Skip to content

build(deps): bump sei-protocol/uci/.github/workflows/ai-assistant.yml from 0.0.22 to 0.0.26 - #122

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/sei-protocol/uci/dot-github/workflows/ai-assistant.yml-0.0.26
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/sei-protocol/uci/dot-github/workflows/ai-assistant.yml-0.0.26

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps sei-protocol/uci/.github/workflows/ai-assistant.yml from 0.0.22 to 0.0.26.

Release notes

Sourced from sei-protocol/uci/.github/workflows/ai-assistant.yml's releases.

v0.0.26

What's Changed

Callers: seidroid-review.yml now requires sei-agent-driver v0.23.0 or later. A caller that pins driver-version below it is refused.

Full Changelog: v0.0.25...v0.0.26

v0.0.25

What's Changed

  • fix(seidroid-review): match this tool's GraphQL bot login when reading and closing threads (PLT-1338) in sei-protocol/uci#114
  • fix(seidroid-review): take the review's position on the review that carries the verdict, not a second one in sei-protocol/uci#115
  • fix(seidroid-review): recheck the head before withdrawing, and find a batch review that landed without an answer in sei-protocol/uci#116

Full Changelog: v0.0.24...v0.0.25


seidroid-review.yml

One review per run. The review that carries the verdict and the inline findings is now submitted with the decided event (REQUEST_CHANGES, or APPROVE when approve-on-success allows it). The separate position-only review with boilerplate text is no longer posted.

  • If GitHub refuses the event (422), the review is posted as COMMENT, and the position step records the position.
  • A COMMENT position, such as a note saying why approval was withheld, is still posted as its own review.
  • The review body still starts with <!-- seidroid-review -->. The guard's block check and the withdrawal of an earlier block therefore match the combined review.

Thread readers match the GraphQL bot login. Finding threads are read and resolved again for this tool's own threads (#114).

Safer withdrawal and retries.

  • The position step reads the PR head again before it clears an earlier block. It does not clear the block if the head moved or cannot be confirmed.
  • A batch review POST can fail with a 5xx or no response. The run then looks for a review carrying a hidden per-run marker. If the review landed, the run uses it and does not post a second one.
uses: sei-protocol/uci/.github/workflows/seidroid-review.yml@v0.0.25

v0.0.24

What's Changed

Full Changelog: v0.0.23...v0.0.24

... (truncated)

Commits
  • 0dc48cf feat(seidroid-review): drive sei-agent-driver v0.23.0 (#119)
  • 54c9dac feat(seidroid-review): run the review at high reasoning effort (#118)
  • 1b4330b fix(ai-assistant): reserve @seidroid review close for the review workflow (...
  • 5abb126 Bump korthout/backport-action from 4.6.0 to 4.6.1 (#111)
  • a4de9be Bump sei-protocol/uci/.github/workflows/ai-assistant.yml from 0.0.17 to 0.0.2...
  • 1849c10 Bump sei-protocol/uci/.github/workflows/ai-review.yml from 0.0.17 to 0.0.22 (...
  • fcdcbed fix(seidroid-review): recheck the head before withdrawing, and find a batch r...
  • b6a6b14 fix(seidroid-review): take the review's position on the review that carries t...
  • 3cb8276 fix(seidroid-review): match this tool's GraphQL bot login when reading and cl...
  • ad9635a perf(seidroid-review): install the prebuilt driver, pin Opus 5.5 (PLT-1330) (...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [sei-protocol/uci/.github/workflows/ai-assistant.yml](https://github.com/sei-protocol/uci) from 0.0.22 to 0.0.26.
- [Release notes](https://github.com/sei-protocol/uci/releases)
- [Commits](4bd0b78...0dc48cf)

---
updated-dependencies:
- dependency-name: sei-protocol/uci/.github/workflows/ai-assistant.yml
  dependency-version: 0.0.26
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 5, 2026
@cursor

cursor Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Single CI workflow pin change with no application or auth logic; only possible mismatch is assistant prompt/assets still fetched from the older uci-ref.

Overview
Bumps the AI Assistant GitHub Actions reusable workflow from sei-protocol/uci commit 4bd0b78 (v0.0.22) to 0dc48cf (v0.0.26) in .github/workflows/ai-assist.yml.

That pulls in upstream v0.0.26 behavior for comment/review-triggered assistant runs— notably reserving @seidroid review close for the dedicated review workflow instead of the assistant. The with.uci-ref input is unchanged and still points at the old 4bd0b78 ref while uses: now targets 0dc48cf; repo docs recommend keeping those pins aligned when bumping UCI.

Reviewed by Cursor Bugbot for commit 7d211e6. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This Dependabot bump moves the reusable ai-assistant.yml workflow from v0.0.22 to v0.0.26 (0dc48cf). But the uci-ref input and both release-tag comments still point at v0.0.22, so the workflow and the prompt it fetches now come from different versions.

Findings: 0 blocking | 2 non-blocking | 1 posted inline

Blockers

  • None at the file/PR level.

Non-blocking

  • [suggestion] Repoint the # See: .../releases/tag/v0.0.22 comments on lines 11 and 20 to v0.0.26 so they match the pinned SHA. As they stand, they misstate which version is in use.
  • 1 suggestion(s)/nit(s) flagged inline on specific lines.

assistant:
# See: https://github.com/sei-protocol/uci/releases/tag/v0.0.22
uses: sei-protocol/uci/.github/workflows/ai-assistant.yml@4bd0b7826bdf7966c2bd899b8810a3aaaa52e80d
uses: sei-protocol/uci/.github/workflows/ai-assistant.yml@0dc48cfb58b6c88f528b6def9784524d444ed0f6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[suggestion] uses: now pins v0.0.26 (0dc48cf…), but uci-ref on line 21 still points at v0.0.22 (4bd0b78…). The uci-ref input says "Pin to your uses: ref." The v0.0.26 workflow will check out .github/seidroid/ai-review from the old ref, so it runs with the v0.0.22 prompt and skips any prompt changes made since then. Set uci-ref to 0dc48cfb58b6c88f528b6def9784524d444ed0f6 as well, and update both v0.0.22 comments to v0.0.26.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 7d211e6. Configure here.

assistant:
# See: https://github.com/sei-protocol/uci/releases/tag/v0.0.22
uses: sei-protocol/uci/.github/workflows/ai-assistant.yml@4bd0b7826bdf7966c2bd899b8810a3aaaa52e80d
uses: sei-protocol/uci/.github/workflows/ai-assistant.yml@0dc48cfb58b6c88f528b6def9784524d444ed0f6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Workflow pin and uci-ref diverged

Low Severity

The uses: pin now targets v0.0.26, but uci-ref still names the v0.0.22 SHA. The reusable workflow checks out assistant.md from uci-ref, so this bump runs the new assistant against the old prompt set.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 7d211e6. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants