Skip to content

gardener: Add triage, pull request review and mention tasks - #164

Merged
scuffi merged 3 commits into
mainfrom
add-gardener
Sep 29, 2026
Merged

scuffi merged 3 commits into
mainfrom
add-gardener

Conversation

@scuffi

@scuffi scuffi commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Adds Gardener (internal preview), a repository bot that runs as GitHub Actions workflows and uses Workers AI. It can only take the actions each task declares.

What it does

Task Runs when Does
triage an org member or collaborator opens an issue Comments with a short summary and likely duplicates, and adds up to two existing labels
pr-review an org member or collaborator opens a PR Leaves one comment-only review; it never approves or requests changes
mention-reply someone comments @gardener-cf … on an issue, PR or discussion Replies on the thread. On a PR, @gardener-cf rebase this has GitHub rebase the branch onto main (or merge main in)

Only org members and collaborators can trigger it. It never pushes code, merges or closes anything.

Anyone with write access to this repository counts, even with a private cloudflare membership. Members without write access need their membership public (github.com/orgs/cloudflare/people → your name → Public): GitHub reports private members as non-members to workflows.

How to use it

  • Just open issues and PRs as usual.
  • To ask it something, mention @gardener-cf in a comment, e.g. "@gardener-cf where is the exec timeout set?"
  • To update a stale PR: "@gardener-cf rebase this" or "@gardener-cf merge main into this".

Each task runs as a Gardener · … workflow in the Actions tab. A red run means Gardener couldn't finish; nothing in the repo changes, so just let me know.

Changing or adding tasks

Tasks live in .gardener/tasks/<id>/TASK.md: YAML front matter for triggers, tools, allowed effects and limits, plus plain-language instructions. See the task authoring guide.

  1. Edit or add a TASK.md. To stop a task, delete its folder or set draft: true.
  2. Run npm run gardener:generate (Node.js 24+) and commit the task with the regenerated files. If you forget, the pull request's Check tasks check fails and says so.
  3. Merge. The Gardener · Sync tasks workflow sends the tasks to Gardener when they reach main, so the change is live straight away.

If stale files get merged anyway, the sync run on main goes red and the previous tasks keep running until a fixed commit lands.

What's in this PR

  • .gardener/: project config (handle gardener-cf, pinned to a Gardener release), the three tasks, and the generated lock file.
  • .github/workflows/gardener-*.yml: one generated workflow per task, plus gardener-sync.yml, which enrols the tasks on each change to main and checks pull requests that change them. Don't edit these by hand.
  • package.json: a gardener:generate script, pinned to the same Gardener release as the workflows.
  • biome.jsonc: ignores the generated .gardener/gardener.lock.json, like package-lock.json.

The repository is already connected to the Gardener runtime, so the tasks start working once this merges.

@changeset-bot

changeset-bot Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: d109048

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@github-actions

Copy link
Copy Markdown
Contributor

Thanks for your interest in Cloudflare Computer.

This repository does not accept unsolicited pull requests. Please use one of the accepted contribution paths instead:

If a maintainer asked you to open this pull request, they can add the allow-pr label and reopen it.

@github-actions github-actions Bot closed this Sep 28, 2026
@scuffi scuffi added the allow-pr Allow a PR to remain open. label Sep 28, 2026
@scuffi scuffi reopened this Sep 28, 2026
@pkg-pr-new

pkg-pr-new Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/@cloudflare/computer@164

commit: d109048

@scuffi
scuffi marked this pull request as ready for review September 29, 2026 12:38

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 3 potential issues.

Devin Review

gardener:
if: >-
${{
(github.event_name == 'pull_request' && github.event.action == 'opened' && github.event.pull_request.head.repo.full_name == github.repository)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 Forked maintainer PRs receive no review

When a maintainer opens a PR from a fork, gardener skips the review because its head repository differs. Eligible maintainer PRs receive no review.

Learn more

The review task accepts pull requests authored by maintainers, but the job guard checks the head repository rather than the author's eligibility. A maintainer can open an approved pull request from their own fork. The workflow then skips the job before Gardener can run. A forked pull_request workflow also has restricted token permissions, so removing the guard alone will not enable submitting the review.

Example: A collaborator opens PR #200 from alice/computer into cloudflare/computer. The task admits the collaborator, but the repositories have different full names, so the review job is skipped.

Recommended fix: Use a fork-compatible event and permission model for the review task, while retaining Gardener's maintainer-author check. Regenerate the workflow and lock file rather than editing generated output alone.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +6 to +10
triggers:
- event: github.issue_comment.created
mentions: [self]
- event: github.discussion_comment.created
mentions: [self]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Inline PR mentions go unanswered

When a maintainer mentions @gardener-cf in an inline review comment, mention-reply never runs. GitHub emits pull_request_review_comment, not either subscribed comment event.

Learn more

GitHub separates general PR conversation comments from inline review comments. General comments produce issue_comment, which this task handles; comments attached to a diff produce pull_request_review_comment, which it does not. This leaves mentions in code review threads unanswered.

Example: A maintainer writes @gardener-cf what does this change do? on a changed line in PR #200. No configured event starts mention-reply, although the same message on the PR's Conversation tab starts it.

Recommended fix: Add a github.pull_request_review_comment.created trigger if Gardener supports it, regenerate the workflow and lock file, and ensure the effect replies to the appropriate review thread.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +6 to +15
trigger:
event: github.issue.opened
authors: maintainers
tools:
- repository.list_files
- repository.read_file
- provider.api.read
effects:
- issue.comment.create
- issue.label.add

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Task behavior lacks event-level tests

The generated check covers configuration consistency, not task outcomes. No tests exercise representative issue, PR, or mention events, despite the repository's new-behavior testing rule.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

@scuffi
scuffi merged commit ada6480 into main Sep 29, 2026
23 checks passed
@scuffi
scuffi deleted the add-gardener branch September 29, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

allow-pr Allow a PR to remain open.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant