yml #171 dist/-drift fix added a two-job sequence in .github/workflows/test.yml: repack-dist (rebuilds dist/ and uploads it as an artifact, outputs 'changed') followed by push-repacked-dist (needs.repack-dist.outputs.changed == 'true'; creates a GitHub App token via actions/create-github-app-token using secrets.REPACK_APP_ID and secrets.REPACK_APP_PRIVATE_KEY, then is meant to commit the rebuilt dist/ back onto the PR branch). On PR chore(deps): bump js-yaml from 5.4.2 to 5.4.3 in the production-dependencies group #440 (dependabot js-yaml 5.4.2->5.4.3, a runtime dep bundled into dist/ via ncc), repack-dist correctly detected dist drift and set changed=true, but push-repacked-dist's create-github-app-token step failed immediately: 'Error: The client-id (or deprecated app-id) input must be set to a non-empty string.' GitHub does not forward repository Actions secrets to pull_request workflow runs triggered by the dependabot[bot] actor unless those same secrets are also added under Settings > Secrets and variables > Dependabot (a separate secrets store from Actions secrets). Because REPACK_APP_ID/REPACK_APP_PRIVATE_KEY only exist as Actions secrets, every dependabot PR that touches an ncc-bundled runtime dep hits this: repack-dist succeeds, push-repacked-dist fails outright, and build-test still fails its 'Verify committed dist/ matches source' step -- so the [quality] dependabot PRs bumping ncc-bundled deps always fail the dist/ gate — add a repack-dist job to test.yml #171 automation never actually closes the loop for the exact PR class it was built for (dependabot runtime-dep bumps). Non-runtime dependabot bumps (devDependencies, GitHub Actions version bumps) are unaffected because they don't touch dist/, so repack-dist reports changed=false and push-repacked-dist is skipped -- which is why most recent dependabot build-test runs are green and this only surfaces on runtime-dep PRs like chore(deps): bump js-yaml from 5.4.2 to 5.4.3 in the production-dependencies group #440 (js-yaml). Fix options for a maintainer: (1) duplicate REPACK_APP_ID/REPACK_APP_PRIVATE_KEY into the repo's Dependabot secrets store so dependabot-triggered runs can read them, or (2) since GitHub App tokens can't be minted for dependabot-actor runs anyway (Dependabot PRs also don't get write-permission GITHUB_TOKEN by default), gate push-repacked-dist to skip when github.actor == 'dependabot[bot]' and instead re-trigger the repack via a maintainer re-run/approval step (e.g.
dependabotrecreate, or a workflow_run-triggered follow-up with repo-scoped permissions) rather than attempting an inline commit during the dependabot-triggered run. - [advisory] prow-github-actions#440: push-repacked-dist fails — Dependabot secrets REPACK_APP_ID/REPACK_APP_PRIVATE_KEY never configured after ci: repack dist/ on dependabot branches without exposing a write token #390; bundled-dep dependabot bumps still red on dist/ gate
.github/workflows/test.ymlqualityRun 38068101038 on chore(deps): bump js-yaml from 5.4.2 to 5.4.3 in the production-dependencies group #440: repack-dist success (changed=true), push-repacked-dist fails at create-github-app-token: app-id empty (Secret source: Dependabot). REPACK_APP_ID/REPACK_APP_PRIVATE_KEY Dependabot secrets from ci: repack dist/ on dependabot branches without exposing a write token #390 never configured. Maintainer-only fix; recorded on [quality] config.ts:305 — the explicit
configsource'snot foundarm is never driven through dist/index.js #422 fold comment + PR 440 comment. - [advisory] 0-byte OWNERS file fails every OWNERS-reading run: decode treats content '' as missing (owners.ts:163, auth.ts:493)
src/utils/owners.tsqualityGitHub returns an empty blob as content:'' encoding:'base64' (verified: gh api repos/cncf/prow-github-actions/git/blobs/e69de29...). decode() in owners.ts:163 and retrieveOwnersFile in auth.ts:493 test !content, so a 0-byte OWNERS file fails /approve, /lgtm and the OWNERS plugins with 'invalid OWNERS file returned from GitHub API' instead of parsing as nobody-listed. Unit tests pin only the missing-key shape (ownersAuth.test.ts:296, auth.test.ts:362). Filed cncf/prow-github-actions#404 for a maintainer (production fix).
- [advisory] prow-github-actions: comment-only prow.yaml throws YAMLException (js-yaml 5 zero-document input) instead of loading as an empty config
src/utils/config.tsqualityjs-yaml ^5.4.2 load() throws 'expected a document, but the input is empty' on zero-document input; parseProwConfig's text.trim()==='' guard (added feat(config): tiered prow.yaml configuration from org .project/.github, an explicit source, and the repo #144) rescues blank/whitespace but not comment-only files, so a '# comment' prow.yaml (repo or org tier) fails every label command with a YAMLException instead of loading as {}. Verified through dist/index.js on main@aa6a0f8. Unit cases cover '', '---', whitespace only. Issue filed with fix options; production change, maintainer PR.
