⚒️ Generated with [Fabro](https://fabro.sh)
This commit is contained in:
Fabro 2026-07-01 17:04:28 +00:00
commit b477967ad0
2 changed files with 298 additions and 0 deletions

22
graph.fabro Normal file
View file

@ -0,0 +1,22 @@
digraph PatchCves {
graph [
goal="Triage GitHub Dependabot alerts and open verified dependency-patch PRs",
model_stylesheet="
* { model: claude-opus-4-8; }
"
]
rankdir=LR
start [shape=Mdiamond, label="Start"]
exit [shape=Msquare, label="Exit"]
// Single agent stage. The `/eng-patch-cves` prompt-syntax activates the
// skill of the same name (discovered from .fabro/skills/), which expands to
// the full CVE-patching instructions. The skill self-discovers the target
// repo from the cloned workspace via `gh repo view`, so no extra prompt
// text is needed (and any extra text would be dropped: the skill body has
// no {{user_input}} placeholder).
patch [label="Patch CVEs", prompt="/eng-patch-cves"]
start -> patch -> exit
}

276
run.json Normal file
View file

@ -0,0 +1,276 @@
{
"title": "Triage GitHub Dependabot alerts and open verified dependency-patch PRs",
"spec": {
"run_id": "01KWFA6TC0GC574MQMR4E0MV5D",
"settings": {
"project": {
"name": null,
"description": null,
"metadata": {}
},
"workflow": {
"name": null,
"description": null,
"graph": "workflow.fabro",
"metadata": {}
},
"run": {
"goal": {
"type": "inline",
"value": "Triage GitHub Dependabot alerts and open verified dependency-patch PRs"
},
"working_dir": null,
"metadata": {},
"inputs": {},
"model": {
"provider": "anthropic",
"name": "claude-sonnet-4-6",
"fallbacks": [],
"controls": {
"reasoning_effort": null,
"speed": null
}
},
"git": {
"author": null
},
"prepare": {
"commands": [],
"timeout_ms": 300000
},
"execution": {
"mode": "normal",
"approval": "prompt"
},
"checkpoint": {
"exclude_globs": [],
"skip_git_hooks": false
},
"clone": {
"enabled": true
},
"run_branch": {
"enabled": true,
"push": true
},
"meta_branch": {
"enabled": true,
"push": true
},
"environment": {
"id": "fabro-dev",
"provider": "daytona",
"image": {
"docker": null,
"dockerfile": {
"type": "inline",
"value": "FROM ubuntu:24.04\n\nRUN apt-get update && apt-get install -y --no-install-recommends \\\n curl git ripgrep ca-certificates build-essential pkg-config libssl-dev unzip python3 \\\n xvfb xfce4 xfce4-terminal x11vnc novnc dbus-x11 \\\n libx11-6 libxrandr2 libxext6 libxrender1 libxfixes3 libxss1 libxtst6 libxi6 \\\n && rm -rf /var/lib/apt/lists/*\n\n# Install real Chromium (not the snap stub) via xtradeb PPA\nRUN apt-get update && apt-get install -y --no-install-recommends \\\n software-properties-common curl gnupg \\\n && add-apt-repository -y ppa:xtradeb/apps \\\n && apt-get update \\\n && apt-get install -y --no-install-recommends chromium \\\n && rm -rf /var/lib/apt/lists/*\n\n# Wrapper: Chromium needs --no-sandbox when running as root in a container,\n# and --disable-dev-shm-usage avoids crashes from small /dev/shm\nRUN printf '#!/bin/bash\\nexec /usr/bin/chromium --no-sandbox --disable-dev-shm-usage \"$@\"\\n' \\\n > /usr/local/bin/chromium-wrapper \\\n && chmod +x /usr/local/bin/chromium-wrapper\n\n# Make the wrapper the default in the system .desktop file and via alternatives\nRUN sed -i 's|^Exec=.*|Exec=/usr/local/bin/chromium-wrapper %U|' \\\n /usr/share/applications/chromium.desktop \\\n && update-alternatives --install /usr/bin/x-www-browser x-www-browser \\\n /usr/local/bin/chromium-wrapper 100\n\n# Tell XFCE's exo-open that Chromium is the WebBrowser helper (system-wide)\nRUN mkdir -p /etc/xdg/xfce4 /usr/share/xfce4/helpers \\\n && printf 'WebBrowser=custom-WebBrowser\\n' > /etc/xdg/xfce4/helpers.rc \\\n && printf '[Desktop Entry]\\n\\\nVersion=1.0\\n\\\nType=X-XFCE-Helper\\n\\\nName=Chromium\\n\\\nIcon=chromium\\n\\\nX-XFCE-Category=WebBrowser\\n\\\nX-XFCE-CommandsWithParameter=/usr/local/bin/chromium-wrapper \"%%s\"\\n\\\nX-XFCE-Commands=/usr/local/bin/chromium-wrapper\\n' \\\n > /usr/share/xfce4/helpers/custom-WebBrowser.desktop\n\n# GitHub CLI\nRUN curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg \\\n | dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg \\\n && echo \"deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main\" \\\n | tee /etc/apt/sources.list.d/github-cli.list > /dev/null \\\n && apt-get update && apt-get install -y --no-install-recommends gh \\\n && rm -rf /var/lib/apt/lists/*\n\n# Rust\nRUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y\nENV PATH=\"/root/.cargo/bin:${PATH}\"\nRUN rustup toolchain install nightly-2026-04-14 --profile minimal --component clippy,rustfmt\nRUN cargo install cargo-nextest --locked\nENV CARGO_INCREMENTAL=0\n\n# Bun\nRUN curl -fsSL https://bun.sh/install | bash\nENV PATH=\"/root/.bun/bin:${PATH}\"\n\nWORKDIR /root\n"
