From dbbd94dcb706125665b40421bfe563516e5c164c Mon Sep 17 00:00:00 2001 From: Ilya Bogin Date: Tue, 29 Sep 2026 20:56:18 +0300 Subject: [PATCH] ci(auto-approve): job-level concurrency so unrelated comments stop cancelling the approval The approval bridge's workflow-level concurrency group (auto-approve-) was joined by every comment on the PR: Qodo's summary, SonarCloud, Infracost, tofu plans. Those runs cancelled the one carrying the "Code Review by Qodo" event, then their own job-level `if` skipped them, so the PR never got its recorded approval. That fed the Vanta approved-or-justified test failing. Moving the group to the job means jobs skipped by `if` never join it; only Qodo review events compete. Canonical fix from keenable-integrations, byte-identical copy. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/auto-approve.yml | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/.github/workflows/auto-approve.yml b/.github/workflows/auto-approve.yml index a612235..a20b271 100644 --- a/.github/workflows/auto-approve.yml +++ b/.github/workflows/auto-approve.yml @@ -13,12 +13,6 @@ on: issue_comment: types: [created, edited] -# Qodo edits its persistent review comment on every re-review; when edits land -# in a burst, only the newest matters. -concurrency: - group: auto-approve-${{ github.event.issue.number }} - cancel-in-progress: true - jobs: approve: name: Approve on Qodo review @@ -29,6 +23,14 @@ jobs: github.event.comment.user.login == 'qodo-code-review[bot]' && github.event.comment.user.type == 'Bot' && contains(github.event.comment.body, 'Code Review by Qodo') + # Job-level, not workflow-level: a workflow-level group is joined by EVERY + # comment on the PR (Sonar, Infracost, plans, Qodo's summary), and those + # runs cancelled the one carrying the review before their own `if` skipped + # them. Jobs skipped by `if` never join a job-level group, so only Qodo + # review events compete here; when its edits land in a burst, the newest wins. + concurrency: + group: auto-approve-${{ github.event.issue.number }} + cancel-in-progress: true runs-on: ubuntu-latest timeout-minutes: 5 permissions: