Conversation
- validate dbt-package-version via env var, fail-closed on invalid input - flow validated version through env vars to all downstream run: steps - SHA-pin repo-sync/pull-request@v2 - deny GITHUB_TOKEN by default, grant minimum per job Made-with: Cursor
|
Warning Rate limit exceeded
Your organization is not enrolled in usage-based pricing. Contact your admin to enable usage-based pricing to continue reviews beyond the rate limit, or try again in 3 minutes and 49 seconds. ⌛ How to resolve this issue?After the wait time has elapsed, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout. Please see our FAQ for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughThe workflow refactors version validation from sed-based extraction to bash regex checking, exports the validated version via Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
👋 @GuyEshdat |
Made-with: Cursor
Made-with: Cursor
Summary
Hardens the manual release-bump workflow against script injection and supply-chain risk.
inputs.dbt-package-versionflows throughenv:(no shell-template substitution) and is regex-validated; invalid input fails the job rather than producing an empty filtered string. The validated value is exported as a job output for downstream consumption.run:steps read the validated version vianeeds.validate-version.outputs.versionand pass it throughenv:— no${{ }}interpolation inside any shell script.repo-sync/pull-request@v2.GITHUB_TOKEN: top-levelpermissions: {}, job-level overrides for the minimum each job needs (contents: writefor the push job,contents: read+pull-requests: writefor PR creation).Test plan
1.2.3) → release branch + PR created.1.2,1.2.3; rm, ``) → job fails at validation.Made with Cursor
Summary by CodeRabbit