- [advisory] test.yml never runs build-test on main after a tide (github.token) merge; main@3fc21f2 is red but unmeasured — needs workflow_dispatch + schedule ([quality] test.yml never runs on main after a tide merge — github.token merges don't trigger push; add workflow_dispatch + schedule #329)
.github/workflows/test.ymlqualitytest.yml is on:[push,pull_request] only; tide merges via github.token so no push run fires. main has no build-test run after a270568; main@3fc21f2 reproduces the [shared-ci] build-test failing across cncf/prow-github-actions #294 meow unhandled error locally. Fix needs workflows permission: add workflow_dispatch + schedule (issue [quality] test.yml never runs on main after a tide merge — github.token merges don't trigger push; add workflow_dispatch + schedule #329).
- [advisory] prow-github-actions: build-test red on test(bundle): drive the approve.github_review refusals, short-circuits and failures through dist/index.js #286/test(bundle): drive the tide merge gate's missing_labels block and labelMatch wildcards through dist/index.js #289/test(bundle): drive the configured hold and sweep sections through dist/index.js #293 from shared meow.test.ts passthrough flake; incident [shared-ci] build-test failing across cncf/prow-github-actions #294, fix held in test(meow): keep the unit /meow suite off the real network under msw 3 #287
__tests__/issueCommentTest/meow.test.ts⚠️ (not re-reported within the staleness window — still open, but not recently verified) quality - …plus 2 more [advisory] findings from quality, collapsed to keep lower-severity sections within GitHub's comment limit
- [regression-risk] msw 3 bump (chore(deps-dev): bump msw from 2.15.0 to 3.0.1 #278) fails 6 tests and silently disables onUnhandledRequest enforcement across the suite
__tests__/testUtils.ts⚠️ (not re-reported within the staleness window — still open, but not recently verified) qualitydependabot chore(deps-dev): bump msw from 2.15.0 to 3.0.1 #278 (msw 2.15.0 -> 3.0.1) fails build-test: 6 tests red (assign/cc multi-user order via Promise.all+push; configLoader org-500 test leaks its parallel repo-tier probe chain into the next test; HttpResponse.error() now 'fetch failed' not 'Failed to fetch'). Worse, msw 3 renamed onUnhandledRequest -> onUnhandledFrame, so all 55 server.listen({ onUnhandledRequest: 'error' }) calls are ignored and unhandled requests pass through to the real network (CI's unhandled POST /graphql hit api.github.com and got a 401). Reproduced main@a270568 with msw@3.0.1 on Node 24.21.0: 6 failed with egress, 141 timeouts without. Fix is tests-only.
- [bug] prow-github-actions#440: push-repacked-dist job fails — REPACK_APP_ID/REPACK_APP_PRIVATE_KEY secrets still not provisioned, blocking all dependabot dist-bump PRs #440 scanner
PR chore(deps): bump js-yaml from 5.4.2 to 5.4.3 in the production-dependencies group #440 (js-yaml 5.4.2->5.4.3, production dep, ncc-bundled) fails build-test on the known dist/ drift gate (dependabot never runs npm run pack) AND fails the new ci: repack dist/ on dependabot branches without exposing a write token #390 auto-fix job push-repacked-dist: run 38068101038 shows push-repacked-dist's create-github-app-token step erroring 'The client-id (or deprecated app-id) input must be set to a non-empty string' because secrets.REPACK_APP_ID/REPACK_APP_PRIVATE_KEY (test.yml:122-123) are empty — the GitHub App used to mint a write-scoped token for the auto-repack commit+push was never provisioned as Dependabot+Actions secrets. This is exactly the failure mode predicted in closed bead 457a9550-a36 when ci: repack dist/ on dependabot branches without exposing a write token #390 merged, now empirically confirmed live against chore(deps): bump js-yaml from 5.4.2 to 5.4.3 in the production-dependencies group #440. Every future dependabot bump touching a runtime (ncc-bundled) dependency will hit the same two failures until the secrets exist.
☑️ Recently Closed — Fix Not Verified (1)
Closed on an agent's word or a hive heuristic (a merged PR's title matching the finding, or the issues/PRs it cites closing). The hive did not re-check the condition, so it may still hold.
- onPrLgtm error paths + handlePullReq lgtm .catch now covered by unit tests; PR blocked: App token has no push to cncf/prow-github-actions
src/pullReq/onPrLgtm.tsquality — closed Sep 28 (the issues/PRs it cites closed), fix not verified
Analyzed at
cncf/prow-github-actions@511bd1263f23(branchmain) — the latest commit when this digest was generated. File references that no longer exist at this commit are flagged as outdated. Findings marked⚠️ were computed at an older commit and have NOT been re-verified here./kind cleanup
- addedkind/cleanupCategorizes issue or PR as related to cleaning up code, process, or technical debt.Categorizes issue or PR as related to cleaning up code, process, or technical debt.and removed
on Oct 11, 2026
This issue collects advisory findings from Hive agents.
At lower ACMM levels, some agents work in advisory mode — they analyze code and post findings here but do not create issues or PRs. At higher levels, designated agents (e.g. quality) can open issues and PRs directly, while other agents remain advisory-only.
The governor posts periodic digest comments summarizing what advisory agents found.
Do not close this issue. It is a living document.
— hive: agent=governor