}
},
"resources": {
"cpu": 8,
"memory": "16GB",
"disk": "20GB"
},
"network": {
"mode": "allow_all",
"allow": []
},
"lifecycle": {
"preserve": false,
"stop_on_terminal": true,
"auto_stop": "30m"
},
"labels": {
"repo": "fabro-sh/fabro"
},
"env": {}
},
"notifications": {},
"interviews": {
"provider": null,
"slack": null
},
"agent": {
"fabro_tools": false,
"permissions": null,
"mcps": {}
},
"hooks": [],
"scm": {
"provider": null,
"owner": null,
"repository": null,
"github": null
},
"pull_request": {
"enabled": true,
"draft": false,
"auto_merge": false,
"merge_strategy": "squash"
},
"artifacts": {
"include": []
},
"integrations": {
"github": {
"permissions": {
"contents": "write",
"checks": "read",
"vulnerability_alerts": "read",
"pull_requests": "write"
}
}
}
}
},
"graph": {
"name": "PatchCves",
"nodes": {
"exit": {
"id": "exit",
"attrs": {
"label": {
"String": "Exit"
},
"model": {
"String": "claude-opus-4-8"
},
"provider": {
"String": "anthropic"
},
"shape": {
"String": "Msquare"
}
}
},
"start": {
"id": "start",
"attrs": {
"provider": {
"String": "anthropic"
},
"label": {
"String": "Start"
},
"model": {
"String": "claude-opus-4-8"
},
"shape": {
"String": "Mdiamond"
}
}
},
"patch": {
"id": "patch",
"attrs": {
"model": {
"String": "claude-opus-4-8"
},
"prompt": {
"String": "/eng-patch-cves"
},
"label": {
"String": "Patch CVEs"
},
"provider": {
"String": "anthropic"
}
}
}
},
"edges": [
{
"from": "start",
"to": "patch",
"attrs": {}
},
{
"from": "patch",
"to": "exit",
"attrs": {}
}
],
"attrs": {
"model_stylesheet": {
"String": "\n * { model: claude-opus-4-8; }\n "
},
"goal": {
"String": "Triage GitHub Dependabot alerts and open verified dependency-patch PRs"
},
"rankdir": {
"String": "LR"
}
}
},
"graph_source": "digraph PatchCves {\n graph [\n goal=\"Triage GitHub Dependabot alerts and open verified dependency-patch PRs\",\n model_stylesheet=\"\n * { model: claude-opus-4-8; }\n \"\n ]\n rankdir=LR\n\n start [shape=Mdiamond, label=\"Start\"]\n exit [shape=Msquare, label=\"Exit\"]\n\n // Single agent stage. The `/eng-patch-cves` prompt-syntax activates the\n // skill of the same name (discovered from .fabro/skills/), which expands to\n // the full CVE-patching instructions. The skill self-discovers the target\n // repo from the cloned workspace via `gh repo view`, so no extra prompt\n // text is needed (and any extra text would be dropped: the skill body has\n // no {{user_input}} placeholder).\n patch [label=\"Patch CVEs\", prompt=\"/eng-patch-cves\"]\n\n start -> patch -> exit\n}\n",
"workflow_slug": "patch-cves",
"source_directory": "/Users/swerner/Development/os/fabro",
"provenance": {
"server": {
"version": "0.278.0-nightly.0"
},
"client": {
"user_agent": "fabro-cli/0.267.0-nightly.0",
"name": "fabro-cli",
"version": "0.267.0-nightly.0"
},
"subject": {
"kind": "user",
"identity": {
"issuer": "https://github.com",
"subject": "138379"
},
"login": "swerner",
"auth_method": "github",
"avatar_url": "https://avatars.githubusercontent.com/u/138379?v=4"
}
},
"manifest_blob": "809d42dc016060fadf368d97e2d144240b709fb9c028212f5e91beb02b2e284a",
"definition_blob": "396459e10e76f5c8b33c4bc4f7f74da3b71702194e78ae3b0ca726f84cebf17d",
"git": {
"origin_url": "https://github.com/fabro-sh/fabro",
"branch": "add-patch-cves-workflow",
"sha": "943dbe224a3a12cf993e443cc50a2e54f816cfa8",
"dirty": "dirty",
"push_outcome": {
"type": "not_attempted"
}
}
},
"web_url": "https://fabro-testing.walleye-rainbow.ts.net/runs/01KWFA6TC0GC574MQMR4E0MV5D",
"start": null,
"status": {
"kind": "starting"
},
"status_updated_at": "2026-07-01T17:04:13.783168201Z",
"last_event_at": "2026-07-01T17:04:27.943769346Z",
"pending_control": null,
"checkpoints": [],
"conclusion": null,
"sandbox": {
"kind": "ready",
"plan": {
"provider": "daytona"
},
"instance": {
"provider": "daytona",
"snapshot": "fabro-fdb28dec-1233-892c-b9d7-9f88f8353e7a",
"runtime": {
"id": "fabro-01KWFA6TC0GC574MQMR4E0MV5D",
"working_directory": "/home/daytona/workspace/fabro",
"repo_cloned": true,
"clone_origin_url": "https://github.com/fabro-sh/fabro",
"clone_branch": "add-patch-cves-workflow",
"workspace_root": "/home/daytona/workspace",
"repos_root": "/home/daytona/repos",
"primary_repo_path": "/home/daytona/repos/fabro-sh/fabro",
"primary_repo_link": "/home/daytona/workspace/fabro"
}
}
},
"pull_request": null,
"superseded_by": null,
"pending_interviews": {},
"stages": {}
}