From b477967ad07705ff309199ec6af8b58f0a297066 Mon Sep 17 00:00:00 2001 From: Fabro Date: Wed, 1 Jul 2026 17:04:28 +0000 Subject: [PATCH] =?UTF-8?q?init=20run=20=E2=9A=92=EF=B8=8F=20Generated=20w?= =?UTF-8?q?ith=20[Fabro](https://fabro.sh)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- graph.fabro | 22 +++++ run.json | 276 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 298 insertions(+) create mode 100644 graph.fabro create mode 100644 run.json diff --git a/graph.fabro b/graph.fabro new file mode 100644 index 000000000..4840008a5 --- /dev/null +++ b/graph.fabro @@ -0,0 +1,22 @@ +digraph PatchCves { + graph [ + goal="Triage GitHub Dependabot alerts and open verified dependency-patch PRs", + model_stylesheet=" + * { model: claude-opus-4-8; } + " + ] + rankdir=LR + + start [shape=Mdiamond, label="Start"] + exit [shape=Msquare, label="Exit"] + + // Single agent stage. The `/eng-patch-cves` prompt-syntax activates the + // skill of the same name (discovered from .fabro/skills/), which expands to + // the full CVE-patching instructions. The skill self-discovers the target + // repo from the cloned workspace via `gh repo view`, so no extra prompt + // text is needed (and any extra text would be dropped: the skill body has + // no {{user_input}} placeholder). + patch [label="Patch CVEs", prompt="/eng-patch-cves"] + + start -> patch -> exit +} diff --git a/run.json b/run.json new file mode 100644 index 000000000..70bebc33e --- /dev/null +++ b/run.json @@ -0,0 +1,276 @@ +{ + "title": "Triage GitHub Dependabot alerts and open verified dependency-patch PRs", + "spec": { + "run_id": "01KWFA6TC0GC574MQMR4E0MV5D", + "settings": { + "project": { + "name": null, + "description": null, + "metadata": {} + }, + "workflow": { + "name": null, + "description": null, + "graph": "workflow.fabro", + "metadata": {} + }, + "run": { + "goal": { + "type": "inline", + "value": "Triage GitHub Dependabot alerts and open verified dependency-patch PRs" + }, + "working_dir": null, + "metadata": {}, + "inputs": {}, + "model": { + "provider": "anthropic", + "name": "claude-sonnet-4-6", + "fallbacks": [], + "controls": { + "reasoning_effort": null, + "speed": null + } + }, + "git": { + "author": null + }, + "prepare": { + "commands": [], + "timeout_ms": 300000 + }, + "execution": { + "mode": "normal", + "approval": "prompt" + }, + "checkpoint": { + "exclude_globs": [], + "skip_git_hooks": false + }, + "clone": { + "enabled": true + }, + "run_branch": { + "enabled": true, + "push": true + }, + "meta_branch": { + "enabled": true, + "push": true + }, + "environment": { + "id": "fabro-dev", + "provider": "daytona", + "image": { + "docker": null, + "dockerfile": { + "type": "inline", + "value": "FROM ubuntu:24.04\n\nRUN apt-get update && apt-get install -y --no-install-recommends \\\n curl git ripgrep ca-certificates build-essential pkg-config libssl-dev unzip python3 \\\n xvfb xfce4 xfce4-terminal x11vnc novnc dbus-x11 \\\n libx11-6 libxrandr2 libxext6 libxrender1 libxfixes3 libxss1 libxtst6 libxi6 \\\n && rm -rf /var/lib/apt/lists/*\n\n# Install real Chromium (not the snap stub) via xtradeb PPA\nRUN apt-get update && apt-get install -y --no-install-recommends \\\n software-properties-common curl gnupg \\\n && add-apt-repository -y ppa:xtradeb/apps \\\n && apt-get update \\\n && apt-get install -y --no-install-recommends chromium \\\n && rm -rf /var/lib/apt/lists/*\n\n# Wrapper: Chromium needs --no-sandbox when running as root in a container,\n# and --disable-dev-shm-usage avoids crashes from small /dev/shm\nRUN printf '#!/bin/bash\\nexec /usr/bin/chromium --no-sandbox --disable-dev-shm-usage \"$@\"\\n' \\\n > /usr/local/bin/chromium-wrapper \\\n && chmod +x /usr/local/bin/chromium-wrapper\n\n# Make the wrapper the default in the system .desktop file and via alternatives\nRUN sed -i 's|^Exec=.*|Exec=/usr/local/bin/chromium-wrapper %U|' \\\n /usr/share/applications/chromium.desktop \\\n && update-alternatives --install /usr/bin/x-www-browser x-www-browser \\\n /usr/local/bin/chromium-wrapper 100\n\n# Tell XFCE's exo-open that Chromium is the WebBrowser helper (system-wide)\nRUN mkdir -p /etc/xdg/xfce4 /usr/share/xfce4/helpers \\\n && printf 'WebBrowser=custom-WebBrowser\\n' > /etc/xdg/xfce4/helpers.rc \\\n && printf '[Desktop Entry]\\n\\\nVersion=1.0\\n\\\nType=X-XFCE-Helper\\n\\\nName=Chromium\\n\\\nIcon=chromium\\n\\\nX-XFCE-Category=WebBrowser\\n\\\nX-XFCE-CommandsWithParameter=/usr/local/bin/chromium-wrapper \"%%s\"\\n\\\nX-XFCE-Commands=/usr/local/bin/chromium-wrapper\\n' \\\n > /usr/share/xfce4/helpers/custom-WebBrowser.desktop\n\n# GitHub CLI\nRUN curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg \\\n | dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg \\\n && echo \"deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main\" \\\n | tee /etc/apt/sources.list.d/github-cli.list > /dev/null \\\n && apt-get update && apt-get install -y --no-install-recommends gh \\\n && rm -rf /var/lib/apt/lists/*\n\n# Rust\nRUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y\nENV PATH=\"/root/.cargo/bin:${PATH}\"\nRUN rustup toolchain install nightly-2026-04-14 --profile minimal --component clippy,rustfmt\nRUN cargo install cargo-nextest --locked\nENV CARGO_INCREMENTAL=0\n\n# Bun\nRUN curl -fsSL https://bun.sh/install | bash\nENV PATH=\"/root/.bun/bin:${PATH}\"\n\nWORKDIR /root\n" + } + }, + "resources": { + "cpu": 8, + "memory": "16GB", + "disk": "20GB" + }, + "network": { + "mode": "allow_all", + "allow": [] + }, + "lifecycle": { + "preserve": false, + "stop_on_terminal": true, + "auto_stop": "30m" + }, + "labels": { + "repo": "fabro-sh/fabro" + }, + "env": {} + }, + "notifications": {}, + "interviews": { + "provider": null, + "slack": null + }, + "agent": { + "fabro_tools": false, + "permissions": null, + "mcps": {} + }, + "hooks": [], + "scm": { + "provider": null, + "owner": null, + "repository": null, + "github": null + }, + "pull_request": { + "enabled": true, + "draft": false, + "auto_merge": false, + "merge_strategy": "squash" + }, + "artifacts": { + "include": [] + }, + "integrations": { + "github": { + "permissions": { + "contents": "write", + "checks": "read", + "vulnerability_alerts": "read", + "pull_requests": "write" + } + } + } + } + }, + "graph": { + "name": "PatchCves", + "nodes": { + "exit": { + "id": "exit", + "attrs": { + "label": { + "String": "Exit" + }, + "model": { + "String": "claude-opus-4-8" + }, + "provider": { + "String": "anthropic" + }, + "shape": { + "String": "Msquare" + } + } + }, + "start": { + "id": "start", + "attrs": { + "provider": { + "String": "anthropic" + }, + "label": { + "String": "Start" + }, + "model": { + "String": "claude-opus-4-8" + }, + "shape": { + "String": "Mdiamond" + } + } + }, + "patch": { + "id": "patch", + "attrs": { + "model": { + "String": "claude-opus-4-8" + }, + "prompt": { + "String": "/eng-patch-cves" + }, + "label": { + "String": "Patch CVEs" + }, + "provider": { + "String": "anthropic" + } + } + } + }, + "edges": [ + { + "from": "start", + "to": "patch", + "attrs": {} + }, + { + "from": "patch", + "to": "exit", + "attrs": {} + } + ], + "attrs": { + "model_stylesheet": { + "String": "\n * { model: claude-opus-4-8; }\n " + }, + "goal": { + "String": "Triage GitHub Dependabot alerts and open verified dependency-patch PRs" + }, + "rankdir": { + "String": "LR" + } + } + }, + "graph_source": "digraph PatchCves {\n graph [\n goal=\"Triage GitHub Dependabot alerts and open verified dependency-patch PRs\",\n model_stylesheet=\"\n * { model: claude-opus-4-8; }\n \"\n ]\n rankdir=LR\n\n start [shape=Mdiamond, label=\"Start\"]\n exit [shape=Msquare, label=\"Exit\"]\n\n // Single agent stage. The `/eng-patch-cves` prompt-syntax activates the\n // skill of the same name (discovered from .fabro/skills/), which expands to\n // the full CVE-patching instructions. The skill self-discovers the target\n // repo from the cloned workspace via `gh repo view`, so no extra prompt\n // text is needed (and any extra text would be dropped: the skill body has\n // no {{user_input}} placeholder).\n patch [label=\"Patch CVEs\", prompt=\"/eng-patch-cves\"]\n\n start -> patch -> exit\n}\n", + "workflow_slug": "patch-cves", + "source_directory": "/Users/swerner/Development/os/fabro", + "provenance": { + "server": { + "version": "0.278.0-nightly.0" + }, + "client": { + "user_agent": "fabro-cli/0.267.0-nightly.0", + "name": "fabro-cli", + "version": "0.267.0-nightly.0" + }, + "subject": { + "kind": "user", + "identity": { + "issuer": "https://github.com", + "subject": "138379" + }, + "login": "swerner", + "auth_method": "github", + "avatar_url": "https://avatars.githubusercontent.com/u/138379?v=4" + } + }, + "manifest_blob": "809d42dc016060fadf368d97e2d144240b709fb9c028212f5e91beb02b2e284a", + "definition_blob": "396459e10e76f5c8b33c4bc4f7f74da3b71702194e78ae3b0ca726f84cebf17d", + "git": { + "origin_url": "https://github.com/fabro-sh/fabro", + "branch": "add-patch-cves-workflow", + "sha": "943dbe224a3a12cf993e443cc50a2e54f816cfa8", + "dirty": "dirty", + "push_outcome": { + "type": "not_attempted" + } + } + }, + "web_url": "https://fabro-testing.walleye-rainbow.ts.net/runs/01KWFA6TC0GC574MQMR4E0MV5D", + "start": null, + "status": { + "kind": "starting" + }, + "status_updated_at": "2026-07-01T17:04:13.783168201Z", + "last_event_at": "2026-07-01T17:04:27.943769346Z", + "pending_control": null, + "checkpoints": [], + "conclusion": null, + "sandbox": { + "kind": "ready", + "plan": { + "provider": "daytona" + }, + "instance": { + "provider": "daytona", + "snapshot": "fabro-fdb28dec-1233-892c-b9d7-9f88f8353e7a", + "runtime": { + "id": "fabro-01KWFA6TC0GC574MQMR4E0MV5D", + "working_directory": "/home/daytona/workspace/fabro", + "repo_cloned": true, + "clone_origin_url": "https://github.com/fabro-sh/fabro", + "clone_branch": "add-patch-cves-workflow", + "workspace_root": "/home/daytona/workspace", + "repos_root": "/home/daytona/repos", + "primary_repo_path": "/home/daytona/repos/fabro-sh/fabro", + "primary_repo_link": "/home/daytona/workspace/fabro" + } + } + }, + "pull_request": null, + "superseded_by": null, + "pending_interviews": {}, + "stages": {} +} \ No newline at end of file