Address CodeRabbit review comments on a PR end-to-end: fetch, classify, fix, reply, commit, push. See ci/tools/coderabbit_addressor.py for the helper that drives the workflow.
Arguments: $ARGUMENTS
Workflow
Fetch comments. Run:
uv run ci/tools/coderabbit_addressor.py $ARGUMENTS --planThis prints a JSON plan listing every unresolved CodeRabbit comment, classified into one of four buckets:
valid-fix— actionable code changestyle— preference/nit; reply-onlyfalse-positive— disagree; reply with rationalesecurity-flag— flag a human; do not auto-fix
Review the plan. For each
valid-fix, read the file/line being flagged and decide the concrete change. Forfalse-positive, draft the reply. Do not touch anything insecurity-flag— leave it for a human reviewer.Apply fixes one comment at a time. Edit the referenced file, re-read to confirm the change is correct, and stage it.
Reply to each thread via:
uv run ci/tools/coderabbit_addressor.py $ARGUMENTS --reply <comment-id> "<message>"Keep replies terse: either "Fixed in " or a one-sentence rationale for disagreement.
Commit and push using a conventional-commit-format message that lists each addressed comment:
fix: address CodeRabbit review feedback - <comment-1-summary> - <comment-2-summary>Re-run the plan. If
valid-fixcount hits zero and nosecurity-flagremains, the PR is ready to merge. Otherwise iterate — hard limit: 3 passes.
Safety rails
- Max 3 iterations per PR. If CodeRabbit keeps asking for changes after 3 rounds, stop and flag the human reviewer — something structural is off.
- Never auto-fix
security-flagcomments. The classifier routes any comment mentioningsecurity,CVE,auth,credential,secret,RCE,injection,CRITICAL,data loss,UAF,use-after-free,buffer overflow, orout-of-boundsinto this bucket. - The pre-merge hook (
ci/hooks/check_pr_merge_reviews.py) blocksgh pr mergeuntil all CodeRabbit threads are resolved, so you cannot accidentally ship with pending feedback.
When to invoke
- Before any
gh pr mergeon a PR where CodeRabbit has posted review comments. - After pushing a new commit that might have triggered a re-review — the hook will remind you.
When NOT to invoke
- On draft PRs where CodeRabbit has not yet reviewed.
- When every open comment is already in a
security-flagstate — defer to a human.