Skip to content

probe: PYTHONSAFEPATH shadowing check (do not merge) - #10

Closed
wezell wants to merge 1 commit into
mainfrom
probe/shadowing-check
Closed

wezell wants to merge 1 commit into
mainfrom
probe/shadowing-check

Conversation

@wezell

@wezell wezell commented Sep 29, 2026

Copy link
Copy Markdown
Member

Throwaway PR to verify end-to-end that the pinned action's code runs instead of the checkout's cli/ package after #7/#9/#8.

It changes one always-printed review log line to include [SHADOW-PROBE]. The review run's log is the test: if the marker appears, the checkout's code is still executing; if not, the pinned release runs (expected). Closed immediately after checking.

@github-actions

Copy link
Copy Markdown

dotbot code review:

  • Reviewer: meta/muse-spark-1.3 (medium)
  • Overall: patch is correct
  • New findings this run: 0
  • Prior unresolved dotbot findings still relevant: 0
  • Active findings total: 0

Single log-string change adding [SHADOW-PROBE] marker has no functional impact; intentional throwaway probe per PR description.

Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads.

reviewed by dotbot · meta/muse-spark-1.3 · medium

@github-actions

Copy link
Copy Markdown

dotbot code review:

  • Reviewer: ~z-ai/glm-latest (medium)
  • Overall: patch is correct
  • New findings this run: 0
  • Prior unresolved dotbot findings still relevant: 0
  • Active findings total: 0

The patch only appends '[SHADOW-PROBE]' to a log message string in review_workflow.py, which has no functional, correctness, or security impact.

Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads.

reviewed by dotbot · ~z-ai/glm-latest · medium

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ dotbot review: all reviewer models (meta/muse-spark-1.3, ~z-ai/glm-latest) agree — patch is correct.

approved automatically by dotbot

@wezell

wezell commented Sep 29, 2026

Copy link
Copy Markdown
Member Author

Probe complete — closing without merging.

Result: the runtime log line is Running dotbot (meta/muse-spark-1.3) to generate review findings... — without the [SHADOW-PROBE] marker this PR adds — so the review executed the pinned v1.3.1 release, not this checkout's cli/ package. (PYTHONSAFEPATH=1 does its job.)

For contrast, before the fix (v1.2.0 pin) a run here printed a message format that only existed in the PR head's code and submitted an approval the pinned revision could not.

@wezell wezell closed this Sep 29, 2026
@wezell
wezell deleted the probe/shadowing-check branch September 29, 2026 16:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant