🤖 fix: accept Resolved mark on Codex summary findings - #220
Conversation
Codex now appends " · **Resolved**" to finding lines in its review summary card. The finding regex required the line to end right after the severity, so a marked finding counted as unresolved and turned the Codex Comments check red on #212. Accept the exact optional suffix. A finding marked Resolved, or whose bot-started thread is resolved, is cleared. Unresolved findings and unresolved bot threads still block. --- _Generated with `mux` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex security review |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
@codex review |
|
Codex Review: Didn't find any major issues. What shall we delve into next? Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
scripts/check_codex_comments.shnow accepts the· **Resolved**suffix that Codex appends to finding lines in its review-summary card. A finding marked Resolved, or whose review thread is resolved, no longer fails theCodex Commentscheck. Unresolved findings still fail.Background
Codex now writes resolved findings in the summary card as, for example:
The finding regex required the line to end right after the severity (
· \*\*(Critical|High|Medium|Low)\*\*$). A marked line did not match, so the whole card counted as an unresolved comment. This turned the non-requiredCodex Commentscheck red on #212 (run 37137600873), although all 11 Codex threads on that PR were resolved.Implementation
finding_regextakes an optional· \*\*Resolved\*\*group after the severity, anchored at end of line.is_resolved_findingclears a finding that links to this PR when the exact Resolved mark is present, or (as before) when its linked thread is a resolved thread the bot started.Validation
origin/main(3 of 68 failed), then passed with the fix (68 of 68).summary-security-advisory-findings-resolved-pr212.txt: the 🤖 docs: add GitOps health rules for CoderTemplateTest #212 summary card (comment 5970636463) with only the two finding titles replaced. It has one marked and one unmarked finding, as in the failing run.**Unresolved**,**resolved**, unbolded, repeated, trailing text (all fail).make test-scripts, andshellcheck0.11.0 on both scripts. No workflow changed, so actionlint was not needed.Risks
Low. Only the non-required
Codex Commentscheck uses this parser. The change widens one exact, end-anchored suffix, and only on bot-authored cards that already pass the structural checks.Generated with
mux• Model:anthropic:claude-opus-5-5• Thinking:high