ci: add pull request stats comment - #467
Conversation
Comments a breakdown of a pull request's changed lines per package (compiler, SDK, utils, website, examples) and per kind of change (source, tests, docs, dependencies, config, generated), along with the test-to-source ratio, the comment share of added source lines, dependency changes, new files and a reminder when package source changes without a release notes update. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #467 +/- ##
=======================================
Coverage 85.92% 85.92%
=======================================
Files 51 51
Lines 4044 4044
Branches 757 757
=======================================
Hits 3475 3475
Misses 444 444
Partials 125 125 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Adds a Net column next to the Total churn. Splits version lines (a package's own version, workspace package versions in dependency lists, and the compiler's version constant) off into a Version kind that is left out of the reviewable totals and summarised as a single "Version bump" line, so release bumps no longer read as dependency or source changes. Counts AGENTS.md and CLAUDE.md as config rather than docs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It introduces a pull_request_target workflow with pull-requests: write that processes untrusted fork PRs, a security-sensitive CI pattern that warrants final human review despite the implementation appearing sound.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
This PR adds a CI workflow that posts (and keeps up to date) a comment on each pull request summarizing its changed lines, broken down per package (Compiler, SDK, Utils, Website, Examples, Repository) and per kind of change (Source, Tests, Docs, Deps, Config, Generated), plus derived metrics (test-to-source ratio, comment share, dependency changes, new files, and a release-notes reminder). It uses pull_request_target so it can also comment on fork PRs, while only executing the trusted script from the base branch and reading the PR's commits purely as git data. This is a self-contained addition to the repo's automation and does not touch any package source.
Changes:
- New
pr-stats.tsscript (no dependencies, run directly by Node 24 via type stripping) that diffs against the merge base and renders a markdown stats report. - New
pr-stats.ymlworkflow triggered on non-draft PR events that computes the report and comments viagh pr comment --edit-last --create-if-none. - Adds
numstatto the cspell dictionary.
| File | Description |
|---|---|
.github/scripts/pr-stats.ts |
Generates the per-package/per-kind changed-lines report from git diff --numstat, plus summary metrics, dependency diff, new files, and release-notes reminder. |
.github/workflows/pr-stats.yml |
pull_request_target workflow that checks out the base branch, fetches PR head as data, runs the script, and posts/edits the stats comment. |
.cspell.json |
Adds numstat to the allowed-words list so spellcheck passes. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| permissions: | ||
| contents: read | ||
| pull-requests: write |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It introduces a security-sensitive pull_request_target workflow with pull-requests: write and a non-trivial 390-line script, which warrants final human review despite appearing correct.
Review effort: Balanced
Findings: 1

Adds a CI job that comments a breakdown of a pull request's changed lines, adapted from the one in Cashonize.
The table has one row per package (Compiler, SDK, Utils, Website, Examples, Repository) and one column per kind of change (Source, Tests, Docs, Deps, Config, Version, Generated), plus Total, Net and Share. Version bumps (a package's own version, workspace package versions in dependency lists, the compiler's version constant) and generated files (
yarn.lock, the ANTLR output next toCashScript.g4) are shown but left out of the totals.AGENTS.mdandCLAUDE.mdcount as config rather than docs. Below the table:package.jsonrelease-notes.mdThe workflow uses
pull_request_targetso it can also comment on pull requests from forks. It only runs the script from the base branch and reads the pull request's commits as git data, without checking them out or running them. It diffs against the merge base and edits its own earlier comment on later pushes.Because the workflow is read from the base branch, it won't run on this PR itself. Here is its output for #458:
Pull request stats
cashc)@cashscript/utils)Reviewable churn: 505 lines (net +161), version bumps and generated files excluded.
Test lines per line of source: 7.81.
Comments: 10 of 51 added source lines, 20%.
New files: 2
packages/cashc/test/generation/fixtures/valid-contract-files/deep_increment_decrement.tspackages/cashc/test/valid-contract-files/deep_increment_decrement.cashAnd for the 0.13.3 version bump commit (bd95aa5):
Pull request stats
cashc)cashscript)@cashscript/utils)Reviewable churn: 0 lines, version bumps and generated files excluded.
Version bump: 0.13.2 → 0.13.3 in
cashscript-examples,testing-suite,cashc,cashscript,@cashscript/utils.🤖 Generated with Claude Code