Skip to content

build(deps): bump sei-protocol/uci/.github/workflows/ai-review.yml from 0.0.22 to 0.0.26 - #123

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/sei-protocol/uci/dot-github/workflows/ai-review.yml-0.0.26
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/sei-protocol/uci/dot-github/workflows/ai-review.yml-0.0.26

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps sei-protocol/uci/.github/workflows/ai-review.yml from 0.0.22 to 0.0.26.

Release notes

Sourced from sei-protocol/uci/.github/workflows/ai-review.yml's releases.

v0.0.26

What's Changed

Callers: seidroid-review.yml now requires sei-agent-driver v0.23.0 or later. A caller that pins driver-version below it is refused.

Full Changelog: v0.0.25...v0.0.26

v0.0.25

What's Changed

  • fix(seidroid-review): match this tool's GraphQL bot login when reading and closing threads (PLT-1338) in sei-protocol/uci#114
  • fix(seidroid-review): take the review's position on the review that carries the verdict, not a second one in sei-protocol/uci#115
  • fix(seidroid-review): recheck the head before withdrawing, and find a batch review that landed without an answer in sei-protocol/uci#116

Full Changelog: v0.0.24...v0.0.25


seidroid-review.yml

One review per run. The review that carries the verdict and the inline findings is now submitted with the decided event (REQUEST_CHANGES, or APPROVE when approve-on-success allows it). The separate position-only review with boilerplate text is no longer posted.

  • If GitHub refuses the event (422), the review is posted as COMMENT, and the position step records the position.
  • A COMMENT position, such as a note saying why approval was withheld, is still posted as its own review.
  • The review body still starts with <!-- seidroid-review -->. The guard's block check and the withdrawal of an earlier block therefore match the combined review.

Thread readers match the GraphQL bot login. Finding threads are read and resolved again for this tool's own threads (#114).

Safer withdrawal and retries.

  • The position step reads the PR head again before it clears an earlier block. It does not clear the block if the head moved or cannot be confirmed.
  • A batch review POST can fail with a 5xx or no response. The run then looks for a review carrying a hidden per-run marker. If the review landed, the run uses it and does not post a second one.
uses: sei-protocol/uci/.github/workflows/seidroid-review.yml@v0.0.25

v0.0.24

What's Changed

Full Changelog: v0.0.23...v0.0.24

... (truncated)

Commits
  • 0dc48cf feat(seidroid-review): drive sei-agent-driver v0.23.0 (#119)
  • 54c9dac feat(seidroid-review): run the review at high reasoning effort (#118)
  • 1b4330b fix(ai-assistant): reserve @seidroid review close for the review workflow (...
  • 5abb126 Bump korthout/backport-action from 4.6.0 to 4.6.1 (#111)
  • a4de9be Bump sei-protocol/uci/.github/workflows/ai-assistant.yml from 0.0.17 to 0.0.2...
  • 1849c10 Bump sei-protocol/uci/.github/workflows/ai-review.yml from 0.0.17 to 0.0.22 (...
  • fcdcbed fix(seidroid-review): recheck the head before withdrawing, and find a batch r...
  • b6a6b14 fix(seidroid-review): take the review's position on the review that carries t...
  • 3cb8276 fix(seidroid-review): match this tool's GraphQL bot login when reading and cl...
  • ad9635a perf(seidroid-review): install the prebuilt driver, pin Opus 5.5 (PLT-1330) (...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [sei-protocol/uci/.github/workflows/ai-review.yml](https://github.com/sei-protocol/uci) from 0.0.22 to 0.0.26.
- [Release notes](https://github.com/sei-protocol/uci/releases)
- [Commits](4bd0b78...0dc48cf)

---
updated-dependencies:
- dependency-name: sei-protocol/uci/.github/workflows/ai-review.yml
  dependency-version: 0.0.26
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 5, 2026
@cursor

cursor Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
CI-only reusable workflow pin with no application or runtime code changes; misaligned uci-ref may mean prompts/scripts still load from v0.0.22 while the workflow definition is v0.0.26.

Overview
Updates AI Review in .github/workflows/ai-review-self.yml to call sei-protocol/uci/.github/workflows/ai-review.yml at commit 0dc48cfb… (v0.0.26) instead of the previous v0.0.22 pin.

That pulls in upstream CI changes from UCI v0.0.23–v0.0.26, including stricter handling of @seidroid review close, high reasoning effort for automated reviews, sei-agent-driver v0.23.0, and several seidroid-review reliability fixes (single verdict review, GraphQL bot login matching, safer block withdrawal, batch-review retry).

The with.uci-ref input is unchanged and still points at the old v0.0.22 commit; repo docs recommend keeping it aligned with the uses: ref.

Reviewed by Cursor Bugbot for commit 8ae7505. Bugbot is set up for automated code reviews on this repo. Configure here.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This Dependabot bump moves the ai-review.yml reusable workflow pin from v0.0.22 to v0.0.26 (0dc48cf). The new pin is fine, but uci-ref still points at the v0.0.22 SHA, so the new workflow would load the old prompt files. Two "See: …v0.0.22" comments are also out of date.

Findings: 0 blocking | 2 non-blocking | 1 posted inline

Blockers

  • None at the file/PR level.

Non-blocking

  • [suggestion] .github/workflows/ai-review-self.yml:24: uci-ref is still 4bd0b7826bdf7966c2bd899b8810a3aaaa52e80d (v0.0.22). The ai-review.yml input says to "Pin to your uses: ref", and the workflow uses uci-ref to sparse-checkout .github/seidroid/ai-review/{scout,review}.md. As things stand, the v0.0.26 workflow would run with the v0.0.22 prompts. Update it to 0dc48cfb58b6c88f528b6def9784524d444ed0f6, along with the release-link comment above it at line 23. Dependabot only updates the uses: line, so this will keep drifting on future bumps unless it's handled.
  • 1 suggestion(s)/nit(s) flagged inline on specific lines.

if: github.event_name != 'issue_comment' || github.event.issue.pull_request != null
# See: https://github.com/sei-protocol/uci/releases/tag/v0.0.22
uses: sei-protocol/uci/.github/workflows/ai-review.yml@4bd0b7826bdf7966c2bd899b8810a3aaaa52e80d
uses: sei-protocol/uci/.github/workflows/ai-review.yml@0dc48cfb58b6c88f528b6def9784524d444ed0f6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[suggestion] The pin now points at v0.0.26 (0dc48cf), but the comment on the line above still links releases/tag/v0.0.22. The uci-ref input at line 24 (and its comment) also still uses the v0.0.22 SHA 4bd0b78…. Because uci-ref chooses which prompt files are checked out, the workflow and its prompts would come from different versions. Bump both lines to match this pin.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want higher recall? High effort reviews run extra passes and find more bugs. A team admin can switch effort levels in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 8ae7505. Configure here.

if: github.event_name != 'issue_comment' || github.event.issue.pull_request != null
# See: https://github.com/sei-protocol/uci/releases/tag/v0.0.22
uses: sei-protocol/uci/.github/workflows/ai-review.yml@4bd0b7826bdf7966c2bd899b8810a3aaaa52e80d
uses: sei-protocol/uci/.github/workflows/ai-review.yml@0dc48cfb58b6c88f528b6def9784524d444ed0f6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Workflow pin and uci-ref diverge

Medium Severity

The uses pin now points at 0dc48cf (v0.0.26), but uci-ref still names 4bd0b78 (v0.0.22). The reusable workflow checks out prompt files from uci-ref, so this run loads the old prompts under the new review logic. Those two refs are required to stay together.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 8ae7505. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants