diff --git a/.cargo/config.toml b/.cargo/config.toml
new file mode 100644
index 00000000000..e6afd7ff530
--- /dev/null
+++ b/.cargo/config.toml
@@ -0,0 +1,19 @@
+[http]
+# CI has seen transient crates.io failures from libcurl's HTTP/2 multiplexing
+# during `maturin` metadata resolution. Disable multiplexing and retry more
+# aggressively so editable `uv sync` builds are not failed by one flaky frame.
+multiplexing = false
+
+[net]
+retry = 5
+
+# PyO3 cdylib (`litellm-python-bridge`) links against the host interpreter's
+# symbols, which are not present at link time when building an extension module.
+# On macOS, tell the linker to resolve undefined `_Py*` symbols dynamically at
+# load time (the standard pyo3 extension-module flag) so the cdylib links without
+# a libpython on the link line.
+[target.x86_64-apple-darwin]
+rustflags = ["-C", "link-arg=-undefined", "-C", "link-arg=dynamic_lookup"]
+
+[target.aarch64-apple-darwin]
+rustflags = ["-C", "link-arg=-undefined", "-C", "link-arg=dynamic_lookup"]
diff --git a/.circleci/config.yml b/.circleci/config.yml
index dbeb412506f..f13e9bf66f1 100644
--- a/.circleci/config.yml
+++ b/.circleci/config.yml
@@ -133,6 +133,26 @@ commands:
done
echo "record/replay proxy did not become ready" >&2
exit 1
+ start_fake_openai_endpoint:
+ description: "Start the canned OpenAI mock (tests/_fake_openai_endpoint_server.py) on host port 8190 and wait until healthy. Models whose api_base points here (via FAKE_OPENAI_API_BASE) get well-formed chat/text/embedding responses with realistic usage, so the E2E run neither pays for nor depends on the live provider. A request whose model is '429' returns HTTP 429 for rate-limit/cooldown tests. Run after uv deps are synced."
+ steps:
+ - run:
+ name: Start fake OpenAI endpoint
+ background: true
+ command: |
+ uv run --no-sync python tests/_fake_openai_endpoint_server.py --host 0.0.0.0 --port 8190
+ - run:
+ name: Wait for fake OpenAI endpoint
+ command: |
+ for i in $(seq 1 30); do
+ if curl -sf http://localhost:8190/health >/dev/null 2>&1; then
+ echo "fake OpenAI endpoint is up"
+ exit 0
+ fi
+ sleep 1
+ done
+ echo "fake OpenAI endpoint did not become ready" >&2
+ exit 1
setup_litellm_enterprise_pip:
steps:
- run:
@@ -168,6 +188,10 @@ jobs:
name: win/default
shell: powershell.exe
working_directory: ~/project
+ environment:
+ UV_PYTHON: "3.11"
+ CARGO_HTTP_MULTIPLEXING: "false"
+ CARGO_NET_RETRY: "5"
steps:
- checkout
- run:
@@ -183,6 +207,24 @@ jobs:
environment:
UV_HTTP_TIMEOUT: "300"
command: |
+ $rustupInit = Join-Path $env:TEMP "rustup-init.exe"
+ $rustupVersion = "1.28.2"
+ $rustupUrl = "https://static.rust-lang.org/rustup/archive/$rustupVersion/x86_64-pc-windows-msvc/rustup-init.exe"
+ Invoke-WebRequest -Uri $rustupUrl -OutFile $rustupInit
+ $rustupExpected = "88d8258dcf6ae4f7a80c7d1088e1f36fa7025a1cfd1343731b4ee6f385121fc0"
+ $rustupActual = (Get-FileHash -Path $rustupInit -Algorithm SHA256).Hash.ToLower()
+ if ($rustupActual -ne $rustupExpected) {
+ throw "rustup installer hash mismatch: expected $rustupExpected got $rustupActual"
+ }
+ & $rustupInit -y --profile minimal --default-toolchain stable
+ if ($LASTEXITCODE -ne 0) {
+ exit $LASTEXITCODE
+ }
+ Remove-Item $rustupInit
+ $cargoBin = Join-Path $HOME ".cargo\bin"
+ $env:Path = "$cargoBin;$env:Path"
+ rustc --version
+ cargo --version
$installer = Join-Path $env:TEMP "uv-install.ps1"
Invoke-WebRequest -Uri https://astral.sh/uv/0.10.9/install.ps1 -OutFile $installer
$expected = "d43ffff8d28e7d1e7d1831a212465f12b24a43c7f87f386e95e2a5915aee5d7d"
@@ -200,7 +242,20 @@ jobs:
if (-not (Select-String -Path $PROFILE -SimpleMatch $uvBin -Quiet)) {
Add-Content -Path $PROFILE -Value "`$env:Path = `"$uvBin;`$env:Path`""
}
- uv sync --frozen --group dev --python (Get-Command python).Source
+ if (-not (Select-String -Path $PROFILE -SimpleMatch $cargoBin -Quiet)) {
+ Add-Content -Path $PROFILE -Value "`$env:Path = `"$cargoBin;`$env:Path`""
+ }
+ for ($attempt = 1; $attempt -le 5; $attempt++) {
+ Write-Host "uv sync attempt $attempt/5"
+ uv sync --frozen --group dev --python 3.11
+ if ($LASTEXITCODE -eq 0) {
+ break
+ }
+ if ($attempt -eq 5) {
+ exit $LASTEXITCODE
+ }
+ Start-Sleep -Seconds 15
+ }
- run:
name: Run Windows-specific test
command: |
@@ -210,6 +265,9 @@ jobs:
environment:
UV_HTTP_TIMEOUT: "300"
command: |
+ $env:Path = "$HOME\.cargo\bin;$HOME\.local\bin;$env:Path"
+ cargo --version
+ Get-ChildItem -Path "litellm\rust_bridge" -Filter "_native*" -File -ErrorAction SilentlyContinue | Remove-Item -Force
uv build --wheel --out-dir dist
uv run --no-sync python tests/windows_tests/check_windows_wheel_install.py
@@ -594,6 +652,8 @@ jobs:
working_directory: ~/project
resource_class: large
parallelism: 4
+ environment:
+ FAKE_OPENAI_API_BASE: http://127.0.0.1:8190
steps:
- checkout
- setup_google_dns
@@ -609,6 +669,7 @@ jobs:
paths:
- ~/.cache/uv
key: v1-uv-cache-{{ checksum "uv.lock" }}
+ - start_fake_openai_endpoint
# Run pytest and generate JUnit XML report
- setup_litellm_enterprise_pip
- run:
@@ -995,7 +1056,9 @@ jobs:
name: Run tests
command: |
mkdir -p test-results
- TEST_FILES=$(circleci tests glob "tests/ocr_tests/**/test_*.py")
+ TEST_FILES=$(printf "%s\n%s\n" \
+ "$(circleci tests glob "tests/ocr_tests/**/test_*.py")" \
+ "tests/test_litellm/ocr/test_rust_bridge.py")
echo "$TEST_FILES" | circleci tests run \
--verbose \
--command="tr ' ' '\\n' | awk '/\\.py/ {print; next} {sub(/\\.[A-Z][^.]*$/, \"\"); gsub(/\\./, \"/\"); print \$0 \".py\"}' | xargs uv run --no-sync python -m pytest \
@@ -1549,6 +1612,7 @@ jobs:
name: Install Dependencies
command: |
uv sync --frozen --all-groups --all-extras --python 3.12
+ - start_fake_openai_endpoint
- start_postgres:
db_name: litellm_test
- attach_workspace:
@@ -1586,6 +1650,7 @@ jobs:
-e DATABASE_URL="postgresql://postgres:postgres@host.docker.internal:5432/litellm_test" \
-e DEFAULT_NUM_WORKERS_LITELLM_PROXY=1 \
-e DISABLE_SCHEMA_UPDATE="True" \
+ -e FAKE_OPENAI_API_BASE=http://host.docker.internal:8190 \
--name my-app \
--add-host=host.docker.internal:host-gateway \
-v $(pwd)/litellm/proxy/example_config_yaml/bad_schema.prisma:/app/schema.prisma \
@@ -1648,6 +1713,7 @@ jobs:
zstd -d litellm-docker-database.tar.zst --stdout | docker load
docker tag litellm-docker-database:ci my-app:latest
- start_openai_record_replay_proxy
+ - start_fake_openai_endpoint
- run:
name: Run Docker container
command: |
@@ -1655,6 +1721,7 @@ jobs:
-p 4000:4000 \
-e DATABASE_URL=postgresql://postgres:postgres@host.docker.internal:5432/circle_test \
-e USE_PRISMA_MIGRATE=True \
+ -e FAKE_OPENAI_API_BASE=http://host.docker.internal:8190 \
-e AZURE_API_KEY=$AZURE_API_KEY \
-e REDIS_HOST=$REDIS_HOST \
-e REDIS_PASSWORD=$REDIS_PASSWORD \
@@ -1817,6 +1884,7 @@ jobs:
zstd -d litellm-docker-database.tar.zst --stdout | docker load
docker images | grep litellm-docker-database
- start_openai_record_replay_proxy
+ - start_fake_openai_endpoint
- run:
name: Run Docker container
# intentionally give bad redis credentials here
@@ -1830,6 +1898,7 @@ jobs:
-e REDIS_PORT=$REDIS_PORT \
-e LITELLM_MASTER_KEY="sk-1234" \
-e OPENAI_API_KEY=$OPENAI_API_KEY \
+ -e FAKE_OPENAI_API_BASE=http://host.docker.internal:8190 \
-e LITELLM_LICENSE=$LITELLM_LICENSE \
-e OTEL_EXPORTER="in_memory" \
-e AWS_ACCESS_KEY_ID=$AWS_ACCESS_KEY_ID \
@@ -1889,6 +1958,7 @@ jobs:
-e REDIS_PORT=$REDIS_PORT \
-e LITELLM_MASTER_KEY="sk-1234" \
-e OPENAI_API_KEY=$OPENAI_API_KEY \
+ -e FAKE_OPENAI_API_BASE=http://host.docker.internal:8190 \
-e LITELLM_LICENSE="bad-license" \
--add-host host.docker.internal:host-gateway \
--name my-app-3 \
@@ -1938,6 +2008,7 @@ jobs:
uv sync --frozen --all-groups --all-extras --python 3.12
- start_postgres
- start_redis
+ - start_fake_openai_endpoint
- attach_workspace:
at: ~/project
- run:
@@ -1961,6 +2032,7 @@ jobs:
-e REDIS_PORT=6379 \
-e LITELLM_MASTER_KEY="sk-1234" \
-e OPENAI_API_KEY=$OPENAI_API_KEY \
+ -e FAKE_OPENAI_API_BASE=http://host.docker.internal:8190 \
-e LITELLM_LICENSE=$LITELLM_LICENSE \
-e AWS_ACCESS_KEY_ID=$AWS_ACCESS_KEY_ID \
-e AWS_SECRET_ACCESS_KEY=$AWS_SECRET_ACCESS_KEY \
@@ -2020,6 +2092,7 @@ jobs:
command: |
uv sync --frozen --all-groups --all-extras --python 3.12
- start_postgres
+ - start_fake_openai_endpoint
- attach_workspace:
at: ~/project
- run:
@@ -2039,6 +2112,7 @@ jobs:
-e REDIS_PASSWORD=$REDIS_PASSWORD \
-e REDIS_PORT=$REDIS_PORT \
-e LITELLM_MASTER_KEY="sk-1234" \
+ -e FAKE_OPENAI_API_BASE=http://host.docker.internal:8190 \
-e LITELLM_LICENSE=$LITELLM_LICENSE \
-e USE_DDTRACE=True \
-e DD_API_KEY=$DD_API_KEY \
@@ -2060,6 +2134,7 @@ jobs:
-e REDIS_PASSWORD=$REDIS_PASSWORD \
-e REDIS_PORT=$REDIS_PORT \
-e LITELLM_MASTER_KEY="sk-1234" \
+ -e FAKE_OPENAI_API_BASE=http://host.docker.internal:8190 \
-e LITELLM_LICENSE=$LITELLM_LICENSE \
-e USE_DDTRACE=True \
-e DD_API_KEY=$DD_API_KEY \
@@ -2112,6 +2187,7 @@ jobs:
command: |
uv sync --frozen --all-groups --all-extras --python 3.12
- start_postgres
+ - start_fake_openai_endpoint
- attach_workspace:
at: ~/project
- run:
@@ -2129,6 +2205,7 @@ jobs:
-e DATABASE_URL=postgresql://postgres:postgres@host.docker.internal:5432/circle_test \
-e STORE_MODEL_IN_DB="True" \
-e LITELLM_MASTER_KEY="sk-1234" \
+ -e FAKE_OPENAI_API_BASE=http://host.docker.internal:8190 \
-e LITELLM_LICENSE=$LITELLM_LICENSE \
--add-host host.docker.internal:host-gateway \
--name my-app \
@@ -2187,6 +2264,7 @@ jobs:
command: |
docker build -t my-app:latest -f docker/build_from_pip/Dockerfile.build_from_pip .
- start_postgres
+ - start_fake_openai_endpoint
- run:
name: Run Docker container
# intentionally give bad redis credentials here
@@ -2200,6 +2278,7 @@ jobs:
-e REDIS_PORT=$REDIS_PORT \
-e LITELLM_MASTER_KEY="sk-1234" \
-e OPENAI_API_KEY=$OPENAI_API_KEY \
+ -e FAKE_OPENAI_API_BASE=http://host.docker.internal:8190 \
-e LITELLM_LICENSE=$LITELLM_LICENSE \
-e OTEL_EXPORTER="in_memory" \
-e AWS_ACCESS_KEY_ID=$AWS_ACCESS_KEY_ID \
diff --git a/.dockerignore b/.dockerignore
index a487d2a859a..f3a80fee3e4 100644
--- a/.dockerignore
+++ b/.dockerignore
@@ -49,6 +49,10 @@ build/
*.egg-info/
.DS_Store
**/node_modules
+ui/litellm-dashboard/.next
+ui/litellm-dashboard/out
+litellm-rust/target/
+litellm/rust_bridge/_native*.so
*.log
.env
.env.local
diff --git a/.git-blame-ignore-revs b/.git-blame-ignore-revs
index 23b520e2ad5..7e705ec4f8f 100644
--- a/.git-blame-ignore-revs
+++ b/.git-blame-ignore-revs
@@ -11,3 +11,9 @@
# style(ui): run prettier --write across the dashboard (#29622)
7edf3a9cb55548b143df1692f4ed7c4681d7fcf7
+
+# style: reformat litellm/ with ruff format (#31317)
+430b5b8f1b12dc261a49fda99ac5d1b22381a428
+
+# style: unify ruff format width on 120 (#31518)
+3dfbeabe626d203ac9de86024519d9a96c484ce4
diff --git a/.github/deploy-on-aws.png b/.github/deploy-on-aws.png
new file mode 100644
index 00000000000..06d41f2a5e0
Binary files /dev/null and b/.github/deploy-on-aws.png differ
diff --git a/.github/deploy-on-gcp.png b/.github/deploy-on-gcp.png
new file mode 100644
index 00000000000..e831a8c2e4e
Binary files /dev/null and b/.github/deploy-on-gcp.png differ
diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md
index 99f79c0b272..12ad124fa20 100644
--- a/.github/pull_request_template.md
+++ b/.github/pull_request_template.md
@@ -1,17 +1,17 @@
## Relevant issues
-
+
## Linear ticket
-
+
## Pre-Submission checklist
**Please complete all items before asking a LiteLLM maintainer to review your PR**
- [ ] I have added meaningful tests
-- [ ] My PR passes all unit tests on [`make test-unit`](https://docs.litellm.ai/docs/extras/contributing_code)
+- [ ] My PR passes all CI/CD checks (e.g., lint, format, unit tests)
- [ ] My PR's scope is as isolated as possible; it only solves 1 specific problem
- [ ] I have requested a Greptile review by commenting `@greptileai` and received a **Confidence Score of at least 4/5** before requesting a maintainer review
@@ -19,29 +19,13 @@
If you're seeing a delay in your PR being merged, ping the LiteLLM Team on [Slack (#pr-review)](https://join.slack.com/t/litellmossslack/shared_invite/zt-3o7nkuyfr-p_kbNJj8taRfXGgQI1~YyA).
-## CI (LiteLLM team)
-
-> **CI status guideline:**
->
-> - 50-55 passing tests: main is stable with minor issues.
-> - 45-49 passing tests: acceptable but needs attention
-> - <= 40 passing tests: unstable; be careful with your merges and assess the risk.
-
-- [ ] **Branch creation CI run**
- Link:
-
-- [ ] **CI run for the last commit**
- Link:
-
-- [ ] **Merge / cherry-pick CI run**
- Links:
-
## Screenshots / Proof of Fix
-
+
## Type
diff --git a/.github/scripts/_agent_shin_actions.py b/.github/scripts/_agent_shin_actions.py
new file mode 100644
index 00000000000..b3d1ff055b3
--- /dev/null
+++ b/.github/scripts/_agent_shin_actions.py
@@ -0,0 +1,50 @@
+"""Dry-run wrapper(s) around Agent Shin GitHub mutations.
+
+The rollout scripts currently need only one mutation wrapped, so this module
+exposes a single ``maybe_post_comment`` helper. It takes a ``dry_run: bool``
+keyword argument and the body is intentionally trivial:
+
+ if dry_run:
+ print(...) # log what we would do, return
+ return
+ real_mutation(...) # otherwise, actually do it
+
+That shape means a dry-run preview differs from the real run in exactly one
+line per side effect: the call site. So when you `python3 script.py` locally
+without ``--close``, you can be confident the actions printed are the ones the
+GitHub Action would have performed (modulo ordering on retry/error paths,
+which are deliberately simple). Any further mutation a rollout script needs
+should get the same ``maybe_*`` treatment instead of calling the raw
+``triage_with_llm`` mutation directly.
+
+Importing from this module pulls in the real mutation from ``triage_with_llm``
+— call sites in the rollout scripts should NEVER import ``post_comment``
+directly; that would skip the dry-run gate and is the bug class this module
+exists to prevent.
+"""
+
+from __future__ import annotations
+
+import sys
+import textwrap
+
+# Import the module itself rather than the bare names so monkeypatching
+# `triage_with_llm.post_comment` (or any of the other mutations) in tests is
+# reflected here — `from triage_with_llm import post_comment` would bind the
+# original function to a local name and bypass the patch, defeating the whole
+# point of these wrappers.
+import triage_with_llm
+
+
+def _log(line: str) -> None:
+ """Print a single dry-run line to stdout (one log statement per side effect)."""
+ print(line, file=sys.stdout, flush=True)
+
+
+def maybe_post_comment(repo: str, number: int, body: str, *, dry_run: bool) -> None:
+ """Post a comment on ``repo#number`` — or, in dry-run, log what we would post."""
+ if dry_run:
+ _log(f"[DRY RUN] comment {repo}#{number}:")
+ _log(textwrap.indent(body, " "))
+ return
+ triage_with_llm.post_comment(repo, number, body)
diff --git a/.github/scripts/agent_shin_shared.py b/.github/scripts/agent_shin_shared.py
new file mode 100644
index 00000000000..8f3dc3c2322
--- /dev/null
+++ b/.github/scripts/agent_shin_shared.py
@@ -0,0 +1,211 @@
+"""Constants and helpers shared by Agent Shin's triage scripts.
+
+Both `triage_with_llm.py` (the LLM-judge entrypoint) and
+`close_low_quality_prs.py` (the daily Greptile-score sweep) need to
+agree on the same notions of:
+
+ * What counts as a Greptile-authored review comment
+ (``GREPTILE_BOT_LOGINS``) and how to extract a confidence score from
+ its body (``SCORE_PATTERN`` / :func:`extract_greptile_score`).
+ * How long the 2-hour grace window is (``GRACE_PERIOD_SECONDS``) and
+ the HTML marker stamped into a grace-warning comment so the *other*
+ script can see "Agent Shin already warned" and behave accordingly
+ (``GRACE_COMMENT_MARKER``).
+ * Who Agent Shin is on GitHub (``AGENT_SHIN_DEFAULT_BOT_LOGIN``).
+ * How GitHub-style ISO-8601 timestamps round-trip into timezone-aware
+ :class:`datetime.datetime` (:func:`parse_iso8601`).
+
+Keeping these in one module means a future change (new Greptile output
+format, a longer grace window, a new allowlisted account) is a single edit
+instead of two — the original split version had to call out in comments
+that the two copies "must stay in sync" precisely because nothing
+enforced it.
+"""
+
+from __future__ import annotations
+
+import datetime as dt
+import json
+import os
+import re
+import subprocess
+from typing import Iterable
+
+GREPTILE_BOT_LOGINS = frozenset({"greptile-apps", "greptile-apps[bot]"})
+
+SCORE_PATTERN = re.compile(
+ r"confidence\s*score\s*[:\-]?\s*(\d+)\s*/\s*5",
+ re.IGNORECASE,
+)
+
+GRACE_COMMENT_MARKER = ""
+
+# Hidden HTML marker stamped on every Agent Shin auto-close comment (the LLM
+# judge's grace/review-gate close and the daily Greptile sweep's close).
+# `was_closed_by_agent_shin` requires this marker — not just the closing actor —
+# before `@agent-shin reconsider` may reopen, because the `github-actions[bot]`
+# identity is shared with every other workflow in the repo and is not unique to
+# Agent Shin. Both close paths must stamp it or the reconsider path silently
+# rejects the contributor.
+AGENT_SHIN_CLOSE_MARKER = ""
+
+# 2 hours between the grace warning and the auto-close. Short enough to
+# dogfood the "fix it before it closes" loop in one sitting; bump back up
+# (e.g. 86400 for a day) for the public rollout.
+GRACE_PERIOD_SECONDS = 7200
+
+AGENT_SHIN_DEFAULT_BOT_LOGIN = "github-actions[bot]"
+
+
+def _logins(*names: str) -> frozenset[str]:
+ """Build a login set normalized for case-insensitive membership checks.
+
+ Callers compare via ``login.lower() in ``, so the stored values
+ must be lowercase. Normalizing here lets the literals keep each
+ account's canonical GitHub casing (e.g. ``SwiftWinds``) for
+ readability without breaking the lookup.
+ """
+ return frozenset(name.lower() for name in names)
+
+
+# Dogfood rollout gate. While this set is non-empty, Agent Shin acts ONLY on
+# PRs/issues authored by these logins and skips everyone else. For an
+# allowlisted author the usual internal/external classification is bypassed, so
+# an internal account (e.g. a maintainer's own work login) still gets triaged
+# while the bot is being tested on a small set of accounts. Empty the set to
+# lift the restriction and restore full triage for the public rollout. Logins
+# are compared case-insensitively.
+ALLOWLIST_LOGINS = _logins("mateo-berri", "SwiftWinds")
+
+# `gh {pr,issue} list` has no "fetch everything" flag — `--limit` is the only
+# control and it defaults to 30. Pass a ceiling far above any realistic open
+# backlog (low thousands today) so gh paginates the API until the queue is
+# exhausted rather than silently truncating. The bulk sweeps MUST see the whole
+# backlog: gh lists newest-first, so a low cap drops the *oldest* PRs/issues —
+# exactly the stale ones a low-quality sweep is meant to catch.
+GH_LIST_ALL_LIMIT = 100_000
+
+
+def extract_greptile_score(comments: Iterable[dict]) -> tuple[int, dict] | None:
+ """Return (score, comment) for the most recent Greptile-authored comment
+ that contains a "Confidence Score: X/5". Returns None if no such comment.
+
+ "Most recent" is determined by the comment's `updated_at` (falling back to
+ `created_at`), so re-reviews override earlier passes.
+ """
+ candidates: list[tuple[str, int, dict]] = []
+ for comment in comments:
+ user = (comment.get("user") or {}).get("login", "")
+ if user not in GREPTILE_BOT_LOGINS:
+ continue
+ body = comment.get("body") or ""
+ match = SCORE_PATTERN.search(body)
+ if not match:
+ continue
+ score = int(match.group(1))
+ timestamp = comment.get("updated_at") or comment.get("created_at") or ""
+ candidates.append((timestamp, score, comment))
+
+ if not candidates:
+ return None
+
+ candidates.sort(key=lambda triple: triple[0])
+ _, score, comment = candidates[-1]
+ return score, comment
+
+
+def parse_iso8601(value: str) -> dt.datetime:
+ """Parse a GitHub ISO-8601 timestamp into a timezone-aware datetime."""
+ return dt.datetime.fromisoformat(value.replace("Z", "+00:00"))
+
+
+def gh(*args: str) -> str:
+ """Run a `gh` CLI command and return stdout. Raises on non-zero exit.
+
+ Shared by both Agent Shin entrypoints so a future change here
+ (timeout handling, logging, retry on transient failures) only needs
+ to be made once.
+ """
+ result = subprocess.run(
+ ["gh", *args],
+ capture_output=True,
+ text=True,
+ check=True,
+ )
+ return result.stdout
+
+
+def list_open_items(kind: str, *, repo: str | None, fields: str) -> list[dict]:
+ """Return EVERY open PR (``kind="pr"``) or issue (``kind="issue"``) in ``repo``.
+
+ Wraps ``gh {pr,issue} list`` with ``--limit GH_LIST_ALL_LIMIT`` so the full
+ backlog is fetched instead of the default 30 (or any other arbitrary cap).
+ Both bulk sweeps — the daily Greptile closer and the one-shot rollout
+ heads-up — rely on this seeing the whole queue, including the oldest items.
+
+ ``fields`` is the comma-separated ``--json`` field list the caller needs
+ (e.g. ``"number"`` for the rollout, the full set for the closer).
+ """
+ if kind not in ("pr", "issue"):
+ raise ValueError(f"kind must be 'pr' or 'issue', got {kind!r}")
+ repo_args = ["--repo", repo] if repo else []
+ raw = gh(
+ kind,
+ "list",
+ "--state",
+ "open",
+ "--limit",
+ str(GH_LIST_ALL_LIMIT),
+ "--json",
+ fields,
+ *repo_args,
+ )
+ return json.loads(raw)
+
+
+def seconds_since_latest_marker_comment(
+ comments: Iterable[dict],
+ *,
+ marker: str,
+ bot_login: str | None = None,
+ now: dt.datetime | None = None,
+) -> float | None:
+ """Return seconds since the bot's most recent comment containing ``marker``.
+
+ Filters comments by author so a contributor who quotes the HTML
+ marker (e.g. via GitHub's "Quote reply" feature, which preserves
+ HTML comments in the raw markdown of the quoted text) is not
+ mistaken for a bot warning — that would silently reset cooldown
+ timers and suppress legitimate notifications.
+
+ ``bot_login`` defaults to the `AGENT_SHIN_BOT_LOGIN` env override or
+ ``AGENT_SHIN_DEFAULT_BOT_LOGIN`` so callers normally don't need to
+ pass it. ``now`` is injectable for tests / callers (like the daily
+ sweep) that want every age calculation pinned to one snapshot.
+ """
+ expected_login = (
+ bot_login
+ or os.environ.get("AGENT_SHIN_BOT_LOGIN")
+ or AGENT_SHIN_DEFAULT_BOT_LOGIN
+ ).lower()
+ latest: dt.datetime | None = None
+ for comment in comments:
+ author = ((comment.get("user") or {}).get("login") or "").lower()
+ if author != expected_login:
+ continue
+ body = comment.get("body") or ""
+ if marker not in body:
+ continue
+ created = comment.get("created_at")
+ if not created:
+ continue
+ try:
+ ts = parse_iso8601(created)
+ except ValueError:
+ continue
+ if latest is None or ts > latest:
+ latest = ts
+ if latest is None:
+ return None
+ reference = now if now is not None else dt.datetime.now(dt.timezone.utc)
+ return (reference - latest).total_seconds()
diff --git a/.github/scripts/close_low_quality_prs.py b/.github/scripts/close_low_quality_prs.py
new file mode 100644
index 00000000000..7b9bbb579e3
--- /dev/null
+++ b/.github/scripts/close_low_quality_prs.py
@@ -0,0 +1,573 @@
+#!/usr/bin/env python3
+"""
+Auto-close low-quality pull requests.
+
+Closes open PRs (including drafts, regardless of age) that satisfy ALL of:
+ 1. Have a Greptile (`greptile-apps`) review comment whose latest
+ "Confidence Score: X/5" is below the configured threshold (default: 4).
+ 2. Are authored by an external OSS contributor (internal BerriAI
+ contributors are exempt).
+ 3. Do not carry an opt-out label (default: "do not close").
+
+`--min-age-days` is retained as an opt-in safety net for one-off backfill
+runs (default: 0). The team's intent is that the count of open PRs equals
+the count of PRs internal collaborators need to action on, so neither age
+nor draft status acts as a free pass.
+
+For each match, the script posts an explanatory comment and closes the PR.
+Because OSS contributors *cannot* reopen a PR closed by the bot/maintainer
+(GitHub limitation), the close-comment instructs them to push their fixes
+and **open a fresh PR**, or to comment `@agent-shin reconsider` on the
+closed PR to have the LLM judge re-evaluate (and reopen on pass).
+
+Requires the `gh` CLI to be authenticated.
+
+Usage examples:
+ # Dry run (default) - prints what would be closed
+ python3 close_low_quality_prs.py
+
+ # Actually close matching PRs
+ python3 close_low_quality_prs.py --close
+
+ # Restrict to PRs at least N days old (one-off backfill safety net)
+ python3 close_low_quality_prs.py --min-age-days 7 --min-score 4 --close
+"""
+
+from __future__ import annotations
+
+import argparse
+import datetime as dt
+import json
+import os
+import subprocess
+import sys
+from typing import Iterable
+
+# Add this script's directory to `sys.path` so the sibling
+# `agent_shin_shared` module is importable when the script is invoked
+# directly (e.g. `python3 .github/scripts/close_low_quality_prs.py ...`).
+sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
+
+from agent_shin_shared import ( # noqa: E402 -- sys.path adjusted above
+ AGENT_SHIN_CLOSE_MARKER,
+ ALLOWLIST_LOGINS,
+ GRACE_COMMENT_MARKER,
+ GRACE_PERIOD_SECONDS,
+ GREPTILE_BOT_LOGINS,
+ SCORE_PATTERN,
+ extract_greptile_score,
+ gh,
+ list_open_items,
+ parse_iso8601,
+ seconds_since_latest_marker_comment,
+)
+
+# `GREPTILE_BOT_LOGINS` and `SCORE_PATTERN` (Greptile's GitHub App login
+# variants and the "Confidence Score: X/5" regex) are imported from
+# `agent_shin_shared` so the LLM judge in `triage_with_llm.py` and this
+# daily Greptile sweep read the score through the same set of logins
+# and the same regex.
+
+# `author_association` values for internal BerriAI contributors who should be
+# exempt from auto-triage.
+INTERNAL_AUTHOR_ASSOCIATIONS = frozenset({"OWNER", "MEMBER", "COLLABORATOR"})
+
+# Default labels that exempt a PR from auto-close. Defined at module scope (not
+# as a mutable argparse default) so that `--optout-label foo` REPLACES the
+# defaults instead of appending to them — the argparse `action="append"` +
+# `default=[...]` combination silently mutates the shared default list.
+DEFAULT_OPTOUT_LABELS = ("do not close", "keep open", "wip")
+
+# `GRACE_COMMENT_MARKER` (HTML marker appended to grace-period warning
+# comments — used by either script to recognize that a warning was
+# already posted) and `GRACE_PERIOD_SECONDS` (length of the grace
+# period between the warning and the actual auto-close, 2 hours) are
+# imported from `agent_shin_shared` so the Agent Shin LLM judge and
+# this daily Greptile sweep agree on the same marker and duration.
+
+
+def fetch_open_prs(repo: str | None) -> list[dict]:
+ """Fetch all open PRs (number, createdAt, isDraft, labels, author).
+
+ Includes drafts: `gh pr list --state open` returns both ready-for-review
+ and draft PRs by default. This is the desired behavior — drafts are not
+ a free pass; the internal-collaborator open-PR queue should reflect every
+ PR that needs human attention regardless of draft status.
+ """
+ fields = "number,title,createdAt,isDraft,labels,author,url"
+ return list_open_items("pr", repo=repo, fields=fields)
+
+
+def fetch_pr_author_association(pr_number: int, repo: str | None) -> str:
+ """Return the GitHub `author_association` for a PR, uppercase.
+
+ Values: OWNER, MEMBER, COLLABORATOR, CONTRIBUTOR, FIRST_TIME_CONTRIBUTOR,
+ FIRST_TIMER, MANNEQUIN, NONE. Returns "" on lookup failure.
+ """
+ endpoint = (
+ f"repos/{repo}/pulls/{pr_number}"
+ if repo
+ else f"repos/{{owner}}/{{repo}}/pulls/{pr_number}"
+ )
+ try:
+ data = json.loads(gh("api", endpoint))
+ except subprocess.CalledProcessError:
+ return ""
+ return (data.get("author_association") or "").upper()
+
+
+def is_external_pr_author(pr: dict, repo: str | None) -> bool:
+ """Return True if the PR author is an external OSS contributor.
+
+ Internal = `OWNER` / `MEMBER` / `COLLABORATOR` association, or a bot login.
+ """
+ login = ((pr.get("author") or {}).get("login") or "").lower()
+ if login.endswith("[bot]") or login in {"dependabot", "github-actions"}:
+ return False
+ association = fetch_pr_author_association(pr["number"], repo)
+ # Fail-safe: if the API lookup failed (empty string), treat the author as
+ # internal so we don't auto-close their PR. Auto-close is destructive, so
+ # an unknown association should never make a PR eligible for closing.
+ if not association or association in INTERNAL_AUTHOR_ASSOCIATIONS:
+ return False
+ return True
+
+
+def fetch_pr_comments(pr_number: int, repo: str | None) -> list[dict]:
+ """Fetch issue-level comments on a PR (where Greptile posts its summary)."""
+ endpoint = (
+ f"repos/{repo}/issues/{pr_number}/comments?per_page=100"
+ if repo
+ else f"repos/{{owner}}/{{repo}}/issues/{pr_number}/comments?per_page=100"
+ )
+ raw = gh("api", "--paginate", endpoint)
+ comments: list[dict] = []
+ for line in raw.strip().splitlines():
+ line = line.strip()
+ if not line:
+ continue
+ try:
+ parsed = json.loads(line)
+ except json.JSONDecodeError:
+ # A malformed line should not blow up the whole sweep. Skip and
+ # carry on so the remaining PRs in this run still get evaluated.
+ continue
+ if isinstance(parsed, list):
+ comments.extend(parsed)
+ else:
+ comments.append(parsed)
+ return comments
+
+
+def has_optout_label(pr: dict, optout_labels: set[str]) -> bool:
+ labels = {label.get("name", "").lower() for label in pr.get("labels", [])}
+ return bool(labels & {lbl.lower() for lbl in optout_labels})
+
+
+def seconds_since_last_grace_warning(
+ comments: Iterable[dict],
+ *,
+ bot_login: str | None = None,
+ now: dt.datetime | None = None,
+) -> float | None:
+ """Return seconds since the bot's most recent grace-period warning, or
+ None if no such warning has ever been posted on this PR.
+
+ Thin wrapper over
+ `agent_shin_shared.seconds_since_latest_marker_comment` — the
+ centralized helper handles the bot-author filter, marker match,
+ timestamp parsing, and `now` injection. Keeping this wrapper
+ preserves the closer's "already-fetched comments + injectable now"
+ interface so callers (and tests) don't need to change.
+ """
+ return seconds_since_latest_marker_comment(
+ comments,
+ marker=GRACE_COMMENT_MARKER,
+ bot_login=bot_login,
+ now=now,
+ )
+
+
+def format_grace_warning_comment(score: int, threshold: int) -> str:
+ """Comment posted on the FIRST low-Greptile-score detection — gives
+ the contributor a 2-hour grace window before the auto-close fires on
+ the next daily cron run.
+
+ Mirrors `format_grace_warning_pr_comment` in
+ `triage_with_llm.py` in spirit (2-hour grace + escape hatches), but
+ framed around Greptile's confidence score instead of the LLM judge's
+ rubric since the close trigger here is the Greptile signal.
+ """
+ return (
+ "🚅 Hi, thanks for the PR! I'm **Agent Shin**, the automated triage bot for this "
+ "repository.\n"
+ "\n"
+ "Heads up: Greptile's most recent review scored this PR "
+ f"**{score}/5**, below our merge bar of **{threshold}/5**.\n"
+ "\n"
+ "If the score isn't lifted in the next **2 hours**, I'll auto-close this PR. That's "
+ "**not** us saying the change isn't worthwhile. We want the open-PR list to mirror "
+ "what a maintainer can act on *right now*, so contributors like you don't get lost in "
+ "a backlog. Take your time; everything below still works after the close.\n"
+ "\n"
+ "**During the grace period:** push fixes that address Greptile's feedback, then comment "
+ "`@greptileai` to request a fresh review. If "
+ f"the new score is **{threshold}/5 or higher**, the PR stays open and no further "
+ "action is needed on your side.\n"
+ "\n"
+ "**If the PR does get auto-closed in 2 hours, you still have an easy recovery path:**\n"
+ "\n"
+ "- Comment `@greptileai` to request a fresh review. **This still works even after "
+ f"the PR is closed**, and a score of {threshold}/5 or higher is one of the signals "
+ "that lifts the PR back into the review queue. A low Greptile score isn't a blocker.\n"
+ "- Comment `@agent-shin reconsider` after pushing fixes; I'll re-run the rubric and "
+ "reopen the PR if both gates (description rubric + Greptile score) now pass.\n"
+ "\n"
+ f"{GRACE_COMMENT_MARKER}"
+ )
+
+
+def post_grace_warning(
+ pr: dict,
+ score: int,
+ threshold: int,
+ repo: str | None,
+ dry_run: bool,
+) -> None:
+ """Post the 2-hour grace-period warning comment on `pr`.
+
+ The warning carries `GRACE_COMMENT_MARKER` so subsequent runs can
+ detect that the contributor has already been told about the
+ pending close. Does NOT close the PR — the close happens on the
+ next eligible run after `GRACE_PERIOD_SECONDS` elapses (handled
+ by `close_pr`).
+ """
+ pr_number = pr["number"]
+ repo_args = ["--repo", repo] if repo else []
+
+ if dry_run:
+ print(
+ f" [DRY RUN] Would post grace warning to PR #{pr_number} "
+ f"(greptile={score}/5): {pr['title']}"
+ )
+ return
+
+ comment_body = format_grace_warning_comment(score, threshold)
+ gh("pr", "comment", str(pr_number), "--body", comment_body, *repo_args)
+ print(f" Posted grace warning on PR #{pr_number} (greptile={score}/5)")
+
+
+def format_close_comment(score: int, threshold: int) -> str:
+ """Comment posted when a low-Greptile-score PR is auto-closed.
+
+ Carries `AGENT_SHIN_CLOSE_MARKER` so the `@agent-shin reconsider` path
+ (guarded by `was_closed_by_agent_shin`) recognizes this as an Agent Shin
+ close and is allowed to reopen the PR once it passes again; without the
+ marker that recovery path the comment advertises silently rejects the
+ contributor.
+ """
+ score_sentence = (
+ f"Greptile's most recent review scored this PR **{score}/5**, below "
+ f"our merge bar of **{threshold}/5**, and the 2-hour grace period since "
+ "the warning has elapsed.\n\n"
+ )
+ return (
+ f"Closing as part of automated PR triage.\n\n"
+ f"{score_sentence}"
+ "We close low-confidence PRs aggressively to keep the review queue "
+ "manageable for maintainers and contributors alike. **This is not a "
+ "rejection of the idea.** To bring this back:\n\n"
+ "1. Push the fixes that address Greptile's feedback (continue using "
+ "your existing branch is fine).\n"
+ "2. **Open a new PR** with the updated branch. Greptile will review "
+ "it again, and if it scores "
+ f"**{threshold}/5 or higher** a maintainer will take another look.\n\n"
+ "_Why open a new PR instead of reopening this one?_ GitHub does not "
+ "let external contributors reopen a PR that was closed by a bot or "
+ "maintainer, so a fresh PR is the most reliable path forward. If you "
+ "would prefer this exact PR re-evaluated, comment "
+ "`@agent-shin reconsider` once you've pushed the fixes; Agent Shin "
+ "will re-run triage and reopen this PR if it now meets the bar. "
+ "You can also comment `@greptileai` to request a fresh Greptile "
+ "review; that works **even after the PR is closed**.\n\n"
+ "Thanks for contributing to LiteLLM. We know auto-closures can sting; "
+ "the goal is to keep the project healthy, not to dismiss your work."
+ f"\n\n{AGENT_SHIN_CLOSE_MARKER}"
+ )
+
+
+def close_pr(
+ pr: dict,
+ score: int,
+ threshold: int,
+ age_days: int,
+ repo: str | None,
+ dry_run: bool,
+ label: str | None,
+) -> None:
+ """Post the explanatory comment and close the PR."""
+ pr_number = pr["number"]
+ repo_args = ["--repo", repo] if repo else []
+
+ if dry_run:
+ print(
+ f" [DRY RUN] Would close PR #{pr_number} "
+ f"(age={age_days}d, greptile={score}/5): {pr['title']}"
+ )
+ return
+
+ comment_body = format_close_comment(score, threshold)
+ gh("pr", "comment", str(pr_number), "--body", comment_body, *repo_args)
+
+ if label:
+ try:
+ gh("pr", "edit", str(pr_number), "--add-label", label, *repo_args)
+ except subprocess.CalledProcessError as exc:
+ stderr = (exc.stderr or "").strip()
+ print(f" warn: failed to add label '{label}' to #{pr_number}: {stderr}")
+
+ gh("pr", "close", str(pr_number), *repo_args)
+ print(f" Closed PR #{pr_number} (greptile={score}/5, age={age_days}d)")
+
+
+def evaluate_pr(
+ pr: dict,
+ now: dt.datetime,
+ min_age_days: int,
+ min_score: int,
+ repo: str | None,
+ optout_labels: set[str],
+ allowlist: frozenset[str] = ALLOWLIST_LOGINS,
+) -> tuple[str, int | None, int | None]:
+ """Decide what to do with `pr` on this triage run.
+
+ Returns (action, score_or_none, age_days_or_none) where action is one of:
+ "skip-too-young", "skip-optout-label", "skip-not-allowlisted",
+ "skip-internal", "skip-no-greptile-score", "skip-score-ok",
+ "warn-grace", "skip-in-grace-period", or "close".
+
+ Drafts are NOT skipped — the goal is "open PR count == PRs internal
+ collaborators need to action on", and a draft that Greptile scored <4/5
+ is still in that queue. Authors can opt out via the `wip` label (see
+ `DEFAULT_OPTOUT_LABELS`) if they need to keep a long-lived draft open.
+
+ Grace-period semantics: the first time a PR fails the rubric, the
+ action is `warn-grace` — the caller should post a warning comment but
+ NOT close the PR. On a subsequent run, if the warning is still less
+ than `GRACE_PERIOD_SECONDS` old AND the PR still fails, the action is
+ `skip-in-grace-period`. Once the warning ages out and the rubric is
+ still failing, the action is `close`.
+ """
+ if has_optout_label(pr, optout_labels):
+ return ("skip-optout-label", None, None)
+
+ created = parse_iso8601(pr["createdAt"])
+ age_days = (now - created).days
+ # `min_age_days` defaults to 0 (close as soon as Greptile scores low).
+ # Set a positive value via --min-age-days for one-off backfill runs that
+ # want to skip very-young PRs.
+ if min_age_days > 0 and age_days < min_age_days:
+ return ("skip-too-young", None, age_days)
+
+ # While the allowlist is active it is the sole author gate: only those
+ # logins are acted on and the external-only restriction is bypassed for
+ # them. Otherwise auto-close only external OSS contributors — internal
+ # contributors (BerriAI org members) handle their own backlog.
+ login = ((pr.get("author") or {}).get("login") or "").lower()
+ if allowlist:
+ if login not in allowlist:
+ return ("skip-not-allowlisted", None, age_days)
+ elif not is_external_pr_author(pr, repo):
+ return ("skip-internal", None, age_days)
+
+ comments = fetch_pr_comments(pr["number"], repo)
+ extraction = extract_greptile_score(comments)
+ if extraction is None:
+ return ("skip-no-greptile-score", None, age_days)
+
+ score, _ = extraction
+ if score >= min_score:
+ return ("skip-score-ok", score, age_days)
+
+ grace_age = seconds_since_last_grace_warning(comments, now=now)
+ if grace_age is None:
+ return ("warn-grace", score, age_days)
+ if grace_age < GRACE_PERIOD_SECONDS:
+ return ("skip-in-grace-period", score, age_days)
+
+ return ("close", score, age_days)
+
+
+def main() -> int:
+ parser = argparse.ArgumentParser(description=__doc__)
+ parser.add_argument(
+ "--repo",
+ type=str,
+ default=None,
+ help="Repository (owner/repo). Auto-detected if omitted.",
+ )
+ parser.add_argument(
+ "--min-age-days",
+ type=int,
+ default=0,
+ help=(
+ "Minimum age (in days) before a PR is eligible. Default 0 = "
+ "close as soon as Greptile flags it. Set a positive value for "
+ "one-off backfill runs that want to spare very-young PRs."
+ ),
+ )
+ parser.add_argument(
+ "--min-score",
+ type=int,
+ default=4,
+ choices=range(1, 6),
+ help="Greptile score below which a PR is closed (default: 4 -> closes <4/5).",
+ )
+ parser.add_argument(
+ "--optout-label",
+ action="append",
+ default=None,
+ help=(
+ "Label(s) that exempt a PR from auto-close. Repeat to add more. "
+ "Case-insensitive. When omitted, defaults to "
+ f"{list(DEFAULT_OPTOUT_LABELS)!r}; passing this flag REPLACES the "
+ "defaults (argparse `append` with a mutable default would append "
+ "instead, which we explicitly avoid)."
+ ),
+ )
+ parser.add_argument(
+ "--close-label",
+ type=str,
+ default=None,
+ help=(
+ "Optional label to add to PRs that get auto-closed "
+ "(e.g. 'auto-closed-low-quality'). Must already exist on the repo."
+ ),
+ )
+ parser.add_argument(
+ "--close",
+ action="store_true",
+ help="Actually close matching PRs (default is dry-run).",
+ )
+ parser.add_argument(
+ "--limit",
+ type=int,
+ default=None,
+ help="Maximum number of PRs to close in one run (safety net).",
+ )
+ args = parser.parse_args()
+
+ dry_run = not args.close
+ if dry_run:
+ print("=== DRY RUN MODE (pass --close to actually close PRs) ===\n")
+
+ print("Fetching open PRs...")
+ prs = fetch_open_prs(args.repo)
+ print(f"Found {len(prs)} open PRs.\n")
+
+ now = dt.datetime.now(dt.timezone.utc)
+ optout_labels = set(args.optout_label or DEFAULT_OPTOUT_LABELS)
+
+ closed = 0
+ summary = {
+ "close": 0,
+ "warn-grace": 0,
+ "skip-in-grace-period": 0,
+ "skip-too-young": 0,
+ "skip-optout-label": 0,
+ "skip-not-allowlisted": 0,
+ "skip-internal": 0,
+ "skip-no-greptile-score": 0,
+ "skip-score-ok": 0,
+ }
+
+ # `warned` tracks grace-warning comments posted in this run so the
+ # `--limit` safety net bounds *all* destructive write actions, not
+ # just closures. Without this cap, a backlog of PRs failing the
+ # threshold simultaneously could flood contributors with comments.
+ warned = 0
+ for pr in sorted(prs, key=lambda p: p["createdAt"]):
+ try:
+ action, score, age_days = evaluate_pr(
+ pr,
+ now,
+ args.min_age_days,
+ args.min_score,
+ args.repo,
+ optout_labels,
+ )
+ summary[action] = summary.get(action, 0) + 1
+
+ if action == "warn-grace":
+ assert score is not None
+ print(
+ f"#{pr['number']}: \"{pr['title']}\" "
+ f"(age={age_days}d, greptile={score}/5) -> warn-grace"
+ )
+ post_grace_warning(
+ pr,
+ score=score,
+ threshold=args.min_score,
+ repo=args.repo,
+ dry_run=dry_run,
+ )
+ if not dry_run:
+ warned += 1
+ if args.limit is not None and (warned + closed) >= args.limit:
+ print(
+ f"\nReached --limit={args.limit} "
+ f"(closed={closed}, warned={warned}); stopping."
+ )
+ break
+ continue
+
+ if action != "close":
+ continue
+
+ assert score is not None and age_days is not None
+ print(
+ f"#{pr['number']}: \"{pr['title']}\" "
+ f"(age={age_days}d, greptile={score}/5) -> close"
+ )
+ close_pr(
+ pr,
+ score=score,
+ threshold=args.min_score,
+ age_days=age_days,
+ repo=args.repo,
+ dry_run=dry_run,
+ label=args.close_label,
+ )
+
+ if not dry_run:
+ closed += 1
+ if args.limit is not None and (warned + closed) >= args.limit:
+ print(
+ f"\nReached --limit={args.limit} "
+ f"(closed={closed}, warned={warned}); stopping."
+ )
+ break
+ except Exception as exc: # noqa: BLE001 - per-PR errors don't abort the sweep
+ summary["error"] = summary.get("error", 0) + 1
+ print(
+ f"!! PR #{pr.get('number')}: {exc}",
+ file=sys.stderr,
+ )
+ continue
+
+ print("\n=== Summary ===")
+ for key, value in summary.items():
+ print(f" {key:28s} {value}")
+ if dry_run:
+ print(f"\nTotal would close: {summary['close']}")
+ else:
+ print(f"\nTotal closed: {closed}")
+ print(
+ f"Total {'would warn (grace)' if dry_run else 'warned (grace)'}: "
+ f"{summary['warn-grace']}"
+ )
+ return 0
+
+
+if __name__ == "__main__":
+ sys.exit(main())
diff --git a/.github/scripts/triage-requirements.txt b/.github/scripts/triage-requirements.txt
new file mode 100644
index 00000000000..a18f05fbb95
--- /dev/null
+++ b/.github/scripts/triage-requirements.txt
@@ -0,0 +1,282 @@
+# Hash-pinned dependency set for the Agent Shin triage scripts.
+# Installed in privileged triage workflows, so every package is pinned to an
+# exact version with SHA-256 hashes and installed with pip --require-hashes.
+#
+# Regenerate after bumping openai:
+# echo 'openai==' \
+# | uv pip compile - --generate-hashes --python-version 3.12 \
+# --no-annotate --no-header -o .github/scripts/triage-requirements.txt
+
+annotated-types==0.7.0 \
+ --hash=sha256:1f02e8b43a8fbbc3f3e0d4f0f4bfc8131bcb4eebe8849b8e5c773f3a1c582a53 \
+ --hash=sha256:aff07c09a53a08bc8cfccb9c85b05f1aa9a2a6f23728d790723543408344ce89
+anyio==4.14.0 \
+ --hash=sha256:b47c1f9ccf73e67021df785332508f99379c68fa7d0684e8e3492cb1d4b23f89 \
+ --hash=sha256:dd9b7a2a9799ed6552fde617b2c5df02b7fdd7d88392fc48101e51bae46164d9
+certifi==2026.6.17 \
+ --hash=sha256:024c88eeec92ca068db80f02b8b07c9cef7b9fe261d1d535abfd5abd6f6af432 \
+ --hash=sha256:2227dcbaafe0d2f59279d1762ddddc37783ed4354594f194ffc31d20f41fc3db
+distro==1.9.0 \
+ --hash=sha256:2fa77c6fd8940f116ee1d6b94a2f90b13b5ea8d019b98bc8bafdcabcdd9bdbed \
+ --hash=sha256:7bffd925d65168f85027d8da9af6bddab658135b840670a223589bc0c8ef02b2
+h11==0.16.0 \
+ --hash=sha256:4e35b956cf45792e4caa5885e69fba00bdbc6ffafbfa020300e549b208ee5ff1 \
+ --hash=sha256:63cf8bbe7522de3bf65932fda1d9c2772064ffb3dae62d55932da54b31cb6c86
+httpcore==1.0.9 \
+ --hash=sha256:2d400746a40668fc9dec9810239072b40b4484b640a8c38fd654a024c7a1bf55 \
+ --hash=sha256:6e34463af53fd2ab5d807f399a9b45ea31c3dfa2276f15a2c3f00afff6e176e8
+httpx==0.28.1 \
+ --hash=sha256:75e98c5f16b0f35b567856f597f06ff2270a374470a5c2392242528e3e3e42fc \
+ --hash=sha256:d909fcccc110f8c7faf814ca82a9a4d816bc5a6dbfea25d6591d6985b8ba59ad
+idna==3.18 \
+ --hash=sha256:7f952cbe720b688055e3f87de14f5c3e5fdaa8bc3928985c4077ca689de849a2 \
+ --hash=sha256:ffb385a7e039654cef1ab9ef32c6fafe283c0c0467bba1d9029738ce4a14a848
+jiter==0.15.0 \
+ --hash=sha256:01a8222cf05ab1128e239421156c207949808acaaea2bdfd33130ae666786e86 \
+ --hash=sha256:032396229564bca02440396bd327710719f724f5e7b7e9f7a8eb3faa4a2c2281 \
+ --hash=sha256:04b400bbf8c9efb03d9bdd976475c919c1d85593b04b9fff7ae234065daf87ae \
+ --hash=sha256:05906b93d72f03339e6bb7cf8dc10ebda64a0266126eed6beba79e20abcf5fd4 \
+ --hash=sha256:066f8f33f18b2419cd8213b2436fa7fbc9c499f315971cfa3ce1f9820c001b1b \
+ --hash=sha256:0ab068bce62a45aa3e7367eceaffb5dde60b7eb853be8dece45132e3d0ff4879 \
+ --hash=sha256:0be6f5ad41a809f303f416d17cec92a7a725902fb9b4f3de3d19362ac0ef8554 \
+ --hash=sha256:0e90a1c315a0226ec822d973817967f9223b7701546c8c2a7913e7ab0926294d \
+ --hash=sha256:0f862193b8696249d22ec433e85fd2ab0ad9596bc3e45e6c0bc55e8aeba97be2 \
+ --hash=sha256:1303d4d68a9b051ea90502402063ecf3807da00ad2affa19ca1ae3b90b3c5f67 \
+ --hash=sha256:144f8e72cb53dab146347b91cceac01f5481237f2b93b4a339a1ee8f8878b67c \
+ --hash=sha256:182226cbc930c9fab81bc2e41a4da672f89539906dadb05e75670ac07b94f71f \
+ --hash=sha256:1c11465f97e2abf45a014b83b730222f8f1c5335e802c7055a67d50de6f1f4e3 \
+ --hash=sha256:1c15024a3d892223b18f597c86d59387249dc396590844ce6b9f6131d1093bae \
+ --hash=sha256:1d54fb5b31dea401a41af3f8a7d2512e9b6a6a005491e6166c7e4ffab9639a9c \
+ --hash=sha256:25ffbe229aa8cd98c28879d8aa1a6e34ae77992ab984a65fba800859dab16269 \
+ --hash=sha256:2a77aadd57cac1682e4401a72724d2796d89a4ba129b1a5812aa94ee480826eb \
+ --hash=sha256:2ae901f3a55bfafdde31d289590fa25e3245735a2b1e8c7cc15871710a002871 \
+ --hash=sha256:2b0074e2f56eb2dacca1689760fd2852a068f85a0547a157b82cb4cafeb6768b \
+ --hash=sha256:2c8aea7781d2a372227871de4e1a1332aa96f5a89fd76c5e835dafdbad102887 \
+ --hash=sha256:2c9cb907439d20bd0c7d7565ca01ee52234203208433749bae5b516907526928 \
+ --hash=sha256:2fb6a5d26af81fc0f00f9360a891e05cf755e149bba391c4d563adc54812973d \
+ --hash=sha256:2fd73e3da91a0a722d67165e849ce2cdc10de0e0d48738c142be8c6c5f310f4c \
+ --hash=sha256:30ce1a5d16b5641dc935d50ef775af6a0871e3d14ab05d6fc54dff371b78e558 \
+ --hash=sha256:30ce785d2adb8e32c3f7741442370a74834ec4c01f3c48f0750227a0b4ef27d6 \
+ --hash=sha256:30f2218e6a9e5c18bc10fe6d41ac189c442c88eacf11bad9f28ef95a9bef00e6 \
+ --hash=sha256:351a341c2105aa430b7047e30f1bf7975f6313b00165d3fc07be2edaf741f279 \
+ --hash=sha256:37a10c377ce3a4a85f4a67f28b7afe093154cde77eaf248a72e856aa08b4d865 \
+ --hash=sha256:392b8ab019e5502d08aff85c6272209c24bc2cbe706ea82a56368f524236614a \
+ --hash=sha256:3e4540b8e74e4268811ac05db226a6a128ff572e7e0ce3f1163b693cadb184cd \
+ --hash=sha256:40b2c7e92c44a84d748d21706c68dc6ff8161d80b59c99d774721a0d2317d7c7 \
+ --hash=sha256:411fa4dfa5a7ae3d11491027ffb9beadec3996010a986862db70d91abba1c750 \
+ --hash=sha256:4251acc80e2b7c9b7b8823456ea0fceeb0734dac2df7636d3c711b38476b5a76 \
+ --hash=sha256:42bfb257930800cf43e7c62c832402c704ab60797c992faf88d20e903eac8f32 \
+ --hash=sha256:4363818355dbc70ae1a8e9eaba9de350d93ede4ff6992b8f8eb8cbb6e5122d42 \
+ --hash=sha256:4ab395feec8d249ec4044e228e98a7033f043426a265df439dc3698823f0a4e4 \
+ --hash=sha256:50164d7610c00e7cd913a873fce30b6beeebf4b37e53983e33f22de4c900f6b8 \
+ --hash=sha256:50e51156192722a9c58db112837d3f8ef96fb3c5ecc14e95f409134b08b158ec \
+ --hash=sha256:510c8b3c17a0ed9ac69850c0438dada3c9b82d9c4d589fcb62002a5a9cf3a866 \
+ --hash=sha256:5157de9f76eb4bc5ea74a1219366a25f945ad305641d74e04f59c54087091aa9 \
+ --hash=sha256:54d5d6090cdc1b7c9e780dfb04949a990adb1e301a2fc0bbcee7de4638d33f9a \
+ --hash=sha256:553fcac2ef2cb990877f9fc0833b8b629a3e6a5670b6b5fd58219b41a653ddc4 \
+ --hash=sha256:5607e6013ed7e6b0ec9661e467b7ffde0aa7ab36833a04850f26fcf88ed4845b \
+ --hash=sha256:5d6a60072b44c3c2b797a7ddcbcbbf2b34ea3cfd4721580fbfd2a09d9d9b84ba \
+ --hash=sha256:5f30bae8bc1c2d613e28e5af3e8cceb09b742f1c8a8a5f839fb67afaffc03b61 \
+ --hash=sha256:62ebd14e47e9aed9df4472afcb2663668ce4d74891cd54f86bf6e44029d6dc89 \
+ --hash=sha256:631f13a3d04e97d4e083993b10f4b99530e3a10d953e2eb5e196b7dc7f812ce0 \
+ --hash=sha256:6550fa135c7deb8ead6af49ed7ff648532ea8334a1447fe34a36315ef79c5c29 \
+ --hash=sha256:66b1880df2d01e206e8339769d1c7c1753bcb653efd6289e203f6f24ebada0c0 \
+ --hash=sha256:6eac374c5c975709b69c10f09afd199df74150172156ad10c8d4fd785b7da995 \
+ --hash=sha256:71683c38c825452999b5717fcae07ea708e8c93003e808be4319c1b02e3d176e \
+ --hash=sha256:7553333dd0930c104a5a0db8df72bf7219fe663d731383b576bb6ed6351c984d \
+ --hash=sha256:75e8a04e91432dde9f1838373cf93d23726c79d3e908d319acf0e796f85592e7 \
+ --hash=sha256:773b6eb282ce11ee19f05f6b2d4404fa308e5bbd353b0b80a0262caad6db2cd7 \
+ --hash=sha256:774f93f65031856bf14ad9f59bdcab8b8cad501e5ceabd51ba3525f76937a25b \
+ --hash=sha256:7c468136b8bd6bb18c8786e4236a1fa27362f24cb23450ba0cb204ab379b8e6f \
+ --hash=sha256:7ce8902f939970048b233087082e7bb829db29375811c7ad50687b8624c6fd08 \
+ --hash=sha256:7d3d6683288c11cbab50e865f2e2f13950179aa45410e30b2cfbd3fb7b0177bf \
+ --hash=sha256:7f6163c0f10b055245f814dcc59f4818da60dfe72f3e72ab89fc24b6bd5e9c52 \
+ --hash=sha256:8020c99ec13a7db2b6f96cbe82ef4721c88b426a4892f27478044af0284615ef \
+ --hash=sha256:813dfbb17d65328bf86e5f0905dd277ba2265d3ca20556e86c0c7035b7182e5a \
+ --hash=sha256:860a74063284a2ae9bfedd694f299cc2c68e2696c5f3d440cc9d18bb81b9dd04 \
+ --hash=sha256:8c9004af7c8d67cce7f1aae1026fb55607f4aa600710d08ede3a3ce4aeefe7e0 \
+ --hash=sha256:8d2c0c44d569ce0f2850f5c926f8caeb5f245fbc84475aeb36efccc2103e6dbd \
+ --hash=sha256:8f7e9bc0f1135039b22ee6eab588d42df1ce55842b30740a352885eb267bd941 \
+ --hash=sha256:90c5db5527c221249a876160663ab891ace358c17f7b9c93ec1478b7f0550e5c \
+ --hash=sha256:9100ddbec09741cc66feb0fc6773f8bdbd0e3c345689368f260082ff85dcc0cd \
+ --hash=sha256:913d02d29c9606643418d9ccfc3b72492ab25a6bf7889934e09a3490f8d3438b \
+ --hash=sha256:980c256edb05b78a111b99c4de3b1d32e31634b867fd1fc2cf726e7b7bba9854 \
+ --hash=sha256:9f924585cdacf631cd382b657966847bb537bf9ed0a6f9b991da5f05a631480f \
+ --hash=sha256:a254e10b593624d230c365b6d616b22ca0ad65e63a16e6631c2b3466022e6ba8 \
+ --hash=sha256:a2a438005b6f22d0273413484d6094d7c2c5d10ec1b3a3bf128e0d1d3ba53258 \
+ --hash=sha256:a97261f1fccb8e50ecd2890a96e46efdc3f57c80a197324c6777827231eca712 \
+ --hash=sha256:ab596fa3837e91e7e6a31b5f639988bfc6a35d1f915ac3932d946062219d588f \
+ --hash=sha256:abbf258599526ad0326fe51e252e24f2bd6f24f1852681b4b78feda3808f1d18 \
+ --hash=sha256:ac0d9ddea4350974be7a221fc25895f251a8fee748c889bdced2141c0fec1a49 \
+ --hash=sha256:acf4ee4d1fc55917239fe72972fb292dd773055d05eb040d36f4326e02cc2c0e \
+ --hash=sha256:ae1b0d82ac2d987f9ea512b1c9adfcc71a28de3dea3a6039b54d76cffda9901e \
+ --hash=sha256:b15741f501469009ae0ae90b7147958a664a7dede40aa7ff174a8a4645f546d0 \
+ --hash=sha256:b15d3ec9b0449c40e85319bdb4caa8b77ab526e74f5532ed94bec15e2f66822c \
+ --hash=sha256:b3b3b775e33d3bfaec9899edc526ae97b0da0bf9d071a46124ba419149a414f8 \
+ --hash=sha256:b6c0ffae686c39bf3737be60793783267628783ea42545632c10b291105aee45 \
+ --hash=sha256:c210f8b35dc6f30aafd4b4365ca89b9d1189f21ab49b8e68fa6322a847aef138 \
+ --hash=sha256:c2f6bb8b5216ab9e7873bc08b5d7bef2b8abbb578a3069bf1cd14a45d71d771d \
+ --hash=sha256:c60e71b6d10cfc284c9bf36bd885e8d44c46f688ce50aa91b5edd90181dea687 \
+ --hash=sha256:c6694a173ecabc12eb60efbc0b474464ead1951ff65cd8b1e72100715c64512b \
+ --hash=sha256:c77496cb10bd7549690fbbab3e5ec05857b83e49276f4a9423a766ddd2afcd4c \
+ --hash=sha256:c84c1b7be454b0c16f8499b4ebfbfd82ea5cca6527cceefcbbc06a7557b5ed2e \
+ --hash=sha256:cc0bc345cf2df9d1c00ac443f50d543c1ccfa8b0422cb85b1ab70d681c0b255b \
+ --hash=sha256:ceb8fc27d38793f9c97149be8302720c5b22e5c195a37bf2c45dc36c4600a512 \
+ --hash=sha256:cf4bd113a69c0a740e27cb962ce10630c36d2b8f59d759a651b955ee9d18a823 \
+ --hash=sha256:d1aa62e277fc1cbd80e6deacae6f4d983b41b3d7728e0645c5d741a6149bba45 \
+ --hash=sha256:d1e7b1776f0797956c509e123d0952d10d293a9492dea9f288ab9570ec01d1a5 \
+ --hash=sha256:d636d5095155afd364247f65070fab7beda13498d7ff4de331046e704ab9657f \
+ --hash=sha256:d726e3ceeb337191324b49de298142f27c3ad10886341555d1d5315b5f252c6a \
+ --hash=sha256:d72d8af5c1013656a8870c866660627d1a75bc185814ee022c8533caa1de88ae \
+ --hash=sha256:d8d2955167274e15d79a7a020afdd9b39c990eb80b2d89fca695d92dcfdd38ec \
+ --hash=sha256:d92a5cd21fdb083931d546c207aa29633787c5dc5b02daab2d32b843f88a2c53 \
+ --hash=sha256:e58585a58209d72691ce2d62a9147445f5a87beb0bde97fde284c96ae392a3d1 \
+ --hash=sha256:e7196e56f1cd69af1dbb07dff02dcfb260a50b45a82d409d92a06fedb32473b5 \
+ --hash=sha256:eda3071db3346334beae1360b46da4606da57bf3528c167b3c38533afaf9f2c5 \
+ --hash=sha256:edebcf7d1f601199084bb6e844d7dc67e03e04f6ac786b0332d616635c4ff7a4 \
+ --hash=sha256:ef1fd24d9413f6209e00d3d5a453e67acfe004a25cc6c8e8484faed4311ab9e8 \
+ --hash=sha256:f0b271b462769543716f92d3a4f90527df6ef5ed05ee95ec4137f513e21e1b77 \
+ --hash=sha256:f18f85e4218d1b40f000f42a92239a7a61a902cd42c65e6c360dbd17dcb20894 \
+ --hash=sha256:f1e1754960f38ec40613a07e5e372df67acb3b890fb383b6fb3de3e49ddbf3c7 \
+ --hash=sha256:f2143ab06181d2b029eedcb6af3cebe95f11bbac62441781860f98ee9330a6a6 \
+ --hash=sha256:f3d37768fce7f88dd2a8c6091f2325dea27d30d30d5c6e7a1c0f0af77723b708 \
+ --hash=sha256:fa248c9eb220197d363f688818dac2fd4b2f0cd7d843ca7105d652034823427d
+openai==2.33.0 \
+ --hash=sha256:03ac37d70e8c9e3a8124214e3afa785e2cbc12e627fbd98177a086ef2fd87ad5 \
+ --hash=sha256:f850c435e2a4685bba3295bd54912dd26315d9c1b7733068186134d6e0599f9a
+pydantic==2.13.4 \
+ --hash=sha256:45a282cde31d808236fd7ea9d919b128653c8b38b393d1c4ab335c62924d9aba \
+ --hash=sha256:c40756b57adaa8b1efeeced5c196f3f3b7c435f90e84ea7f443901bec8099ef6
+pydantic-core==2.46.4 \
+ --hash=sha256:00c603d540afdd6b80eb39f078f33ebd46211f02f33e34a32d9f053bba711de0 \
+ --hash=sha256:0186750b482eefa11d7f435892b09c5c606193ef3375bcf94aa00ae6bfb66262 \
+ --hash=sha256:041bde0a48fd37cf71cab1c9d56d3e8625a3793fef1f7dd232b3ff37e978ecda \
+ --hash=sha256:0c563b08bca408dc7f65f700633d8442fffb2421fc47b8101377e9fd65051ff0 \
+ --hash=sha256:0cbe8b01f948de4286c74cdd6c667aceb38f5c1e26f0693b3983d9d74887c65e \
+ --hash=sha256:0ce40cd7b21210e99342afafbd4d0f76d784eb5b1d60f3bdc566be4983c6c73b \
+ --hash=sha256:0e96592440881c74a213e5ad528e2b24d3d4f940de2766bed9010ab1d9e51594 \
+ --hash=sha256:10e17cbb10a330363733efc4d7c4d0dd827ac0909b8f6a6542298fed1ea62f29 \
+ --hash=sha256:133878133d271ade3d41d1bfb2a45ec38dbdbda40bc065921c6b04e4630127e2 \
+ --hash=sha256:14d4edf427bdcf950a8a02d7cb44a08614388dd6e1bdcbf4f67504fa7887da9c \
+ --hash=sha256:14f4c5d6db102bd796a627bbb3a17b4cf4574b9ae861d8b7c9a9661c6dd3362d \
+ --hash=sha256:17299feefe090f2caa5b8e37222bb5f663e4935a8bfa6931d4102e5df1a9f398 \
+ --hash=sha256:184c081504d17f1c1066e430e117142b2c77d9448a97f7b65c6ac9fd9aee238d \
+ --hash=sha256:18e5ceec2ab67e6d5f1a9085e5a24c9c4e2ac4545730bfe668680bca05e555f3 \
+ --hash=sha256:19e51f073cd3df251856a8a4189fbdf1de4012c3ebacfb1884f94f1eb406079f \
+ --hash=sha256:1a7dd0b3ee80d90150e3495a3a13ac34dbcbfd4f012996a6a1d8900e91b5c0fb \
+ --hash=sha256:1d8ba486450b14f3b1d63bc521d410ec7565e52f887b9fb671791886436a42f7 \
+ --hash=sha256:2108ba5c1c1eca18030634489dc544844144ee36357f2f9f780b93e7ddbb44b5 \
+ --hash=sha256:228ee9bae8bef5b1e97ec58302f80357c37199e0d0a99174e138d28e6957b9d9 \
+ --hash=sha256:23ace664830ee0bfe014a0c7bc248b1f7f25ed7ad103852c317624a1083af462 \
+ --hash=sha256:2412e734dcb48da14d4e4006b82b46b74f2518b8a26ee7e58c6844a6cd6d03c4 \
+ --hash=sha256:29c61fc04a3d840155ff08e475a04809278972fe6aef51e2720554e96367e34b \
+ --hash=sha256:2f84c03c8607173d16b5a854ec68a2f9079ae03237a54fb506d13af47e1d018d \
+ --hash=sha256:3009f12e4e90b7f88b4f9adb1b0c4a3d58fe7820f3238c190047209d148026df \
+ --hash=sha256:3245406455a5d98187ec35530fd772b1d799b26667980872c8d4614991e2c4a2 \
+ --hash=sha256:3447661d99f75a3683a4cf5c87da72f2161964611864dbbeac7fbb118bb4bfc0 \
+ --hash=sha256:372429a130e469c9cd698925ce5fc50940b7a1336b0d82038e63d5bbc4edc519 \
+ --hash=sha256:395aebd9183f9d112f569aeb5b2214d1a10a33bec8456447f7fbdfa51d38d4cd \
+ --hash=sha256:3a233125ac121aa3ffba9a2b59edfc4a985a76092dc8279586ab4b71390875e7 \
+ --hash=sha256:3be77f45df024d789a672ae34f8b06fb346c4f9f46ea714956660ea4862e89ac \
+ --hash=sha256:3bf92c5d0e00fefaab325a4d27828fe6b6e2a21848686b5b60d2d9eeb09d76c6 \
+ --hash=sha256:3ecbc122d18468d06ca279dc26a8c2e2d5acb10943bb35e36ae92096dc3b5565 \
+ --hash=sha256:3fb702cd90b0446a3a1c5e470bfa0dd23c0233b676a9099ddcc964fa6ca13898 \
+ --hash=sha256:428e04521a40150c85216fc8b85e8d39fece235a9cf5e383761238c7fa9b96fb \
+ --hash=sha256:432c179df7874eeb73307aad2df0755e1ae0efa61ff0ea89b93e194411ae3928 \
+ --hash=sha256:4a05d69cba51d852c5c3e92758653245a50c0b646ced0cf05bd793ed592839d6 \
+ --hash=sha256:4c63ebc82684aa89d9a3bcbd13d515b3be44250dc68dd3bd81526c1cb31286c3 \
+ --hash=sha256:4fc73cb559bdb54b1134a706a2802a4cddd27a0633f5abb7e53056268751ac6a \
+ --hash=sha256:4fcbe087dbc2068af7eda3aa87634eba216dbda64d1ae73c8684b621d33f6596 \
+ --hash=sha256:56cb4851bcaf3d117eddcef4fe66afd750a50274b0da8e22be256d10e5611987 \
+ --hash=sha256:5855698a4856556d86e8e6cd8434bc3ac0314ee8e12089ae0e143f64c6256e4e \
+ --hash=sha256:5a4330cdbc57162e4b3aa303f588ba752257694c9c9be3e7ebb11b4aca659b5d \
+ --hash=sha256:5b712b53160b79a5850310b912a5ef8e57e56947c8ad690c227f5c9d7e561712 \
+ --hash=sha256:5d5902252db0d3cedf8d4a1bc68f70eeb430f7e4c7104c8c476753519b423008 \
+ --hash=sha256:617d7e2ca7dcb8c5cf6bcb8c59b8832c94b36196bbf1cbd1bfb56ed341905edd \
+ --hash=sha256:62f875393d7f270851f20523dd2e29f082bcc82292d66db2b64ea71f64b6e1c1 \
+ --hash=sha256:633147d34cf4550417f12e2b1a0383973bdf5cdfde212cb09e9a581cf10820be \
+ --hash=sha256:66ce7632c22d837c95301830e111ad0128a32b8207533b60896a96c4915192ea \
+ --hash=sha256:6b3ace8194b0e5204818c92802dcdca7fc6d88aabbb799d7c795540d9cd6d292 \
+ --hash=sha256:6f2eeda33a839975441c86a4119e1383c50b47faf0cbb5176985565c6bb02c33 \
+ --hash=sha256:7027560ee92211647d0d34e3f7cd6f50da56399d26a9c8ad0da286d3869a53f3 \
+ --hash=sha256:7283d57845ecf5a163403eb0702dfc220cc4fbdd18919cb5ccea4f95ee1cdab4 \
+ --hash=sha256:7a5f930472650a82629163023e630d160863fce524c616f4e5186e5de9d9a49b \
+ --hash=sha256:7bfb192b3f4b9e8a89b6277b6ce787564f62cfd272055f6e685726b111dc7826 \
+ --hash=sha256:811ff8e9c313ab425368bcbb36e5c4ebd7108c2bbf4e4089cfbb0b01eff63fac \
+ --hash=sha256:8233f2947cf85404441fd7e0085f53b10c93e0ee78611099b5c7237e36aacbf7 \
+ --hash=sha256:82cf5301172168103724d49a1444d3378cb20cdee30b116a1bd6031236298a5d \
+ --hash=sha256:8358a950c8909158e3df31538a7e4edc2d7265a7c54b47f0864d9e5bae9dcebf \
+ --hash=sha256:85bb3611ff1802f3ee7fdd7dbff26b56f343fb432d57a4728fdd49b6ef35e2f4 \
+ --hash=sha256:86e1a4418c6cd97d60c95c71164158eaf7324fae7b0923264016baa993eba6fc \
+ --hash=sha256:8b9bab013d1c7a79d3501ff86d0bc9c31bf587db4551677b96bec07df78c6b15 \
+ --hash=sha256:8c5dac79fa1614d1e06ca695109c6105923bd9c7d1d6c918d4e637b7e6b32fd3 \
+ --hash=sha256:8d0820e8192167f80d88d64038e609c31452eeca865b4e1d9950a27a4609b00b \
+ --hash=sha256:8daafc69c93ee8a0204506a3b6b30f586ef54028f52aeeeb5c4cfc5184fd5914 \
+ --hash=sha256:9037063db01f09b09e237c282b6792bd4da634b5402c4e7f0c61effed7701a04 \
+ --hash=sha256:905a0ed8ea6f2d61c1738835f99b699348d7857379083e5fc497fa0c967a407c \
+ --hash=sha256:90884113d8b48f760e9587002789ddd741e76ab9f89518cd1e43b1f1a52ec44b \
+ --hash=sha256:91a06d2e259ecfbd8c901d70c3c507900458498142b3026a296b7de4d1322cc9 \
+ --hash=sha256:926c9541b14b12b1681dca8a0b75feb510b06c6341b70a8e500c2fdcff837cce \
+ --hash=sha256:9401557acd873c3a7f3eb9383edef8ac4968f9510e340f4808d427e75667e7b4 \
+ --hash=sha256:9551187363ffc0de2a00b2e47c25aeaeb1020b69b668762966df15fc5659dd5a \
+ --hash=sha256:962ccbab7b642487b1d8b7df90ef677e03134cf1fd8880bf698649b22a69371f \
+ --hash=sha256:97e7cf2be5c77b7d1a9713a05605d49460d02c6078d38d8bef3cbe323c548424 \
+ --hash=sha256:9aa768456404a8bf48a4406685ac2bec8e72b62c69313734fa3b73cf33b3a894 \
+ --hash=sha256:9bc519fbf2b7578398853d815009ae5e4d4603d12f4e3f91da8c06852d3da3e9 \
+ --hash=sha256:9d56801be94b86a9da183e5f3766e6310752b99ff647e38b09a9500d88e46e76 \
+ --hash=sha256:9f444c499b3eefd3a92e348059471ea0c3a6e303d9c1cec09fa748fd9f895201 \
+ --hash=sha256:9fa8ae11da9e2b3126c6426f147e0fba88d96d65921799bb30c6abd1cb2c97fb \
+ --hash=sha256:a0f62d0a58f4e7da165457e995725421e0064f2255d8eccebc49f41bbc23b109 \
+ --hash=sha256:a396dcc17e5a0b164dbe026896245a4fa9ff402edca1dff0be3d53a517f74de4 \
+ --hash=sha256:aaa2a54443eff1950ba5ddc6b6ccda0d9c84a364276a62f969bdf2a390650848 \
+ --hash=sha256:ad785e92e6dc634c21555edc8bd6b64957ab844541bcb96a1366c202951ae526 \
+ --hash=sha256:af8244b2bef6aaad6d92cda81372de7f8c8d36c9f0c3ea36e827c60e7d9467a0 \
+ --hash=sha256:b078afbc25f3a1436c7a1d2cd3e322497ee99615ba97c563566fdf46aff1ee01 \
+ --hash=sha256:b2f69dec1725e79a012d920df1707de5caf7ed5e08f3be4435e25803efc47458 \
+ --hash=sha256:b8458003118a712e66286df6a707db01c52c0f52f7db8e4a38f0da1d3b94fc4e \
+ --hash=sha256:bb63e0198ca18aad131c089b9204c23079c3afa95487e561f4c522d519e55aba \
+ --hash=sha256:bfec22eab3c8cc2ceec0248aec886624116dc079afa027ecc8ad4a7e62010f8a \
+ --hash=sha256:c1747f85cee84c26985853c6f3d9bd3e75da5212912443fa111c113b9c246f39 \
+ --hash=sha256:c1b3f518abeca3aa13c712fd202306e145abf59a18b094a6bafb2d2bbf59192c \
+ --hash=sha256:c50f2528cf200c5eed56faf3f4e22fcd5f38c157a8b78576e6ba3168ec35f000 \
+ --hash=sha256:c68fcd102d71ea85c5b2dfac3f4f8476eff42a9e078fd5faefff6d145063536b \
+ --hash=sha256:c7a7bd4e39e8e4c12c39cd480356842b6a8a06e41b23a55a5e3e191718838ddf \
+ --hash=sha256:c94f0688e7b8d0a67abf40e57a7eaaecd17cc9586706a31b76c031f63df052b4 \
+ --hash=sha256:cbaf13819775b7f769bf4a1f066cb6df7a28d4480081a589828ef190226881cd \
+ --hash=sha256:cd2213145bcc2ba85884d0ac63d222fece9209678f77b9b4d76f054c561adb28 \
+ --hash=sha256:ce5c1d2a8b27468f433ca974829c44060b8097eedc39933e3c206a90ee49c4a9 \
+ --hash=sha256:d396ec2b979760aaf3218e76c24e65bd0aca24983298653b3a9d7a45f9e47b30 \
+ --hash=sha256:d51026d73fcfd93610abc7b27789c26b313920fcfb20e27462d74a7f8b06e983 \
+ --hash=sha256:d80ee3d731373b24cebbc10d689ca4ee1875caf0d5703a245db18efd4dd37fc1 \
+ --hash=sha256:d995260fdf4e1db774581b4900e0f832abe3c7c84996726bbc161b19c8f29e76 \
+ --hash=sha256:da4b951fe36dc7c3a1ccb4e3cd1747c3542b8c9ceede8fc86cae054e764485f5 \
+ --hash=sha256:daa27d92c36f24388fe3ad306b174781c747627f134452e4f128ea00ce1fe8c4 \
+ --hash=sha256:db06ffe51636ffe9ca531fe9023dd64bdd794be8754cb5df57c5498ae5b518a7 \
+ --hash=sha256:e0d65b8c354be7fb5f720c3caa8bc940bc2d20ce749c8e06135f07f8ed95dd7c \
+ --hash=sha256:e68b7a074f65a2fd746c52a7ce6142ab7006074ac269ace0c25cd8ba171f8066 \
+ --hash=sha256:e739fee756ba1010f8bcccb534252e85a35fe45ae92c295a06059ce58b74ccd3 \
+ --hash=sha256:e846ae7835bf0703ae43f534ab79a867146dadd59dc9ca5c8b53d5c8f7c9ef02 \
+ --hash=sha256:e9c26f834c65f5752f3f06cb08cb86a913ceb7274d0db6e267808a708b46bc89 \
+ --hash=sha256:ea793e075b70290d89d8142074262885d3f7da19634845135751bd6344f73b50 \
+ --hash=sha256:f027324c56cd5406ca49c124b0db10e56c69064fec039acc571c29020cc87c76 \
+ --hash=sha256:f13a646d65d09fbf1bc6b3a9635d30095c8e7e5cc419ff35ecc563c5fd04cd49 \
+ --hash=sha256:f47286a97f0bc9b8859519809077b91b2cefe4ae47fcbf5e466a009c1c5d742b \
+ --hash=sha256:f747929cf940cddb5b3668a390056ddd5ba2e5010615ea2dcf4f9c4f3ab8791d \
+ --hash=sha256:f99626688942fb746e545232e7726926f3be91b5975f8b55327665fafda991c7 \
+ --hash=sha256:f9fa868638bf362d3d138ea55829cefb3d5f4b0d7f142234382a15e2485dbec4 \
+ --hash=sha256:fbdb89b3e1c94a30cc5edfce477c6e6a5dc4d8f84665b455c27582f211a1c72c \
+ --hash=sha256:fc010ab034c8c7452522748bf937df58020d256ccae0874463d1f4d01758af8e \
+ --hash=sha256:fc3e9034a63de20e15e8ade85358bc6efc614008cab72898b4b4952bea0509ff \
+ --hash=sha256:fd8b3d9fd264be37976686c7f65cd52a83f5e84f4bfd2adf9c1d469676bbb6ae
+sniffio==1.3.1 \
+ --hash=sha256:2f6da418d1f1e0fddd844478f41680e794e6051915791a034ff65e5f100525a2 \
+ --hash=sha256:f4324edc670a0f49750a81b895f35c3adb843cca46f0530f79fc1babb23789dc
+tqdm==4.68.3 \
+ --hash=sha256:00dfa48452b6b6cfae3dd9885636c23d3422d1ec97c66d96818cbd5e0821d482 \
+ --hash=sha256:39832cc2def2789a6f29df83f172db7416cea70052c0907a57801c5f2fdccb03
+typing-extensions==4.15.0 \
+ --hash=sha256:0cea48d173cc12fa28ecabc3b837ea3cf6f38c6d1136f85cbaaf598984861466 \
+ --hash=sha256:f0fa19c6845758ab08074a0cfa8b7aecb71c999ca73d62883bc25cc018c4e548
+typing-inspection==0.4.2 \
+ --hash=sha256:4ed1cacbdc298c220f1bd249ed5287caa16f34d44ef4e9c3d0cbad5b521545e7 \
+ --hash=sha256:ba561c48a67c5958007083d386c3295464928b01faa735ab8547c5692e87f464
diff --git a/.github/scripts/triage_rollout_heads_up.py b/.github/scripts/triage_rollout_heads_up.py
new file mode 100644
index 00000000000..a5dedb1c9e7
--- /dev/null
+++ b/.github/scripts/triage_rollout_heads_up.py
@@ -0,0 +1,557 @@
+#!/usr/bin/env python3
+"""One-shot 7-day heads-up sweep for the Agent Shin rollout.
+
+Posts a friendly "the OSS triage bot kicks in next Monday" comment on every
+open external PR/issue that currently *would* fail the new rubric — i.e.,
+every PR/issue Agent Shin would close once the rollout completes. The point
+is to give contributors a full week to fix their description before the bot
+ever takes a destructive action, so nobody is surprised by an auto-close.
+
+The script is designed to run **exactly once** at rollout, fired by a manual
+``workflow_dispatch`` (``dry_run=false``) on the heads-up workflow. Re-runs
+are safe: every comment is stamped with the hidden ``HEADS_UP_MARKER`` and
+PRs/issues that already carry the marker are skipped.
+
+Dry-run vs. real run
+--------------------
+Defaults to dry-run. Passing ``--close`` flips into real mode. Every GitHub
+mutation goes through ``_agent_shin_actions``, which has a one-line
+``if dry_run: log else: do_it`` per call, so the only difference between a
+dry-run preview and the real run is the call site that actually hits the
+GitHub API.
+
+Local preview::
+
+ python3 .github/scripts/triage_rollout_heads_up.py --repo BerriAI/litellm
+
+Real run (the manual rollout dispatch uses this)::
+
+ python3 .github/scripts/triage_rollout_heads_up.py --repo BerriAI/litellm --close
+"""
+
+from __future__ import annotations
+
+import argparse
+import datetime as dt
+import json
+import os
+import sys
+from pathlib import Path
+from typing import Any
+
+# Make the sibling triage_with_llm + _agent_shin_actions importable when this
+# script is invoked directly (the GitHub workflow does `python3 .github/scripts/...`).
+_SCRIPTS_DIR = Path(__file__).resolve().parent
+if str(_SCRIPTS_DIR) not in sys.path:
+ sys.path.insert(0, str(_SCRIPTS_DIR))
+
+from _agent_shin_actions import maybe_post_comment # noqa: E402
+from agent_shin_shared import ( # noqa: E402
+ AGENT_SHIN_DEFAULT_BOT_LOGIN,
+ ALLOWLIST_LOGINS,
+ list_open_items,
+)
+from triage_with_llm import ( # noqa: E402
+ DEFAULT_MODEL,
+ call_llm_judge,
+ fetch_issue,
+ fetch_pr,
+ gh,
+ is_internal_contributor,
+ review_gate,
+ triage,
+)
+
+# Hidden marker so re-runs skip PRs/issues we've already notified. Distinct from
+# the within-grace / ready / regressed markers so it can't be confused with the
+# steady-state lifecycle comments.
+HEADS_UP_MARKER = ""
+
+# Placeholder until the litellm-docs PR ships. The rollout blog post explains
+# the new rubric, the 7-day grace, and how to recover after an auto-close.
+# TODO(docs): replace with the canonical URL once the litellm-docs PR merges.
+ROLLOUT_BLOG_URL = "https://docs.litellm.ai/docs/agent_shin_triage_rollout"
+
+# Default cutoff is one week from "now". Computed at runtime so the wording
+# stays correct even if the rollout is merged later than planned. The user can
+# override with --close-on YYYY-MM-DD when running the script manually.
+DEFAULT_GRACE_DAYS = 7
+
+# The daily auto-close sweeps (close_low_quality_prs.yml at 09:00 UTC and
+# review_gate.yml at 09:30 UTC) are what actually close a still-failing item,
+# so the deadline we promise contributors has to name that wall-clock moment.
+ACTIVATION_TIME_UTC = "09:00 UTC"
+
+
+def _format_cutoff(cutoff: dt.date) -> str:
+ """Human-readable, timezone-explicit cutoff, e.g. ``Monday, June 1, 2026
+ (09:00 UTC)`` — the moment a still-failing PR/issue gets closed."""
+ return (
+ f"{cutoff.strftime('%A, %B')} {cutoff.day}, {cutoff.year} "
+ f"({ACTIVATION_TIME_UTC})"
+ )
+
+
+def _rubric_section_pr() -> str:
+ return (
+ "**Going forward, every external PR needs ONE of:**\n"
+ "\n"
+ "- A linked GitHub issue using a closing keyword: "
+ "`Fixes #1234`, `Closes #1234`, or `Resolves #1234`, OR\n"
+ "- All three of: a clear **problem description**, **expected vs. "
+ "actual behavior**, and **end-to-end QA proof** (at least one of a "
+ "short screen recording / video, before/after screenshots, or the "
+ "exact commands you ran with their real output; mocked or stubbed "
+ "runs don't count).\n"
+ "\n"
+ "PRs also need a **Greptile confidence score of 4/5 or higher** before "
+ "the bot will tag them `ready for review`. You can `@greptileai` to "
+ "request a fresh review at any time, including after the PR is closed."
+ )
+
+
+def _rubric_section_issue() -> str:
+ return (
+ "**Going forward, every external issue needs:**\n"
+ "\n"
+ "- For **bug reports**: end-to-end evidence of the bug (at least one "
+ "of a screen recording / video, a screenshot, or the exact commands "
+ "you ran with their real output / traceback) plus expected vs. actual "
+ "behavior. Written steps with no run output don't count, and mocked "
+ "or stubbed runs don't count.\n"
+ "- For **feature requests**: a clear description of the proposed "
+ "feature plus a use case + concrete example (config, API call, UI "
+ "flow, or scenario showing what's blocked today)."
+ )
+
+
+def _description_only_note(kind: str) -> str:
+ noun = "PR" if kind == "pr" else "issue"
+ return (
+ f"⚠️ **The requirements must live in the {noun} *description*, not in "
+ "comments.** Some PRs/issues collect 100+ comments from humans and "
+ "bots; reading the entire thread on every triage run would balloon "
+ "GitHub API usage (we'd start getting 429'd) and blow out the LLM "
+ "judge's context. The bot only reads the description, so anything "
+ "you add as a comment will be invisible to it."
+ )
+
+
+def _missing_section(verdict: dict, greptile_score: int | None) -> str:
+ """Bullet list of what's currently missing on this PR/issue.
+
+ Combines the LLM judge's `missing` list (rubric items) with a Greptile
+ shortfall (for PRs) so the contributor sees one list of things to fix.
+ """
+ missing = list(verdict.get("missing") or [])
+ if greptile_score is not None and greptile_score < 4:
+ missing.insert(
+ 0,
+ f"Greptile's most recent review scored this PR {greptile_score}/5 "
+ "(below the 4/5 bar Agent Shin will require).",
+ )
+ if not missing:
+ return (
+ "_The bot couldn't articulate a specific missing piece; see the "
+ "rubric link above and double-check the description includes all "
+ "of it before the rollout._"
+ )
+ bullets = "\n".join(f"- {m}" for m in missing)
+ return f"**What this one is currently missing:**\n\n{bullets}"
+
+
+def _recovery_section(kind: str) -> str:
+ if kind == "pr":
+ return (
+ "**If the bot closes this PR after the rollout:** update the "
+ "description with the missing pieces, then either open a fresh "
+ "PR or comment `@agent-shin reconsider` on the closed PR. If "
+ "Greptile re-scores you at 4/5 or higher I'll reopen and tag "
+ "the PR `ready for review`. (`@greptileai` works on closed PRs "
+ "too; a fresh review is one of the signals that lifts you back "
+ "into the queue.) This is **not** us losing interest in your "
+ "change; far from it. We just need open PRs to be a list of "
+ "things a maintainer can act on, so we can get to yours faster."
+ )
+ return (
+ "**If the bot closes this issue after the rollout:** edit the issue "
+ "description to add the missing pieces, then comment `@agent-shin "
+ "reconsider` on the closed issue. I'll re-evaluate and, if the rubric "
+ "is met, reopen it. (GitHub doesn't let external authors reopen an "
+ "issue a maintainer or bot closed, so the comment is the reliable "
+ "path.) This is **not** us saying the bug isn't real or the request "
+ "isn't useful; it's so the remaining open issues are a list of things "
+ "a maintainer can act on."
+ )
+
+
+def format_heads_up_comment(
+ *, kind: str, verdict: dict, greptile_score: int | None, cutoff: dt.date
+) -> str:
+ """Compose the friendly 7-day heads-up comment posted on a failing PR/issue."""
+ noun = "PR" if kind == "pr" else "issue"
+ rubric = _rubric_section_pr() if kind == "pr" else _rubric_section_issue()
+ cutoff_str = _format_cutoff(cutoff)
+ explanation = (verdict.get("explanation") or "").strip()
+ explanation_block = (
+ f"> _(The judge's note for this one: {explanation})_\n\n" if explanation else ""
+ )
+
+ return (
+ "🚅 **Heads-up: we're turning on the OSS triage bot in "
+ f"{DEFAULT_GRACE_DAYS} days, on {cutoff_str}.**\n"
+ "\n"
+ "We're rolling out **Agent Shin**, an LLM-as-judge triage bot for "
+ f"external {noun}s. Once it's live, the bot reads each open "
+ f"{noun}'s description, scores it against a small rubric, and "
+ f"auto-closes any {noun} that's missing the basics, with a single "
+ f"comment explaining what's missing and how to recover. Full "
+ f"context: [Agent Shin rollout blog post]({ROLLOUT_BLOG_URL}).\n"
+ "\n"
+ f"{rubric}\n"
+ "\n"
+ f"{_description_only_note(kind)}\n"
+ "\n"
+ f"{_missing_section(verdict, greptile_score)}\n"
+ "\n"
+ f"{explanation_block}"
+ "**Timeline (you have a week):**\n"
+ "\n"
+ f"- We turn the bot on in {DEFAULT_GRACE_DAYS} days, on "
+ f"**{cutoff_str}**. You have until then to update this {noun}'s "
+ "description with the missing pieces above.\n"
+ f"- If this {noun} still fails the rubric at **{cutoff_str}**, "
+ "we'll close it.\n"
+ f"- From then on the bot runs daily, and every {noun} that fails "
+ "the rubric gets a **2-hour lifetime**: one warning comment, then "
+ "auto-close 2 hours later.\n"
+ "\n"
+ f"{_recovery_section(kind)}\n"
+ "\n"
+ f"{HEADS_UP_MARKER}"
+ )
+
+
+def _list_open_numbers(repo: str, kind: str) -> list[int]:
+ """Return every open PR or issue number in ``repo``.
+
+ Delegates to ``list_open_items`` so the full backlog is fetched (no cap)
+ and the `gh {pr,issue} list` invocation stays in one shared place. ``gh
+ issue list`` would include PRs, but ``list_open_items`` uses the dedicated
+ command per kind, so the two never mix.
+ """
+ return [
+ item["number"] for item in list_open_items(kind, repo=repo, fields="number")
+ ]
+
+
+def _has_heads_up_marker(item: dict) -> bool:
+ """Cheap fast-path: check the PR/issue body itself for the marker.
+
+ The marker is appended to the *comment* we post, not the body, so this
+ will only fire if the body literally contains the marker text. We still
+ do the comment-marker check separately below; this body check just lets
+ us short-circuit for PRs/issues that quote the marker for any reason.
+ """
+ body = item.get("body") or ""
+ return HEADS_UP_MARKER in body
+
+
+def _comments_have_marker(repo: str, number: int) -> bool:
+ """True if the bot already posted a comment carrying the marker.
+
+ Used for idempotency: a re-run skips items the previous run notified.
+ Filters by author (matching the sibling marker-checks in
+ ``triage_with_llm._has_marker`` and
+ ``agent_shin_shared.seconds_since_latest_marker_comment``) so a
+ contributor who quotes the heads-up via GitHub's "Quote reply" — which
+ preserves HTML comments in the raw markdown — can't trick the
+ idempotency check into silently skipping a real heads-up.
+
+ Comments live on the unified issues endpoint regardless of whether the
+ item is a PR or an issue, so no ``kind`` argument is required here.
+ """
+ expected_login = (
+ os.environ.get("AGENT_SHIN_BOT_LOGIN") or AGENT_SHIN_DEFAULT_BOT_LOGIN
+ ).lower()
+ raw = gh(
+ "api",
+ "--paginate",
+ f"repos/{repo}/issues/{number}/comments?per_page=100",
+ )
+ for line in raw.splitlines():
+ line = line.strip()
+ if not line:
+ continue
+ try:
+ payload = json.loads(line)
+ except json.JSONDecodeError:
+ continue
+ comments = payload if isinstance(payload, list) else [payload]
+ for comment in comments:
+ author = ((comment.get("user") or {}).get("login") or "").lower()
+ if author != expected_login:
+ continue
+ if HEADS_UP_MARKER in (comment.get("body") or ""):
+ return True
+ return False
+
+
+def _evaluate_pr(*, repo: str, number: int, model: str, judge: Any = None) -> dict:
+ """Run the future PR rubric (review_gate) in dry-run and return the result."""
+ return review_gate(
+ repo=repo,
+ number=number,
+ close=False, # we only want the verdict, never act here
+ model=model,
+ judge=judge,
+ )
+
+
+def _evaluate_issue(*, repo: str, number: int, model: str, judge: Any = None) -> dict:
+ """Run the future issue rubric (triage kind='issue') in dry-run."""
+ return triage(
+ repo=repo,
+ kind="issue",
+ number=number,
+ close=False,
+ model=model,
+ judge=judge,
+ )
+
+
+def _would_be_closed(kind: str, result: dict) -> bool:
+ """True if the future triage would auto-close this PR/issue based on the
+ rubric (regardless of grace-period gating).
+
+ For PRs we trust ``review_gate``'s ``passing`` field — it combines the LLM
+ verdict and the Greptile score. For issues we read the LLM verdict
+ directly. Both fields are ``None``/missing on skip paths
+ (skip-internal-author, skip-llm-error, etc.) where the future bot would
+ NOT close the item — those return False.
+ """
+ if kind == "pr":
+ passing = result.get("passing")
+ if passing is None:
+ return False # skipped — nothing for the heads-up to warn about
+ return passing is False
+ verdict = result.get("verdict") or {}
+ return (verdict.get("verdict") or "").lower() == "fail"
+
+
+def _process_one(
+ *,
+ repo: str,
+ kind: str,
+ number: int,
+ model: str,
+ cutoff: dt.date,
+ dry_run: bool,
+ judge: Any = None,
+ skip_marker_check: bool = False,
+ allowlist: frozenset[str] = ALLOWLIST_LOGINS,
+) -> dict:
+ """Evaluate one PR/issue and post a heads-up if it would be auto-closed.
+
+ Returns a per-item dict for the summary table.
+ """
+ base = {"kind": kind, "number": number}
+ fetcher = fetch_pr if kind == "pr" else fetch_issue
+ item = fetcher(repo, number)
+
+ if (item.get("state") or "") != "open":
+ return {**base, "action": "skip-not-open"}
+ if allowlist:
+ login = (item.get("user") or {}).get("login") or ""
+ if login.lower() not in allowlist:
+ return {**base, "action": "skip-not-allowlisted"}
+ elif is_internal_contributor(item):
+ return {**base, "action": "skip-internal-author"}
+ if not skip_marker_check and _has_heads_up_marker(item):
+ return {**base, "action": "skip-already-marked-in-body"}
+ if not skip_marker_check and _comments_have_marker(repo, number):
+ return {**base, "action": "skip-already-notified"}
+
+ if kind == "pr":
+ result = _evaluate_pr(repo=repo, number=number, model=model, judge=judge)
+ else:
+ result = _evaluate_issue(repo=repo, number=number, model=model, judge=judge)
+
+ if not _would_be_closed(kind, result):
+ return {**base, "action": "skip-passing", "evaluator": result.get("action")}
+
+ verdict = result.get("verdict") or {}
+ greptile_score = result.get("greptile_score") if kind == "pr" else None
+ comment = format_heads_up_comment(
+ kind=kind, verdict=verdict, greptile_score=greptile_score, cutoff=cutoff
+ )
+ maybe_post_comment(repo, number, comment, dry_run=dry_run)
+ return {
+ **base,
+ "action": "heads-up-posted" if not dry_run else "would-post-heads-up",
+ "verdict": (verdict.get("verdict") or "").lower(),
+ "greptile_score": greptile_score,
+ }
+
+
+def _print_summary(results: list[dict]) -> None:
+ """Tally per-action counts so a dry-run preview tells you at a glance how
+ many comments the real run would post."""
+ counts: dict[str, int] = {}
+ for r in results:
+ counts[r["action"]] = counts.get(r["action"], 0) + 1
+ print("\n=== rollout heads-up summary ===")
+ for action in sorted(counts):
+ print(f" {action:35s} {counts[action]}")
+ print(f" total {len(results)}")
+
+
+def run(
+ *,
+ repo: str,
+ close: bool,
+ cutoff: dt.date,
+ model: str,
+ kinds: tuple[str, ...] = ("pr", "issue"),
+ judge: Any = None,
+ only_numbers: dict[str, list[int]] | None = None,
+ skip_marker_check: bool = False,
+) -> list[dict]:
+ """Sweep ``repo`` and post heads-up comments. Returns the per-item results."""
+ dry_run = not close
+ if dry_run:
+ print(
+ f"[DRY RUN] sweeping {repo}; --close not passed, no comments will be posted."
+ )
+ else:
+ print(f"[REAL RUN] sweeping {repo}; comments WILL be posted.")
+ print(f"Cutoff date in comment body: {cutoff.isoformat()}")
+
+ results: list[dict] = []
+ for kind in kinds:
+ if only_numbers and kind in only_numbers:
+ numbers = list(only_numbers[kind])
+ else:
+ numbers = _list_open_numbers(repo, kind)
+ print(f"\n--- {kind}s: {len(numbers)} open ---")
+ for n in numbers:
+ try:
+ result = _process_one(
+ repo=repo,
+ kind=kind,
+ number=n,
+ model=model,
+ cutoff=cutoff,
+ dry_run=dry_run,
+ judge=judge,
+ skip_marker_check=skip_marker_check,
+ )
+ except (
+ Exception
+ ) as exc: # noqa: BLE001 - per-item errors don't abort the sweep
+ result = {
+ "kind": kind,
+ "number": n,
+ "action": "error",
+ "error": str(exc),
+ }
+ print(f"!! {kind}#{n}: {exc}", file=sys.stderr)
+ print(f" {kind}#{n}: {result['action']}")
+ results.append(result)
+ _print_summary(results)
+ return results
+
+
+def main() -> int:
+ parser = argparse.ArgumentParser(description=__doc__)
+ parser.add_argument("--repo", required=True, help="owner/repo")
+ parser.add_argument(
+ "--close",
+ action="store_true",
+ help=(
+ "Actually post comments. Without this flag the script is in "
+ "dry-run mode and only logs what it would do."
+ ),
+ )
+ parser.add_argument(
+ "--close-on",
+ type=dt.date.fromisoformat,
+ default=None,
+ help=(
+ "Cutoff date shown in the heads-up comment as the rollout date "
+ f"(default: today + {DEFAULT_GRACE_DAYS} days)."
+ ),
+ )
+ parser.add_argument(
+ "--model",
+ default=os.environ.get("TRIAGE_MODEL") or DEFAULT_MODEL,
+ help=f"Model for the rubric LLM judge (default: {DEFAULT_MODEL}).",
+ )
+ parser.add_argument(
+ "--kind",
+ choices=("pr", "issue", "both"),
+ default="both",
+ help="Restrict the sweep to PRs or issues only (default: both).",
+ )
+ parser.add_argument(
+ "--only-pr",
+ type=int,
+ action="append",
+ default=[],
+ help="Limit the PR sweep to these PR numbers (repeat for several).",
+ )
+ parser.add_argument(
+ "--only-issue",
+ type=int,
+ action="append",
+ default=[],
+ help="Limit the issue sweep to these issue numbers (repeat for several).",
+ )
+ parser.add_argument(
+ "--ignore-existing-marker",
+ action="store_true",
+ help=(
+ "Re-post on PRs/issues that already carry the heads-up marker. "
+ "Useful for testing the comment wording on a known PR."
+ ),
+ )
+ args = parser.parse_args()
+
+ cutoff = args.close_on or (
+ dt.datetime.now(dt.timezone.utc).date() + dt.timedelta(days=DEFAULT_GRACE_DAYS)
+ )
+
+ kinds: tuple[str, ...]
+ if args.kind == "pr":
+ kinds = ("pr",)
+ elif args.kind == "issue":
+ kinds = ("issue",)
+ else:
+ kinds = ("pr", "issue")
+
+ only: dict[str, list[int]] = {}
+ if args.only_pr:
+ only["pr"] = args.only_pr
+ if args.only_issue:
+ only["issue"] = args.only_issue
+
+ # The script must NOT hit the LLM in dry-run if no key is set — we still
+ # want a useful preview that says "skip-no-llm-key" for items that would
+ # have been judged. Production runs require OPENAI_API_KEY.
+ if args.close and not os.environ.get("OPENAI_API_KEY"):
+ parser.error("OPENAI_API_KEY must be set for --close (real-run) mode.")
+
+ run(
+ repo=args.repo,
+ close=args.close,
+ cutoff=cutoff,
+ model=args.model,
+ kinds=kinds,
+ only_numbers=only or None,
+ skip_marker_check=args.ignore_existing_marker,
+ )
+ return 0
+
+
+if __name__ == "__main__":
+ sys.exit(main())
diff --git a/.github/scripts/triage_with_llm.py b/.github/scripts/triage_with_llm.py
new file mode 100644
index 00000000000..d2536058e01
--- /dev/null
+++ b/.github/scripts/triage_with_llm.py
@@ -0,0 +1,1778 @@
+#!/usr/bin/env python3
+"""
+Agent Shin — LLM-as-judge triage for external OSS pull requests and issues.
+
+Evaluates a single PR or issue against the contribution rubric and, when the
+LLM judge marks it as failing, posts an explanatory comment + closes the
+PR/issue. Re-triggers on `reopened` so contributors can iterate back in by
+filling in the missing pieces and reopening.
+
+Internal BerriAI contributors (`author_association` in {OWNER, MEMBER,
+COLLABORATOR}) and bot accounts are skipped entirely.
+
+Usage:
+ triage_with_llm.py --repo owner/repo --pr 1234
+ triage_with_llm.py --repo owner/repo --issue 5678
+ triage_with_llm.py --repo owner/repo --pr 1234 --close # actually close
+ triage_with_llm.py --repo owner/repo --pr 1234 --print-prompt # show prompt
+
+Defaults are SAFE: without `--close` the script writes a verdict to stdout (and,
+when running in GitHub Actions, to $GITHUB_STEP_SUMMARY) but takes no GitHub
+write actions.
+
+Environment:
+ GH_TOKEN / GITHUB_TOKEN - for `gh` CLI auth (auto-set in Actions)
+ OPENAI_API_KEY - required when --close is passed
+ OPENAI_BASE_URL - optional (route to any OpenAI-compatible API)
+ TRIAGE_MODEL - optional model override (default: gpt-5.4-mini)
+"""
+
+from __future__ import annotations
+
+import argparse
+import datetime as dt
+import json
+import os
+import re
+import subprocess
+import sys
+import textwrap
+import urllib.parse
+from typing import Any, Iterable
+
+# Add this script's directory to `sys.path` so the sibling
+# `agent_shin_shared` module is importable when the script is invoked
+# directly (e.g. `python3 .github/scripts/triage_with_llm.py ...`) and
+# also when the tests load this script via
+# `importlib.util.spec_from_file_location`.
+sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
+
+from agent_shin_shared import ( # noqa: E402 -- sys.path adjusted above
+ AGENT_SHIN_CLOSE_MARKER,
+ AGENT_SHIN_DEFAULT_BOT_LOGIN,
+ ALLOWLIST_LOGINS,
+ GRACE_COMMENT_MARKER,
+ GRACE_PERIOD_SECONDS,
+ GREPTILE_BOT_LOGINS,
+ SCORE_PATTERN,
+ extract_greptile_score,
+ gh,
+ parse_iso8601,
+ seconds_since_latest_marker_comment,
+)
+
+DEFAULT_MODEL = "gpt-5.4-mini"
+
+INTERNAL_ASSOCIATIONS = frozenset({"OWNER", "MEMBER", "COLLABORATOR"})
+
+# `AGENT_SHIN_DEFAULT_BOT_LOGIN` is imported from `agent_shin_shared`.
+# When the workflow uses the default `secrets.GITHUB_TOKEN`, the
+# closure / reopen event's `actor.login` is `github-actions[bot]`. The
+# env override `AGENT_SHIN_BOT_LOGIN` exists for local debugging and for
+# repos that wire Agent Shin to a PAT.
+
+# HTML marker appended to every reconsider verdict comment. We grep for this
+# on subsequent reconsider triggers to enforce a short cooldown so that
+# repeated `@agent-shin reconsider` comments don't burn CI/LLM budget.
+# Using a unique HTML comment keeps the marker invisible to humans while
+# being trivially greppable from a comments-list API response.
+RECONSIDER_COMMENT_MARKER = ""
+
+# Minimum gap between two reconsider verdicts on the same PR/issue. Set to
+# 10 minutes — long enough that a contributor can't trivially spam the
+# trigger, short enough that a genuine "I just pushed a fix and reupdated
+# the body" iteration loop isn't punished.
+RECONSIDER_RATE_LIMIT_SECONDS = 600
+
+# `GRACE_COMMENT_MARKER` (HTML marker on the grace-period warning comment
+# posted on the first low-quality detection — used on subsequent triage
+# runs to detect that a warning was already posted and measure how long
+# ago it was posted) and `GRACE_PERIOD_SECONDS` (length of the grace
+# period between the warning and the actual auto-close, 2 hours) are
+# imported from `agent_shin_shared` so the daily Greptile sweep and the
+# LLM judge agree on the same marker and duration.
+
+# --- Review-gate ("ready for review" label lifecycle) configuration ----------
+# The review gate keeps a single label in sync with whether a PR currently
+# clears BOTH quality bars: the LLM rubric (clear problem + expected/actual +
+# QA proof, or a linked issue) AND Greptile's most recent confidence score.
+READY_FOR_REVIEW_LABEL = "ready for review"
+DEFAULT_GRACE_DAYS = 1 # 24h before an un-passing, un-tagged PR is auto-closed
+DEFAULT_MIN_GREPTILE_SCORE = 4 # Greptile < 4/5 counts as "not passing"
+
+# Hidden HTML-comment markers stamped into review-gate comments. They never
+# render in the GitHub UI but let the gate detect its own prior actions so it
+# (a) posts the within-grace "what's missing" notice at most once and (b) can
+# tell a first-time pass ("ready for review") from a recovery after a
+# regression ("all clear again").
+READY_MARKER = ""
+REGRESSED_MARKER = ""
+WITHIN_GRACE_MARKER = ""
+
+# `GREPTILE_BOT_LOGINS` (Greptile's GitHub App login variants —
+# `greptile-apps[bot]` in REST API comments, `greptile-apps` in
+# `gh pr view --json` output) and `SCORE_PATTERN` (regex matching lines
+# like `Confidence Score: 3/5`) are imported from `agent_shin_shared`
+# so the daily sweep and the review gate read the score through the
+# same set of logins / patterns.
+
+# `AGENT_SHIN_CLOSE_MARKER` is imported from `agent_shin_shared` so this LLM
+# judge and the daily Greptile sweep stamp the same marker on their close
+# comments — `was_closed_by_agent_shin` keys the reconsider reopen path off it.
+
+# Model families that require `reasoning_effort` to be set, and that reject
+# `temperature != 1` unless `reasoning_effort` is "none". For these models we
+# pass `reasoning_effort="none"` so a `temperature=0` deterministic judgment
+# is still accepted. See litellm/llms/openai/chat/gpt_5_transformation.py for
+# the full set of constraints LiteLLM applies to these models.
+GPT5_FAMILY_PREFIX = "gpt-5"
+
+# Regexes for picking off "obvious passes" without burning LLM tokens.
+#
+# Keep this list to GitHub's documented PR-closing keywords only
+# (https://docs.github.com/issues/tracking-your-work-with-issues/linking-a-pull-request-to-an-issue).
+# Casual mentions like "see #1234" or "ref #1234" are intentionally NOT
+# auto-passed — they should fall through to the LLM judge, which has the
+# stricter rubric "a bare issue number without a closing keyword counts only
+# if it's clearly the related issue (not a passing mention)".
+LINKED_ISSUE_PATTERN = re.compile(
+ r"\b(?:fixes|fix|fixed|closes|close|closed|resolves|resolve|resolved)\s+"
+ r"(?:#\d+|https?://github\.com/[\w.-]+/[\w.-]+/issues/\d+)",
+ re.IGNORECASE,
+)
+HTML_COMMENT_PATTERN = re.compile(r"", re.DOTALL)
+
+
+# ---------------------------------------------------------------------------
+# gh helpers
+#
+# `gh` is imported from `agent_shin_shared` so a future change (timeout,
+# logging, retry) only needs to be made once.
+
+
+def fetch_pr(repo: str, number: int) -> dict:
+ """Return the full GitHub REST representation of a PR."""
+ return json.loads(gh("api", f"repos/{repo}/pulls/{number}"))
+
+
+def fetch_issue(repo: str, number: int) -> dict:
+ """Return the full GitHub REST representation of an issue."""
+ return json.loads(gh("api", f"repos/{repo}/issues/{number}"))
+
+
+def post_comment(repo: str, number: int, body: str) -> None:
+ """Post an issue-style comment (works for both issues and PRs)."""
+ gh(
+ "api",
+ f"repos/{repo}/issues/{number}/comments",
+ "-X",
+ "POST",
+ "-f",
+ f"body={body}",
+ )
+
+
+def close_pr(repo: str, number: int) -> None:
+ """Close a pull request (state=closed)."""
+ gh(
+ "api",
+ f"repos/{repo}/pulls/{number}",
+ "-X",
+ "PATCH",
+ "-f",
+ "state=closed",
+ )
+
+
+def reopen_pr(repo: str, number: int) -> None:
+ """Reopen a previously-closed pull request (state=open).
+
+ Used by the `@agent-shin reconsider` comment-trigger flow: the bot has
+ write access via GH_TOKEN, so it can reopen on the contributor's behalf
+ even though GitHub doesn't let the OSS author do it themselves.
+ """
+ gh(
+ "api",
+ f"repos/{repo}/pulls/{number}",
+ "-X",
+ "PATCH",
+ "-f",
+ "state=open",
+ )
+
+
+def close_issue(repo: str, number: int, *, not_planned: bool = True) -> None:
+ """Close an issue, marking state_reason=not_planned by default."""
+ args = [
+ "api",
+ f"repos/{repo}/issues/{number}",
+ "-X",
+ "PATCH",
+ "-f",
+ "state=closed",
+ ]
+ if not_planned:
+ args.extend(["-f", "state_reason=not_planned"])
+ gh(*args)
+
+
+def reopen_issue(repo: str, number: int) -> None:
+ """Reopen a previously-closed issue (state=open, state_reason=reopened)."""
+ gh(
+ "api",
+ f"repos/{repo}/issues/{number}",
+ "-X",
+ "PATCH",
+ "-f",
+ "state=open",
+ "-f",
+ "state_reason=reopened",
+ )
+
+
+def add_label(repo: str, number: int, label: str) -> None:
+ """Add a label to a PR/issue (GitHub creates the label if it's missing)."""
+ gh(
+ "api",
+ f"repos/{repo}/issues/{number}/labels",
+ "-X",
+ "POST",
+ "-f",
+ f"labels[]={label}",
+ )
+
+
+def remove_label(repo: str, number: int, label: str) -> None:
+ """Remove a label from a PR/issue. A missing label (404) is not an error."""
+ encoded = urllib.parse.quote(label, safe="")
+ try:
+ gh(
+ "api",
+ f"repos/{repo}/issues/{number}/labels/{encoded}",
+ "-X",
+ "DELETE",
+ )
+ except subprocess.CalledProcessError as exc:
+ stderr = (exc.stderr or "").lower()
+ if "404" in stderr or "not found" in stderr:
+ return
+ raise
+
+
+def _iter_paginated_json(*api_args: str) -> Any:
+ """Yield JSON objects from `gh api --paginate ... -q '.[]'`.
+
+ `gh api --paginate` on a JSON-array endpoint concatenates pages into
+ one stream; `-q '.[]'` flattens that stream into newline-delimited
+ objects (jq-style). This keeps memory bounded for chatty endpoints
+ like issue events/comments on long-lived PRs.
+ """
+ raw = gh("api", "--paginate", *api_args, "-q", ".[]")
+ for line in raw.splitlines():
+ line = line.strip()
+ if not line:
+ continue
+ try:
+ yield json.loads(line)
+ except json.JSONDecodeError:
+ # A malformed line should not blow up the whole guard. Skip and
+ # carry on — at worst the guard fail-closes (returns False /
+ # None) and the caller treats it as "unknown".
+ continue
+
+
+def fetch_last_close_event(
+ repo: str, number: int
+) -> tuple[str | None, dt.datetime | None]:
+ """Return the actor login and timestamp of the most recent `closed` event.
+
+ Either field may be None: actor when the events API returns nothing
+ (unusual for a closed item, but possible on transient errors), and
+ timestamp when the event lacks `created_at` or the value can't be
+ parsed. `was_closed_by_agent_shin` fail-closes on either.
+ """
+ actor: str | None = None
+ closed_at: dt.datetime | None = None
+ for event in _iter_paginated_json(f"repos/{repo}/issues/{number}/events"):
+ if event.get("event") != "closed":
+ continue
+ actor = (event.get("actor") or {}).get("login")
+ created = event.get("created_at")
+ if not created:
+ closed_at = None
+ continue
+ try:
+ closed_at = parse_iso8601(created)
+ except ValueError:
+ closed_at = None
+ return actor, closed_at
+
+
+# How much older than the latest `closed` event the Agent Shin marker
+# comment is allowed to be while still counting as "this close was Agent
+# Shin's". Agent Shin posts the close comment immediately before closing,
+# so the marker timestamp is normally at most a few seconds before the
+# close event; the buffer just absorbs clock skew between the comments
+# API and the events API.
+AGENT_SHIN_CLOSE_MARKER_SKEW_SECONDS = 300
+
+
+def was_closed_by_agent_shin(
+ repo: str, number: int, *, bot_login: str | None = None
+) -> bool:
+ """Return True iff Agent Shin itself most-recently closed this PR/issue.
+
+ This is the guard that stops `@agent-shin reconsider` from reopening an
+ item Agent Shin did not close — a maintainer closing for non-rubric
+ reasons (security, duplicate, design rejection), or a different workflow
+ (stale/duplicate sweeps) closing under the shared `github-actions[bot]`
+ identity. Three independent signals must all hold, because that identity
+ is not unique to Agent Shin and a marker comment from a prior
+ closed/reopened cycle would otherwise vouch for an unrelated close:
+
+ 1. The most recent `closed` event's actor is the bot identity.
+ 2. Agent Shin left one of its auto-close comments, detected via
+ `AGENT_SHIN_CLOSE_MARKER`. The actor check alone can't tell an
+ Agent Shin close from any other `github-actions[bot]` close.
+ 3. That marker comment was posted at (or just before) the latest
+ close event, not on a previous close in an
+ Agent-Shin-close -> reconsider-reopen -> other-bot-reclose cycle.
+
+ The check is intentionally fail-closed: any uncertainty about who closed
+ the item is treated as "not Agent Shin" so the destructive reopen path
+ stays gated.
+ """
+ expected = (
+ bot_login
+ or os.environ.get("AGENT_SHIN_BOT_LOGIN")
+ or AGENT_SHIN_DEFAULT_BOT_LOGIN
+ ).lower()
+ actor, closed_at = fetch_last_close_event(repo, number)
+ if not actor or actor.lower() != expected or closed_at is None:
+ return False
+ marker_seconds = seconds_since_last_agent_shin_close(
+ repo, number, bot_login=bot_login
+ )
+ if marker_seconds is None:
+ return False
+ close_age_seconds = (dt.datetime.now(dt.timezone.utc) - closed_at).total_seconds()
+ return marker_seconds <= close_age_seconds + AGENT_SHIN_CLOSE_MARKER_SKEW_SECONDS
+
+
+def _seconds_since_latest_marker_comment(
+ repo: str,
+ number: int,
+ *,
+ marker: str,
+ bot_login: str | None = None,
+) -> float | None:
+ """Return seconds since the bot's most recent comment with ``marker``.
+
+ Fetches comments via `_iter_paginated_json` and delegates the
+ iteration / author-filter / timestamp logic to
+ `agent_shin_shared.seconds_since_latest_marker_comment` so the daily
+ Greptile sweep and the LLM judge use one source of truth for the
+ "bot already posted X" detection. The wall-clock `now` is resolved
+ against this module's `dt` so tests that freeze time via
+ `monkeypatch.setattr(triage_module, "dt", ...)` still apply.
+ """
+ return seconds_since_latest_marker_comment(
+ _iter_paginated_json(f"repos/{repo}/issues/{number}/comments"),
+ marker=marker,
+ bot_login=bot_login,
+ now=dt.datetime.now(dt.timezone.utc),
+ )
+
+
+def seconds_since_last_reconsider_verdict(
+ repo: str, number: int, *, bot_login: str | None = None
+) -> float | None:
+ """Return seconds since the bot's most recent reconsider verdict comment.
+
+ Detects comments by matching the HTML marker `RECONSIDER_COMMENT_MARKER`
+ appended by `format_reopen_comment` and
+ `format_reconsider_still_failing_comment`. Returns None when the bot
+ has never posted a reconsider verdict on this PR/issue (or when the
+ only matching comments are missing a `created_at` timestamp, which
+ shouldn't happen on a real GitHub response).
+ """
+ return _seconds_since_latest_marker_comment(
+ repo, number, marker=RECONSIDER_COMMENT_MARKER, bot_login=bot_login
+ )
+
+
+def seconds_since_last_grace_warning(
+ repo: str, number: int, *, bot_login: str | None = None
+) -> float | None:
+ """Return seconds since the bot's most recent grace-period warning.
+
+ Detects warning comments by matching the HTML marker
+ `GRACE_COMMENT_MARKER` appended by `format_grace_warning_pr_comment`
+ and `format_grace_warning_issue_comment`. Returns None when no
+ grace warning has ever been posted on this PR/issue — that's the
+ "first low-quality detection" signal that drives the warning path.
+ """
+ return _seconds_since_latest_marker_comment(
+ repo, number, marker=GRACE_COMMENT_MARKER, bot_login=bot_login
+ )
+
+
+def seconds_since_last_agent_shin_close(
+ repo: str, number: int, *, bot_login: str | None = None
+) -> float | None:
+ """Return seconds since Agent Shin's most recent auto-close comment.
+
+ Detects close comments by matching `AGENT_SHIN_CLOSE_MARKER` (stamped by
+ `format_pr_close_comment` / `format_issue_close_comment`). Returns None
+ when Agent Shin has never closed this PR/issue — the signal
+ `was_closed_by_agent_shin` uses to keep the reconsider reopen path gated
+ against closures performed by other workflows sharing the bot identity.
+ """
+ return _seconds_since_latest_marker_comment(
+ repo, number, marker=AGENT_SHIN_CLOSE_MARKER, bot_login=bot_login
+ )
+
+
+# ---------------------------------------------------------------------------
+# Author classification
+
+
+def is_internal_contributor(item: dict) -> bool:
+ """Return True if the PR/issue author should be exempted from triage.
+
+ Fail-safe: if `author_association` is missing or empty (which should never
+ happen on a successful GitHub REST response but is possible on schema
+ changes or partial responses), treat the author as INTERNAL so the
+ destructive close path never fires on an unknown contributor. This matches
+ the sibling `is_external_pr_author` in `close_low_quality_prs.py`.
+ """
+ login = ((item.get("user") or {}).get("login") or "").lower()
+ if login.endswith("[bot]") or login in {"dependabot", "github-actions"}:
+ return True
+ association = (item.get("author_association") or "").upper()
+ if not association or association in INTERNAL_ASSOCIATIONS:
+ return True
+ return False
+
+
+# ---------------------------------------------------------------------------
+# Greptile score + age helpers (`extract_greptile_score`, `parse_iso8601`)
+# live in `agent_shin_shared` — they're imported at the top of this module
+# so both `triage_with_llm.py` and `close_low_quality_prs.py` share a
+# single source of truth for the Confidence-Score regex and ISO-8601
+# parsing.
+
+
+# ---------------------------------------------------------------------------
+# Prompt construction
+
+
+def strip_html_comments(text: str) -> str:
+ """Remove HTML comments — template placeholder text shouldn't fool the judge."""
+ return HTML_COMMENT_PATTERN.sub("", text or "")
+
+
+def has_linked_issue(text: str) -> bool:
+ """Heuristic: does this body link to an open issue (Fixes #123 etc.)?"""
+ return bool(LINKED_ISSUE_PATTERN.search(strip_html_comments(text or "")))
+
+
+def build_pr_prompt(*, title: str, body: str) -> str:
+ cleaned_body = strip_html_comments(body or "").strip() or "(empty)"
+ # Dedent the static template *before* interpolating dynamic fields so that
+ # multi-line bodies (whose 2nd+ lines start at column 0) don't defeat the
+ # common-indent computation in textwrap.dedent.
+ template = textwrap.dedent("""
+ You are "Agent Shin", the OSS triage bot for the LiteLLM open-source
+ repository (BerriAI/litellm). Decide whether this external pull request
+ meets the project's contribution standards.
+
+ A PR PASSES triage only if BOTH (1) AND (2) are satisfied. A linked
+ issue alone is NOT enough — it covers context, not proof.
+
+ (1) CONTEXT — the PR provides AT LEAST ONE of:
+ (a) A link to a related GitHub issue. Acceptable forms:
+ "Fixes #1234", "Closes #1234", "Resolves #1234",
+ "Refs https://github.com/BerriAI/litellm/issues/1234". A
+ bare "#1234" without a closing keyword counts only if it
+ is clearly the related issue (not a passing mention).
+ (b) A clear problem description in the body (what bug or
+ missing feature this addresses, beyond the title) AND
+ expected vs. actual behavior (or, for features, "what's
+ possible now vs. with this PR").
+
+ (2) END-TO-END QA PROOF: the PR body contains AT LEAST ONE of:
+ (a) A screen recording / video showing the behavior before
+ and after the change (the bug reproducing, then the fix
+ working). For a brand-new feature with no meaningful
+ "before", a recording of it working end-to-end is fine.
+ (b) A screenshot (or before/after screenshots) showing the
+ fix or feature working.
+ (c) Specific commands that were actually run (curl, python,
+ a CLI invocation, etc.) PAIRED WITH their real
+ output, demonstrating the change works end-to-end against
+ the real system. Commands whose external dependencies
+ (LLM provider, DB, network) are mocked or stubbed do NOT
+ satisfy (2c); they are not end-to-end.
+
+ `has_qa_proof` must be set to `true` only when (2a), (2b),
+ or a non-mocked (2c) is actually present in the body. If the
+ only "proof" is mocked tests, `has_qa_proof` is `false` and
+ the verdict is "fail".
+
+ The following do NOT count as QA proof:
+ - Generic claims like "I tested it", "works locally", "all
+ tests pass", or a checked "I added tests" checkbox with no
+ output shown.
+ - A description of what tests exist or were added, without
+ their actual output in the PR body.
+ - `pytest` (or any test runner) executed against the
+ repository's own unit tests. Those mock the LLM provider,
+ DB, and network, so they are NOT end-to-end and never
+ satisfy (2), no matter how much passing output is pasted.
+ - A linked issue. The linked issue is context (1a), never
+ proof (2).
+
+ FAIL the PR if EITHER (1) or (2) is missing. Do not bias toward PASS:
+ if QA proof is absent, the verdict is "fail" even when the rest of
+ the PR is well-written.
+
+ Respond with a single JSON object, no prose:
+
+ {{
+ "verdict": "pass" | "fail",
+ "linked_issue": boolean,
+ "has_problem_description": boolean,
+ "has_expected_vs_actual": boolean,
+ "has_qa_proof": boolean,
+ "qa_proof_type": "video" | "screenshot" | "commands_with_output" | "none",
+ "missing": ["plain-english strings naming what is missing"],
+ "explanation": "1-2 sentence reasoning for the team to skim"
+ }}
+
+ ---
+ PR title: {title}
+
+ PR body:
+ ---
+ {cleaned_body}
+ ---
+ """).strip()
+ return template.format(title=title, cleaned_body=cleaned_body)
+
+
+def build_issue_prompt(*, title: str, body: str) -> str:
+ cleaned_body = strip_html_comments(body or "").strip() or "(empty)"
+ # Dedent the static template *before* interpolating dynamic fields so that
+ # multi-line bodies (whose 2nd+ lines start at column 0) don't defeat the
+ # common-indent computation in textwrap.dedent.
+ template = textwrap.dedent("""
+ You are "Agent Shin", the OSS triage bot for the LiteLLM open-source
+ repository (BerriAI/litellm). Decide whether this GitHub issue meets
+ the project's reporting standards.
+
+ For a BUG REPORT the issue PASSES triage only when it contains BOTH:
+ (1) END-TO-END EVIDENCE OF THE BUG (the "before"; set
+ `has_repro=true` only when this is present): AT LEAST ONE of:
+ (a) A screen recording / video of the bug happening.
+ (b) A screenshot of the bug.
+ (c) The exact command(s) actually run (curl, python, a CLI
+ invocation, etc.) PAIRED WITH their real output, traceback,
+ or logs showing the failure against the real system.
+ Commands whose external dependencies (LLM provider, DB,
+ network) are mocked or stubbed do NOT count.
+ Prose-only "steps to reproduce" with no run output, video, or
+ screenshot do NOT satisfy (1).
+ (2) Expected vs. actual behavior (`has_expected_vs_actual`).
+
+ FAIL the bug report if either (1) or (2) is missing. Do not bias
+ toward PASS: if the bug isn't demonstrated end-to-end, the verdict is
+ "fail" even when the report is well-written.
+
+ For a FEATURE REQUEST the issue PASSES triage only when it contains
+ ALL of:
+ - A clear description of the proposed feature (what should LiteLLM do
+ that it does not today).
+ - Motivation / use case with a concrete example (config, API call,
+ UI flow, or scenario showing what's blocked today).
+
+ For an issue that is neither a bug report nor a feature request (a
+ question, support request, or discussion), PASS as long as it has a
+ clear, specific ask and is not empty or template placeholder text.
+
+ Respond with a single JSON object, no prose:
+
+ {{
+ "verdict": "pass" | "fail",
+ "kind": "bug" | "feature" | "other",
+ "has_repro": boolean,
+ "has_expected_vs_actual": boolean,
+ "has_motivation_example": boolean,
+ "missing": ["plain-english strings naming what is missing"],
+ "explanation": "1-2 sentence reasoning for the team to skim"
+ }}
+
+ ---
+ Issue title: {title}
+
+ Issue body:
+ ---
+ {cleaned_body}
+ ---
+ """).strip()
+ return template.format(title=title, cleaned_body=cleaned_body)
+
+
+# ---------------------------------------------------------------------------
+# LLM call + verdict parsing
+
+
+def call_llm_judge(
+ prompt: str, *, model: str, api_key: str, base_url: str | None
+) -> str:
+ """Call an OpenAI-compatible chat completions endpoint. Returns raw text."""
+ # Import inside the function so unit tests that monkey-patch this never
+ # need the openai package installed.
+ from openai import OpenAI
+
+ client = (
+ OpenAI(api_key=api_key, base_url=base_url)
+ if base_url
+ else OpenAI(api_key=api_key)
+ )
+ kwargs: dict[str, Any] = {
+ "model": model,
+ "messages": [{"role": "user", "content": prompt}],
+ "temperature": 0,
+ "response_format": {"type": "json_object"},
+ }
+ # gpt-5.x reasoning models reject `temperature != 1` unless
+ # `reasoning_effort` is explicitly "none". Set it via `extra_body` so this
+ # works across openai SDK versions regardless of whether the SDK natively
+ # types `reasoning_effort` as a top-level chat-completions param yet.
+ if model.lower().startswith(GPT5_FAMILY_PREFIX):
+ kwargs["extra_body"] = {"reasoning_effort": "none"}
+ response = client.chat.completions.create(**kwargs)
+ return response.choices[0].message.content or ""
+
+
+def parse_verdict(raw: str) -> dict:
+ """Parse the LLM's JSON response. Tolerates ```json fences and stray text."""
+ if not raw:
+ raise ValueError("empty LLM response")
+ text = raw.strip()
+ if text.startswith("```"):
+ text = re.sub(r"^```(?:json)?\s*", "", text)
+ text = re.sub(r"\s*```$", "", text)
+ try:
+ return json.loads(text)
+ except json.JSONDecodeError:
+ match = re.search(r"\{.*\}", text, re.DOTALL)
+ if not match:
+ raise ValueError(f"could not extract JSON from LLM response: {raw[:200]}")
+ return json.loads(match.group(0))
+
+
+# ---------------------------------------------------------------------------
+# Comment composition
+
+
+def _format_missing(missing: list[str]) -> str:
+ if not missing:
+ return "- (see explanation below)"
+ return "\n".join(f"- {m}" for m in missing)
+
+
+# Rubric items the judge can mark present. The first element of each tuple is
+# the verdict-JSON boolean field, the second is the human-readable label we
+# render in the "what you got right" section of close / grace-warning comments.
+_PR_PRESENT_LABELS: tuple[tuple[str, str], ...] = (
+ ("linked_issue", "Linked a related GitHub issue"),
+ ("has_problem_description", "Clear problem description"),
+ ("has_expected_vs_actual", "Expected vs. actual behavior"),
+ ("has_qa_proof", "End-to-end QA proof"),
+)
+
+# Issue rubric labels grouped by `kind`. The judge sets `kind` to one of
+# {"bug", "feature", "other"}; when "other" we render both groups so we don't
+# silently drop a present-flag the judge actually set to True.
+_ISSUE_BUG_LABELS: tuple[tuple[str, str], ...] = (
+ (
+ "has_repro",
+ "End-to-end evidence of the bug (video, screenshot, or command + real output)",
+ ),
+ ("has_expected_vs_actual", "Expected vs. actual behavior"),
+)
+_ISSUE_FEATURE_LABELS: tuple[tuple[str, str], ...] = (
+ ("has_motivation_example", "Motivation and concrete example"),
+)
+
+
+def _format_present_for_pr(verdict: dict) -> list[str]:
+ """Human-readable rubric items the judge confirmed are present on a PR.
+
+ Drives the "what you got right" section in close / grace-warning comments.
+ The user gave explicit feedback: contributors should see what they nailed
+ *before* the list of gaps, so the comment doesn't read as pure rejection.
+ """
+ return [label for field, label in _PR_PRESENT_LABELS if verdict.get(field)]
+
+
+def _format_present_for_issue(verdict: dict) -> list[str]:
+ """Human-readable rubric items the judge confirmed are present on an issue.
+
+ Branches on the judge's `kind` field. For `"other"` (or missing kind) we
+ render the union so a present-flag isn't dropped just because the judge
+ couldn't classify the issue cleanly.
+ """
+ kind = (verdict.get("kind") or "").lower()
+ groups: list[tuple[tuple[str, str], ...]] = []
+ if kind in ("bug", "other", ""):
+ groups.append(_ISSUE_BUG_LABELS)
+ if kind in ("feature", "other", ""):
+ groups.append(_ISSUE_FEATURE_LABELS)
+ out: list[str] = []
+ for group in groups:
+ for field, label in group:
+ if verdict.get(field) and label not in out:
+ out.append(label)
+ return out
+
+
+def _format_present_block(items: list[str]) -> str:
+ """Render the optional "what you got right" block. Empty string when the
+ judge didn't confirm anything as present — better to omit the section
+ entirely than to show "What you got right: (nothing)".
+ """
+ if not items:
+ return ""
+ bullets = "\n".join(f"- ✅ {item}" for item in items)
+ return f"**What you got right:**\n\n{bullets}\n\n"
+
+
+def format_pr_close_comment(verdict: dict) -> str:
+ missing_lines = _format_missing(verdict.get("missing") or [])
+ present_block = _format_present_block(_format_present_for_pr(verdict))
+ explanation = verdict.get("explanation") or ""
+ return (
+ "🚅 Hi, thanks for the PR! I'm **Agent Shin**, the automated triage bot for this "
+ "repository. "
+ "[What's this and why am I getting it?](https://docs.litellm.ai/blog/agent-shin-triage)\n"
+ "\n"
+ "I read the description against our "
+ "[contribution rubric](https://github.com/BerriAI/litellm/blob/main/.github/pull_request_template.md). "
+ "Here's how it lined up:\n"
+ "\n"
+ f"{present_block}"
+ "**What's still missing:**\n"
+ "\n"
+ f"{missing_lines}\n"
+ "\n"
+ f"> {explanation}\n"
+ "\n"
+ "**Closing this PR isn't a rejection of the change.** We want the open-PR list to "
+ "mirror what a maintainer can act on *right now*, so contributors don't get lost in a "
+ 'backlog. A closed PR is a soft "park this for later"; your work is still here, '
+ "the diff is still here, and getting it reopened is one comment away. Take your time.\n"
+ "\n"
+ "**To bring this PR back:**\n"
+ "\n"
+ "- Update the description with the missing pieces, then comment `@agent-shin reconsider` "
+ "on this PR. I'll re-evaluate and reopen if it now passes.\n"
+ "- Or **Open a new PR** with the same fix and the updated description. GitHub doesn't "
+ "always let external contributors reopen a bot-closed PR, so a fresh PR is the most "
+ "reliable path back into the review queue.\n"
+ "- If Greptile's most recent score on this PR was below 4/5, comment `@greptileai` to "
+ "request a fresh review; that **still works even after the PR is closed**, and a "
+ "stronger score is one of the signals that lifts the PR back into the queue. A low "
+ "Greptile score isn't a blocker.\n"
+ "\n"
+ '**What "end-to-end QA proof" means**, since it\'s the most common gap: at least one '
+ "of a short before/after screen recording / video (the bug reproducing, then the fix "
+ "working; for a brand-new feature, a recording of it working end-to-end), a screenshot "
+ "(or before/after screenshots) of it working, or the exact commands you ran paired "
+ "with their **real output** against the real system. Running `pytest` on the repo's "
+ "unit tests doesn't count; those mock the LLM provider, DB, and network, so they "
+ "aren't end-to-end. Output from a real, no-mocks integration run is what we look "
+ "for. A linked issue alone isn't enough either: it covers context, not proof. See "
+ "[the full rubric](https://docs.litellm.ai/blog/agent-shin-triage#the-rubric-for-pull-requests).\n"
+ "\n"
+ "Internal BerriAI contributors: this rubric doesn't apply to you; ping a maintainer.\n"
+ "\n"
+ "_(I'm an LLM, so I'm not infallible. If you think I got this wrong, comment "
+ "`@agent-shin reconsider` or ping a maintainer; they'll override me.)_"
+ f"\n\n{AGENT_SHIN_CLOSE_MARKER}"
+ )
+
+
+def format_issue_close_comment(verdict: dict) -> str:
+ missing_lines = _format_missing(verdict.get("missing") or [])
+ present_block = _format_present_block(_format_present_for_issue(verdict))
+ explanation = verdict.get("explanation") or ""
+ return (
+ "🚅 Hi, thanks for filing this! I'm **Agent Shin**, the automated triage bot for this "
+ "repository. "
+ "[What's this and why am I getting it?](https://docs.litellm.ai/blog/agent-shin-triage)\n"
+ "\n"
+ "I read the issue against our reporting checklist. Here's how it lined up:\n"
+ "\n"
+ f"{present_block}"
+ "**What's still missing:**\n"
+ "\n"
+ f"{missing_lines}\n"
+ "\n"
+ f"> {explanation}\n"
+ "\n"
+ "**Closing this isn't us saying the bug isn't real or the request isn't useful.** We "
+ "want the open-issue list to mirror what a maintainer can act on *right now*, so "
+ "reports like yours don't get buried in a backlog. A closed issue is a soft \"park "
+ 'this for later"; your report is still here, and getting it reopened is one comment '
+ "away. Take your time.\n"
+ "\n"
+ "**To bring this issue back:**\n"
+ "\n"
+ "1. Edit the issue description to add the missing pieces:\n"
+ " - For **bug reports**: end-to-end evidence of the bug (a screen recording / "
+ "video, a screenshot, or the exact commands you ran with their real output / "
+ "traceback) plus expected vs. actual behavior. Written steps with no run output, "
+ "video, or screenshot don't count, and mocked or stubbed runs don't count.\n"
+ " - For **feature requests**: a concrete description of what should change, plus a "
+ "use case and example (config / API call / UI flow).\n"
+ "2. Comment `@agent-shin reconsider`. I'll re-run triage and reopen the issue if it "
+ "now meets the bar. (GitHub doesn't let external authors reopen an issue a maintainer "
+ "or bot closed, so the comment-based reconsider is the reliable path.)\n"
+ "\n"
+ "Internal BerriAI contributors: this rubric doesn't apply to you; ping a maintainer.\n"
+ "\n"
+ "_(I'm an LLM, so I'm not infallible. If you think I got this wrong, comment "
+ "`@agent-shin reconsider` or ping a maintainer; they'll override me.)_"
+ f"\n\n{AGENT_SHIN_CLOSE_MARKER}"
+ )
+
+
+def format_grace_warning_pr_comment(verdict: dict) -> str:
+ """Comment posted on the FIRST low-quality detection — gives the
+ contributor a 2-hour grace window to fix the PR before the next
+ triage run actually closes it.
+
+ This is the "before-close" warning. On the second triage run, if the
+ grace marker is older than `GRACE_PERIOD_SECONDS` AND the PR still
+ fails the rubric, the close path runs (which posts
+ `format_pr_close_comment` and closes the PR).
+ """
+ missing_lines = _format_missing(verdict.get("missing") or [])
+ present_block = _format_present_block(_format_present_for_pr(verdict))
+ explanation = verdict.get("explanation") or ""
+ return (
+ "🚅 Hi, thanks for the PR! I'm **Agent Shin**, the automated triage bot for this "
+ "repository. "
+ "[What's this and why am I getting it?](https://docs.litellm.ai/blog/agent-shin-triage)\n"
+ "\n"
+ "I read the description against our "
+ "[contribution rubric](https://github.com/BerriAI/litellm/blob/main/.github/pull_request_template.md). "
+ "Here's how it lined up:\n"
+ "\n"
+ f"{present_block}"
+ "**What's still missing:**\n"
+ "\n"
+ f"{missing_lines}\n"
+ "\n"
+ f"> {explanation}\n"
+ "\n"
+ "If the description isn't updated in the next **2 hours**, I'll auto-close this PR. "
+ "That's **not** us saying we don't care about the change; we want the open-PR list to "
+ "mirror what a maintainer can act on *right now*, so contributors don't get lost in a "
+ 'backlog. A closed PR is a soft "park this for later," not a rejection. Take your '
+ "time; everything below still works after the close.\n"
+ "\n"
+ "**During the grace period:** just update the PR description with the missing pieces. "
+ "No need to ping me; I'll re-check on the next sweep and skip the auto-close if it "
+ "now passes. See "
+ "[what counts as QA proof](https://docs.litellm.ai/blog/agent-shin-triage#the-rubric-for-pull-requests) "
+ "for the full rubric (a linked issue alone isn't enough; it covers context, not proof).\n"
+ "\n"
+ "**If the PR does get auto-closed in 2 hours, you still have easy recovery paths:**\n"
+ "\n"
+ "- Comment `@agent-shin reconsider` after updating the description. I'll re-evaluate "
+ "and reopen the PR if it now passes.\n"
+ "- Comment `@greptileai` to request a fresh Greptile review; that **still works even "
+ "after the PR is closed**, and a stronger score is one of the signals that lifts the "
+ "PR back into the queue. So a low Greptile score isn't a blocker either.\n"
+ "\n"
+ "Internal BerriAI contributors: this rubric doesn't apply to you; ping a maintainer.\n"
+ "\n"
+ "_(I'm an LLM, so I'm not infallible. If you think I got this wrong, ping a "
+ "maintainer; they'll override me.)_\n"
+ "\n"
+ f"{GRACE_COMMENT_MARKER}"
+ )
+
+
+def format_grace_warning_issue_comment(verdict: dict) -> str:
+ """Issue analogue of `format_grace_warning_pr_comment`."""
+ missing_lines = _format_missing(verdict.get("missing") or [])
+ present_block = _format_present_block(_format_present_for_issue(verdict))
+ explanation = verdict.get("explanation") or ""
+ return (
+ "🚅 Hi, thanks for filing this! I'm **Agent Shin**, the automated triage bot for this "
+ "repository. "
+ "[What's this and why am I getting it?](https://docs.litellm.ai/blog/agent-shin-triage)\n"
+ "\n"
+ "I read the issue against our reporting checklist. Here's how it lined up:\n"
+ "\n"
+ f"{present_block}"
+ "**What's still missing:**\n"
+ "\n"
+ f"{missing_lines}\n"
+ "\n"
+ f"> {explanation}\n"
+ "\n"
+ "If the issue isn't updated in the next **2 hours**, I'll auto-close it. That's **not** us "
+ "saying the bug isn't real or the request isn't useful; we want the open-issue list "
+ "to mirror what a maintainer can act on *right now*, so reports like yours don't get "
+ 'buried in a backlog. A closed issue is a soft "park this for later," not a '
+ "rejection. Take your time; reopening is one comment away.\n"
+ "\n"
+ "**During the grace period:** just edit the issue description with the missing "
+ "pieces. No need to ping me; I'll re-check on the next sweep and skip the auto-close "
+ "if it now passes.\n"
+ "\n"
+ "Missing pieces, depending on what this is:\n"
+ "\n"
+ "- For **bug reports**: end-to-end evidence of the bug (a screen recording / video, a "
+ "screenshot, or the exact commands you ran with their real output / traceback) plus "
+ "expected vs. actual behavior. Written steps with no run output don't count, and "
+ "mocked or stubbed runs don't count.\n"
+ "- For **feature requests**: a concrete description of what should change, plus a use "
+ "case and example (config / API call / UI flow).\n"
+ "\n"
+ "**If the issue does get auto-closed in 2 hours**, comment `@agent-shin reconsider` "
+ "and I'll re-evaluate. If it now meets the bar, I'll reopen the issue.\n"
+ "\n"
+ "Internal BerriAI contributors: this rubric doesn't apply to you; ping a maintainer.\n"
+ "\n"
+ "_(I'm an LLM, so I'm not infallible. If you think I got this wrong, ping a "
+ "maintainer; they'll override me.)_\n"
+ "\n"
+ f"{GRACE_COMMENT_MARKER}"
+ )
+
+
+# ---------------------------------------------------------------------------
+# Step-summary helpers
+
+
+def write_step_summary(content: str) -> None:
+ """When running inside GitHub Actions, append to the step summary file."""
+ path = os.environ.get("GITHUB_STEP_SUMMARY")
+ if not path:
+ return
+ try:
+ with open(path, "a", encoding="utf-8") as handle:
+ handle.write(content)
+ if not content.endswith("\n"):
+ handle.write("\n")
+ except OSError as exc:
+ print(f"warn: failed to write step summary: {exc}", file=sys.stderr)
+
+
+# ---------------------------------------------------------------------------
+# Core orchestration
+
+
+def format_reopen_comment(kind: str) -> str:
+ """Comment posted when Agent Shin reopens after a successful reconsider."""
+ noun = "PR" if kind == "pr" else "issue"
+ # The trailing HTML marker is used by `seconds_since_last_reconsider_verdict`
+ # to enforce a cooldown between repeated `@agent-shin reconsider` triggers.
+ # Keep the marker on its own line so it doesn't disturb the rendered text.
+ return (
+ f"♻️ **Re-evaluated and reopened.** Thanks for updating the {noun}!\n"
+ "\n"
+ "Agent Shin re-ran triage on the latest description and it now meets "
+ "the bar. A maintainer will take another look soon; please don't "
+ f"close this {noun} again unless asked to.\n"
+ "\n"
+ "_(If a maintainer ends up closing this for non-rubric reasons, that "
+ "decision stands; comment `@agent-shin reconsider` again only if you "
+ "have substantively new information.)_\n"
+ "\n"
+ f"{RECONSIDER_COMMENT_MARKER}"
+ )
+
+
+def format_reconsider_still_failing_comment(kind: str, verdict: dict) -> str:
+ """Comment posted when reconsider re-runs triage but the verdict is still fail."""
+ missing_lines = _format_missing(verdict.get("missing") or [])
+ explanation = verdict.get("explanation") or ""
+ noun = "PR" if kind == "pr" else "issue"
+ # The trailing HTML marker is used by `seconds_since_last_reconsider_verdict`
+ # to enforce a cooldown between repeated `@agent-shin reconsider` triggers.
+ return (
+ f"⏸️ **Re-evaluated; this {noun} still doesn't meet the rubric.**\n"
+ "\n"
+ "Agent Shin re-ran triage on the current description but is still "
+ "missing:\n"
+ "\n"
+ f"{missing_lines}\n"
+ "\n"
+ f"> {explanation}\n"
+ "\n"
+ "Update the description with the missing pieces and comment "
+ "`@agent-shin reconsider` again, or ping a maintainer if you think "
+ "I got this wrong.\n"
+ "\n"
+ "_(I'm an LLM and I'm not infallible.)_\n"
+ "\n"
+ f"{RECONSIDER_COMMENT_MARKER}"
+ )
+
+
+# ---------------------------------------------------------------------------
+# Review gate — "ready for review" label lifecycle
+
+_UNSET = object()
+
+
+def _combine_missing(
+ verdict: dict, greptile_score: int | None, min_score: int
+) -> list[str]:
+ """Merge the LLM rubric's `missing` list with a Greptile-score shortfall."""
+ missing = list(verdict.get("missing") or [])
+ if greptile_score is not None and greptile_score < min_score:
+ missing.insert(
+ 0,
+ f"Greptile's most recent review scored this PR {greptile_score}/5 "
+ f"(below the {min_score}/5 bar)",
+ )
+ return missing or ["(see explanation below)"]
+
+
+def _has_marker(
+ comments: Iterable[dict], marker: str, *, bot_login: str | None = None
+) -> bool:
+ """Return True iff the bot itself posted a comment containing ``marker``.
+
+ Filters by author so a contributor who quotes the marker (e.g. via
+ GitHub's "Quote reply" feature, which preserves HTML comments in
+ raw markdown) is not mistaken for a bot action — that would
+ silently suppress notifications or change which "recovered" wording
+ is selected. Matches the author-filter pattern used by the sibling
+ `_seconds_since_latest_marker_comment` helper.
+ """
+ expected_login = (
+ bot_login
+ or os.environ.get("AGENT_SHIN_BOT_LOGIN")
+ or AGENT_SHIN_DEFAULT_BOT_LOGIN
+ ).lower()
+ for comment in comments:
+ author = ((comment.get("user") or {}).get("login") or "").lower()
+ if author != expected_login:
+ continue
+ if marker in (comment.get("body") or ""):
+ return True
+ return False
+
+
+def format_ready_for_review_comment(
+ verdict: dict,
+ greptile_score: int | None,
+ min_greptile_score: int = DEFAULT_MIN_GREPTILE_SCORE,
+) -> str:
+ """Posted the first time a PR clears the bar (label added)."""
+ score_line = (
+ f" Greptile scored it **{greptile_score}/5**."
+ if greptile_score is not None
+ else ""
+ )
+ explanation = verdict.get("explanation") or ""
+ return (
+ "✅ **Triage passed, tagging `ready for review`.**\n"
+ "\n"
+ "Agent Shin checked this PR against the "
+ "[contribution rubric](https://github.com/BerriAI/litellm/blob/main/.github/pull_request_template.md) "
+ "and it clears the bar (a linked issue, or a clear problem description "
+ f"+ expected vs. actual + QA proof).{score_line}\n"
+ "\n"
+ f"> {explanation}\n"
+ "\n"
+ "A maintainer will take it from here. If a later re-check finds the PR "
+ f"has regressed (Greptile drops below {min_greptile_score}/5, "
+ "the QA proof is removed, etc.) I'll pull the tag and comment with "
+ "what's missing; fix it and the tag comes back automatically.\n"
+ f"{READY_MARKER}"
+ )
+
+
+def format_all_clear_comment(verdict: dict, greptile_score: int | None) -> str:
+ """Posted when a PR recovers after a regression (label re-added)."""
+ score_line = (
+ f" Greptile is back to **{greptile_score}/5**."
+ if greptile_score is not None
+ else ""
+ )
+ explanation = verdict.get("explanation") or ""
+ return (
+ "✅ **All clear again, re-adding `ready for review`.**\n"
+ "\n"
+ "Thanks for addressing the earlier feedback. On re-check this PR meets "
+ f"the contribution bar once more.{score_line}\n"
+ "\n"
+ f"> {explanation}\n"
+ "\n"
+ "A maintainer will take another look.\n"
+ f"{READY_MARKER}"
+ )
+
+
+def format_regression_comment(
+ missing: list[str], explanation: str, grace_days: int
+) -> str:
+ """Posted when a previously-tagged PR regresses (label removed, PR stays open).
+
+ Discloses the same ``grace_days`` deadline the state machine enforces:
+ once that window elapses with the PR still failing, the close path fires.
+ Hiding the deadline behind a bare "stays open" would surprise contributors
+ with an auto-close they were never warned about.
+ """
+ window = "24 hours" if grace_days == 1 else f"{grace_days} days"
+ return (
+ "⚠️ **Removing the `ready for review` tag.**\n"
+ "\n"
+ "On a re-check this PR no longer meets the contribution bar. What's "
+ "missing now:\n"
+ "\n"
+ f"{_format_missing(missing)}\n"
+ "\n"
+ f"> {explanation}\n"
+ "\n"
+ f"The PR stays open for ~{window}; address the points above and Agent "
+ 'Shin will post an "all clear" comment and re-add the tag '
+ "automatically. If the points still aren't addressed after that "
+ "window, the PR is auto-closed; that's not a rejection, and you can "
+ "comment `@agent-shin reconsider` to have it re-evaluated and reopened "
+ "once it passes.\n"
+ f"{REGRESSED_MARKER}"
+ )
+
+
+def format_within_grace_comment(
+ missing: list[str], explanation: str, grace_days: int
+) -> str:
+ """Posted once while a failing PR is still inside its grace window."""
+ window = "24 hours" if grace_days == 1 else f"{grace_days} days"
+ return (
+ "🚅 Hi, thanks for the PR! This is **Agent Shin**, the automated triage "
+ "bot. This PR doesn't quite meet the contribution bar yet:\n"
+ "\n"
+ f"{_format_missing(missing)}\n"
+ "\n"
+ f"> {explanation}\n"
+ "\n"
+ f"You have ~{window} from when this PR was opened to add the missing "
+ "pieces; just update the description and I'll re-check on the next "
+ "sweep. Once it passes I'll tag it `ready for review`. If it does get "
+ "auto-closed, that's not a rejection; comment `@agent-shin reconsider` "
+ "and I'll re-evaluate and reopen if it now passes.\n"
+ f"{WITHIN_GRACE_MARKER}"
+ )
+
+
+def review_gate(
+ *,
+ repo: str,
+ number: int,
+ close: bool,
+ model: str,
+ judge: Any = None,
+ greptile_score: Any = _UNSET,
+ comments: Any = _UNSET,
+ now: dt.datetime | None = None,
+ grace_days: int = DEFAULT_GRACE_DAYS,
+ min_greptile_score: int = DEFAULT_MIN_GREPTILE_SCORE,
+ label: str = READY_FOR_REVIEW_LABEL,
+ allowlist: frozenset[str] = ALLOWLIST_LOGINS,
+) -> dict:
+ """Reconcile the `ready for review` label with a PR's current quality.
+
+ A PR is *passing* when it clears BOTH gates: the LLM rubric (linked issue,
+ or problem description + expected/actual + QA proof) AND Greptile's most
+ recent confidence score (>= ``min_greptile_score``; absence of a score is
+ not held against the PR). The gate then drives a small state machine, using
+ the label itself as the persisted state so comments fire only on
+ transitions (never on every scheduled run):
+
+ passing, untagged -> add label + "ready for review" / "all clear"
+ passing, tagged -> noop-passing
+ not passing, tagged -> remove label + regression comment (stays open)
+ not passing, untagged, old -> close + comment (past the grace window)
+ not passing, untagged, new -> one-time "what's missing" notice (within grace)
+
+ ``close`` gates every destructive side effect: with ``close=False`` the
+ function returns a ``would-*`` preview and touches nothing, mirroring the
+ dry-run contract of :func:`triage`. ``judge``/``greptile_score``/
+ ``comments``/``now`` are injectable for tests; in production they are
+ resolved from the OpenAI judge, the PR's Greptile comment, the live comment
+ list, and the wall clock respectively.
+ """
+ item = fetch_pr(repo, number)
+
+ title = item.get("title") or ""
+ body = item.get("body") or ""
+ login = (item.get("user") or {}).get("login") or ""
+ association = item.get("author_association") or ""
+ state = item.get("state") or ""
+ # GitHub label names are case-insensitive; compare lowercased so a repo
+ # that already has e.g. "Ready for Review" is recognized as the same
+ # label as our READY_FOR_REVIEW_LABEL constant ("ready for review").
+ labels_now = {(lbl.get("name") or "").lower() for lbl in (item.get("labels") or [])}
+ label_key = label.lower()
+ created_raw = item.get("created_at") or ""
+
+ base_result = {
+ "kind": "pr",
+ "number": number,
+ "title": title,
+ "author": login,
+ "author_association": association,
+ "state": state,
+ "labeled": label_key in labels_now,
+ "review_gate": True,
+ }
+
+ if state != "open":
+ return {**base_result, "action": "skip-not-open"}
+
+ if allowlist:
+ if login.lower() not in allowlist:
+ return {**base_result, "action": "skip-not-allowlisted"}
+ elif is_internal_contributor(item):
+ return {**base_result, "action": "skip-internal-author"}
+
+ # Resolve the comment list once — used for both the Greptile score and the
+ # marker-based dedup below.
+ if comments is _UNSET:
+ comments = list(_iter_paginated_json(f"repos/{repo}/issues/{number}/comments"))
+
+ # --- rubric verdict: linked-issue short-circuit, else the LLM judge -------
+ if has_linked_issue(body):
+ verdict = {
+ "verdict": "pass",
+ "linked_issue": True,
+ "missing": [],
+ "explanation": "Linked-issue regex matched; LLM was not called.",
+ }
+ rubric_pass = True
+ else:
+ prompt = build_pr_prompt(title=title, body=body)
+ if judge is None:
+ api_key = os.environ.get("OPENAI_API_KEY")
+ if not api_key:
+ return {**base_result, "action": "skip-no-llm-key"}
+ base_url = os.environ.get("OPENAI_BASE_URL") or None
+
+ def judge(p: str) -> str:
+ return call_llm_judge(
+ p, model=model, api_key=api_key, base_url=base_url
+ )
+
+ try:
+ verdict = parse_verdict(judge(prompt))
+ except Exception as exc: # noqa: BLE001 - judge errors must never act
+ return {**base_result, "action": "skip-llm-error", "error": str(exc)}
+ rubric_pass = (verdict.get("verdict") or "").lower() == "pass"
+
+ # --- Greptile score -------------------------------------------------------
+ if greptile_score is _UNSET:
+ extraction = extract_greptile_score(comments)
+ greptile_score = extraction[0] if extraction else None
+ greptile_ok = greptile_score is None or greptile_score >= min_greptile_score
+ passing = rubric_pass and greptile_ok
+
+ # --- age ------------------------------------------------------------------
+ age_days = None
+ if created_raw:
+ reference = now or dt.datetime.now(dt.timezone.utc)
+ age_days = (reference - parse_iso8601(created_raw)).days
+
+ label_present = label_key in labels_now
+ explanation = verdict.get("explanation") or ""
+ # When the rubric short-circuited to pass (linked-issue regex) but
+ # Greptile dragged the PR below the bar, the synthetic verdict's
+ # explanation ("LLM was not called") would mislead a contributor reading
+ # the regression / close comment. Surface the real reason instead.
+ if rubric_pass and not greptile_ok:
+ explanation = (
+ f"Greptile's most recent review scored this PR "
+ f"{greptile_score}/5 (below the {min_greptile_score}/5 bar)."
+ )
+ verdict = {**verdict, "explanation": explanation}
+ base_result = {
+ **base_result,
+ "verdict": verdict,
+ "greptile_score": greptile_score,
+ "passing": passing,
+ "age_days": age_days,
+ }
+
+ if passing:
+ if label_present:
+ return {**base_result, "action": "noop-passing"}
+ recovered = _has_marker(comments, REGRESSED_MARKER)
+ comment = (
+ format_all_clear_comment(verdict, greptile_score)
+ if recovered
+ else format_ready_for_review_comment(
+ verdict, greptile_score, min_greptile_score
+ )
+ )
+ if not close:
+ return {**base_result, "action": "would-label-ready", "comment": comment}
+ post_comment(repo, number, comment)
+ add_label(repo, number, label)
+ return {**base_result, "action": "labeled-ready", "comment": comment}
+
+ missing = _combine_missing(verdict, greptile_score, min_greptile_score)
+
+ if label_present:
+ comment = format_regression_comment(missing, explanation, grace_days)
+ if not close:
+ return {**base_result, "action": "would-remove-label", "comment": comment}
+ remove_label(repo, number, label)
+ post_comment(repo, number, comment)
+ return {**base_result, "action": "label-removed-regressed", "comment": comment}
+
+ # Not passing and not tagged. If the PR was previously tagged and then
+ # regressed (we removed the label and posted REGRESSED_MARKER), honor the
+ # "PR stays open — fix it and the tag comes back" promise from
+ # `format_regression_comment` and skip the close path. Without this guard,
+ # any PR older than `grace_days` would be closed on the next evaluation,
+ # giving the contributor no realistic window to address the regression.
+ #
+ # The promise has a deliberate expiration: once `grace_days` have elapsed
+ # since the regression notice, fall through to the close path so a PR that
+ # was abandoned post-regression doesn't sit open forever.
+ if _has_marker(comments, REGRESSED_MARKER):
+ reference = now or dt.datetime.now(dt.timezone.utc)
+ seconds_since_regression = seconds_since_latest_marker_comment(
+ comments, marker=REGRESSED_MARKER, now=reference
+ )
+ grace_seconds = grace_days * 86400
+ if seconds_since_regression is None or seconds_since_regression < grace_seconds:
+ return {**base_result, "action": "regressed-already-notified"}
+
+ # Not passing and not tagged: close if past the grace window, else notify once.
+ if age_days is not None and age_days >= grace_days:
+ comment = format_pr_close_comment({**verdict, "missing": missing})
+ if not close:
+ return {**base_result, "action": "would-close", "comment": comment}
+ post_comment(repo, number, comment)
+ close_pr(repo, number)
+ return {**base_result, "action": "closed", "comment": comment}
+
+ if _has_marker(comments, WITHIN_GRACE_MARKER):
+ return {**base_result, "action": "within-grace-already-notified"}
+ comment = format_within_grace_comment(missing, explanation, grace_days)
+ if not close:
+ return {
+ **base_result,
+ "action": "would-notify-within-grace",
+ "comment": comment,
+ }
+ post_comment(repo, number, comment)
+ return {**base_result, "action": "within-grace-notified", "comment": comment}
+
+
+def triage(
+ *,
+ repo: str,
+ kind: str,
+ number: int,
+ close: bool,
+ model: str,
+ judge: Any = None,
+ print_prompt: bool = False,
+ reconsider: bool = False,
+ allowlist: frozenset[str] = ALLOWLIST_LOGINS,
+) -> dict:
+ """Triage a single PR or issue. Returns a result dict for logging/tests.
+
+ `judge` is an optional callable `(prompt) -> str` for tests / dry-run with
+ a stub. In production, leave it None and the script uses `call_llm_judge`.
+
+ When `reconsider=True`, the closed-state guard is skipped and a
+ fail-but-no-comment is replaced with a "still failing" comment + leave
+ closed; a pass triggers `reopen_pr`/`reopen_issue` plus a reopen comment.
+ Reconsider mode is intended for the `@agent-shin reconsider` comment
+ trigger. Like regular triage, `close=False` keeps reconsider in dry-run
+ (returns `would-reopen` / `would-reconsider-still-failing` so a local
+ operator can preview without write side effects); the workflow only
+ passes `--close` when `AGENT_SHIN_ENABLED=true`.
+
+ Reconsider mode adds two extra safety guards on top of the regular
+ triage skip-internal-author check:
+
+ 1. **Bot-closed guard.** Only reopens if the most recent close was
+ performed by the bot identity (default `github-actions[bot]`).
+ This stops a contributor from using `@agent-shin reconsider` to
+ override a maintainer's close for non-rubric reasons.
+ 2. **Rate-limit guard.** If the bot has already posted a reconsider
+ verdict on this PR/issue within `RECONSIDER_RATE_LIMIT_SECONDS`,
+ skip — repeated triggers from the same contributor shouldn't burn
+ CI minutes or LLM budget.
+ """
+ fetcher = {"pr": fetch_pr, "issue": fetch_issue}[kind]
+ item = fetcher(repo, number)
+
+ title = item.get("title") or ""
+ body = item.get("body") or ""
+ login = (item.get("user") or {}).get("login") or ""
+ association = item.get("author_association") or ""
+ state = item.get("state") or ""
+
+ base_result = {
+ "kind": kind,
+ "number": number,
+ "title": title,
+ "author": login,
+ "author_association": association,
+ "state": state,
+ "reconsider": reconsider,
+ }
+
+ # Reconsider only makes sense on a closed PR/issue. A "reconsider on an
+ # open PR" is a no-op (the regular triage flow already evaluates open
+ # PRs); return a clear skip so the workflow can short-circuit.
+ if reconsider:
+ if state != "closed":
+ return {**base_result, "action": "skip-not-closed"}
+ else:
+ if state != "open":
+ return {**base_result, "action": "skip-not-open"}
+
+ if allowlist:
+ if login.lower() not in allowlist:
+ return {**base_result, "action": "skip-not-allowlisted"}
+ elif is_internal_contributor(item):
+ return {**base_result, "action": "skip-internal-author"}
+
+ # Reconsider-only guards — these run BEFORE the LLM call so a
+ # maintainer-closed PR / rate-limited trigger never spends LLM budget.
+ if reconsider:
+ if not was_closed_by_agent_shin(repo, number):
+ return {**base_result, "action": "skip-not-bot-closed"}
+ age = seconds_since_last_reconsider_verdict(repo, number)
+ if age is not None and age < RECONSIDER_RATE_LIMIT_SECONDS:
+ return {
+ **base_result,
+ "action": "skip-rate-limited",
+ "rate_limit_age_seconds": age,
+ "rate_limit_window_seconds": RECONSIDER_RATE_LIMIT_SECONDS,
+ }
+
+ if kind == "pr":
+ # Short-circuit: if body very clearly links a related issue, just pass.
+ if has_linked_issue(body):
+ base = {
+ **base_result,
+ "action": "pass-linked-issue",
+ "verdict": {
+ "verdict": "pass",
+ "linked_issue": True,
+ "explanation": "Linked-issue regex matched; LLM was not called.",
+ },
+ }
+ if reconsider:
+ # Pass-on-reconsider -> reopen the PR with a friendly comment.
+ reopen_body = format_reopen_comment(kind)
+ if not close:
+ return {
+ **base,
+ "action": "would-reopen",
+ "comment": reopen_body,
+ }
+ post_comment(repo, number, reopen_body)
+ reopen_pr(repo, number)
+ return {
+ **base,
+ "action": "reopened",
+ "comment": reopen_body,
+ }
+ return base
+ prompt = build_pr_prompt(title=title, body=body)
+ else:
+ prompt = build_issue_prompt(title=title, body=body)
+
+ if print_prompt:
+ return {**base_result, "action": "print-prompt", "prompt": prompt}
+
+ if judge is None:
+ api_key = os.environ.get("OPENAI_API_KEY")
+ if not api_key:
+ # No key configured — never take a destructive action. Report skip.
+ return {
+ **base_result,
+ "action": "skip-no-llm-key",
+ "prompt_preview": prompt[:200],
+ }
+ base_url = os.environ.get("OPENAI_BASE_URL") or None
+
+ def judge(p: str) -> str:
+ return call_llm_judge(p, model=model, api_key=api_key, base_url=base_url)
+
+ try:
+ raw = judge(prompt)
+ verdict = parse_verdict(raw)
+ except Exception as exc: # noqa: BLE001 - judge errors must never close PRs
+ return {**base_result, "action": "skip-llm-error", "error": str(exc)}
+
+ decision = (verdict.get("verdict") or "").lower()
+
+ if reconsider:
+ # Reconsider: an explicit `pass` -> reopen + post reopen comment;
+ # anything else (fail, missing/malformed verdict, typo) -> leave
+ # closed + post a "still failing" comment so the contributor can
+ # iterate again. Reopen is destructive, so a flaky/empty verdict
+ # must not satisfy the gate.
+ # In dry-run (`close=False`) we return `would-*` actions instead
+ # of touching GitHub state, mirroring the regular triage flow's
+ # `would-close`. This lets a local operator preview the outcome
+ # of `python triage_with_llm.py --reconsider --pr N` without
+ # risking accidental comments or reopens.
+ if decision == "pass":
+ reopen_body = format_reopen_comment(kind)
+ if not close:
+ return {
+ **base_result,
+ "action": "would-reopen",
+ "verdict": verdict,
+ "comment": reopen_body,
+ }
+ post_comment(repo, number, reopen_body)
+ if kind == "pr":
+ reopen_pr(repo, number)
+ else:
+ reopen_issue(repo, number)
+ return {
+ **base_result,
+ "action": "reopened",
+ "verdict": verdict,
+ "comment": reopen_body,
+ }
+ still_failing = format_reconsider_still_failing_comment(kind, verdict)
+ if not close:
+ return {
+ **base_result,
+ "action": "would-reconsider-still-failing",
+ "verdict": verdict,
+ "comment": still_failing,
+ }
+ post_comment(repo, number, still_failing)
+ return {
+ **base_result,
+ "action": "reconsider-still-failing",
+ "verdict": verdict,
+ "comment": still_failing,
+ }
+
+ if decision != "fail":
+ return {**base_result, "action": "pass-llm", "verdict": verdict}
+
+ # Grace-period flow: on the first low-quality detection, post a warning
+ # comment instead of closing immediately. On a subsequent triage run
+ # (manual re-trigger, or the daily `close_low_quality_prs.py` cron
+ # finding the same PR in its own pass), if `GRACE_PERIOD_SECONDS` has
+ # elapsed since the warning AND the PR still fails the rubric, close.
+ grace_age = seconds_since_last_grace_warning(repo, number)
+ if grace_age is None:
+ warning_body = (
+ format_grace_warning_pr_comment(verdict)
+ if kind == "pr"
+ else format_grace_warning_issue_comment(verdict)
+ )
+ if not close:
+ return {
+ **base_result,
+ "action": "would-warn-grace",
+ "verdict": verdict,
+ "comment": warning_body,
+ }
+ post_comment(repo, number, warning_body)
+ return {
+ **base_result,
+ "action": "warned-grace",
+ "verdict": verdict,
+ "comment": warning_body,
+ }
+ if grace_age < GRACE_PERIOD_SECONDS:
+ return {
+ **base_result,
+ "action": "skip-in-grace-period",
+ "verdict": verdict,
+ "grace_age_seconds": grace_age,
+ "grace_period_seconds": GRACE_PERIOD_SECONDS,
+ }
+
+ # The grace window has elapsed. `--close` still gates the destructive
+ # write so a dry-run preview never posts or closes — the workflow only
+ # passes `--close` when `AGENT_SHIN_ENABLED=true`, which keeps the bot
+ # inert by default.
+ if not close:
+ return {**base_result, "action": "would-close", "verdict": verdict}
+
+ comment_body = (
+ format_pr_close_comment(verdict)
+ if kind == "pr"
+ else format_issue_close_comment(verdict)
+ )
+ post_comment(repo, number, comment_body)
+ if kind == "pr":
+ close_pr(repo, number)
+ else:
+ close_issue(repo, number)
+
+ return {
+ **base_result,
+ "action": "closed",
+ "verdict": verdict,
+ "comment": comment_body,
+ }
+
+
+# ---------------------------------------------------------------------------
+# CLI
+
+
+def render_summary(result: dict) -> str:
+ """Render a human-readable summary block (used for stdout + step summary)."""
+ lines = ["## Agent Shin verdict", ""]
+ lines.append(
+ f"- **{result['kind'].upper()} #{result['number']}**: {result.get('title', '')}"
+ )
+ lines.append(
+ f"- **Author**: `{result.get('author', '')}` ({result.get('author_association', '')})"
+ )
+ lines.append(f"- **State**: {result.get('state', '')}")
+ lines.append(f"- **Action**: `{result['action']}`")
+ verdict = result.get("verdict")
+ if verdict:
+ lines.append("")
+ lines.append("```json")
+ lines.append(json.dumps(verdict, indent=2))
+ lines.append("```")
+ error = result.get("error")
+ if error:
+ lines.append("")
+ lines.append(f"_LLM error: {error}_")
+ comment = result.get("comment")
+ if comment:
+ lines.append("")
+ lines.append("### Posted comment:")
+ lines.append("")
+ lines.append("> " + comment.replace("\n", "\n> "))
+ return "\n".join(lines)
+
+
+def main() -> int:
+ parser = argparse.ArgumentParser(description=__doc__)
+ parser.add_argument("--repo", required=True, help="Repository (owner/repo).")
+ target = parser.add_mutually_exclusive_group(required=True)
+ target.add_argument("--pr", type=int, help="Pull request number to triage.")
+ target.add_argument("--issue", type=int, help="Issue number to triage.")
+ parser.add_argument(
+ "--close",
+ action="store_true",
+ help="Actually post comment + close on fail (default: dry run).",
+ )
+ parser.add_argument(
+ "--model",
+ # `os.environ.get("TRIAGE_MODEL", DEFAULT_MODEL)` would return "" when
+ # GitHub Actions exposes an unset repo variable as an empty-string env
+ # var, silently bypassing DEFAULT_MODEL and causing every call to fail
+ # as `skip-llm-error`. The `or` guard collapses empty -> default.
+ default=os.environ.get("TRIAGE_MODEL") or DEFAULT_MODEL,
+ help=f"OpenAI-compatible model name (default: {DEFAULT_MODEL}).",
+ )
+ parser.add_argument(
+ "--print-prompt",
+ action="store_true",
+ help="Print the prompt that would be sent to the judge and exit.",
+ )
+ parser.add_argument(
+ "--reconsider",
+ action="store_true",
+ help=(
+ "Re-run triage on a CLOSED PR/issue and reopen it on pass. "
+ "Used by the `@agent-shin reconsider` comment-trigger workflow. "
+ "Only invoke this from a workflow that has already gated on "
+ "AGENT_SHIN_ENABLED=true and verified the commenter is the "
+ "PR/issue author or an internal collaborator."
+ ),
+ )
+ parser.add_argument(
+ "--review-gate",
+ action="store_true",
+ help=(
+ "Reconcile the `ready for review` label for an OPEN PR: tag on "
+ "pass, remove the tag + comment on regression, close after the "
+ "grace window if it never passed. PR-only."
+ ),
+ )
+ parser.add_argument(
+ "--grace-days",
+ type=int,
+ default=DEFAULT_GRACE_DAYS,
+ help=(
+ "Review-gate only: hours/24 a failing, un-tagged PR may stay open "
+ f"before auto-close (default: {DEFAULT_GRACE_DAYS} = 24h)."
+ ),
+ )
+ parser.add_argument(
+ "--min-greptile-score",
+ type=int,
+ default=DEFAULT_MIN_GREPTILE_SCORE,
+ choices=range(1, 6),
+ help=(
+ "Review-gate only: Greptile score below which a PR counts as not "
+ f"passing (default: {DEFAULT_MIN_GREPTILE_SCORE} -> <4/5 regresses)."
+ ),
+ )
+ args = parser.parse_args()
+
+ kind = "pr" if args.pr is not None else "issue"
+ number = args.pr if args.pr is not None else args.issue
+
+ if args.review_gate:
+ if kind != "pr":
+ parser.error("--review-gate applies to pull requests only (use --pr).")
+ result = review_gate(
+ repo=args.repo,
+ number=number,
+ close=args.close,
+ model=args.model,
+ grace_days=args.grace_days,
+ min_greptile_score=args.min_greptile_score,
+ )
+ else:
+ result = triage(
+ repo=args.repo,
+ kind=kind,
+ number=number,
+ close=args.close,
+ model=args.model,
+ print_prompt=args.print_prompt,
+ reconsider=args.reconsider,
+ )
+
+ if result.get("action") == "print-prompt":
+ print(result["prompt"])
+ return 0
+
+ summary = render_summary(result)
+ print(summary)
+ write_step_summary(summary + "\n")
+ return 0
+
+
+if __name__ == "__main__":
+ sys.exit(main())
diff --git a/.github/scripts/uv_sync_with_retries.sh b/.github/scripts/uv_sync_with_retries.sh
new file mode 100755
index 00000000000..85ed75af566
--- /dev/null
+++ b/.github/scripts/uv_sync_with_retries.sh
@@ -0,0 +1,31 @@
+#!/usr/bin/env bash
+set -euo pipefail
+
+max_attempts="${UV_SYNC_MAX_ATTEMPTS:-5}"
+delay_seconds="${UV_SYNC_RETRY_DELAY_SECONDS:-15}"
+
+export CARGO_HTTP_MULTIPLEXING="${CARGO_HTTP_MULTIPLEXING:-false}"
+export CARGO_NET_RETRY="${CARGO_NET_RETRY:-5}"
+
+if [[ "$#" -eq 0 ]]; then
+ echo "usage: $0 " >&2
+ exit 2
+fi
+
+for attempt in $(seq 1 "${max_attempts}"); do
+ echo "uv sync attempt ${attempt}/${max_attempts}"
+ status=0
+ if uv sync "$@"; then
+ exit 0
+ else
+ status=$?
+ fi
+
+ if [[ "${attempt}" -eq "${max_attempts}" ]]; then
+ echo "uv sync failed after ${max_attempts} attempts" >&2
+ exit "${status}"
+ fi
+
+ echo "uv sync failed; retrying in ${delay_seconds}s..."
+ sleep "${delay_seconds}"
+done
diff --git a/.github/workflows/_test-unit-base.yml b/.github/workflows/_test-unit-base.yml
index a42b2f8f9df..25c6d4a7019 100644
--- a/.github/workflows/_test-unit-base.yml
+++ b/.github/workflows/_test-unit-base.yml
@@ -73,7 +73,7 @@ jobs:
- name: Install dependencies
run: |
- uv sync --frozen --group ci --group proxy-dev --extra google --extra proxy --extra semantic-router
+ .github/scripts/uv_sync_with_retries.sh --frozen --group ci --group proxy-dev --extra google --extra proxy --extra semantic-router
- name: Generate Prisma client
env:
diff --git a/.github/workflows/check-ui-api-types.yml b/.github/workflows/check-ui-api-types.yml
index eeb5545b15e..439126aa1ee 100644
--- a/.github/workflows/check-ui-api-types.yml
+++ b/.github/workflows/check-ui-api-types.yml
@@ -46,7 +46,7 @@ jobs:
${{ runner.os }}-uv-
- name: Install backend dependencies
- run: uv sync --frozen --group ci --group proxy-dev --extra google --extra proxy --extra semantic-router
+ run: .github/scripts/uv_sync_with_retries.sh --frozen --group ci --group proxy-dev --extra google --extra proxy --extra semantic-router
- name: Generate Prisma client
env:
@@ -54,7 +54,7 @@ jobs:
run: uv run --no-sync prisma generate --schema litellm/proxy/schema.prisma
- name: Set up Node.js
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0
+ uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
with:
node-version: "20"
cache: "npm"
diff --git a/.github/workflows/close_low_quality_prs.yml b/.github/workflows/close_low_quality_prs.yml
new file mode 100644
index 00000000000..2401be84000
--- /dev/null
+++ b/.github/workflows/close_low_quality_prs.yml
@@ -0,0 +1,92 @@
+name: Close Low-Quality PRs
+
+# Auto-close any open PR (including drafts, regardless of age) authored by an
+# external OSS contributor that Greptile reviewed with a confidence score
+# below 4/5. Closures are explained in a comment that tells the contributor
+# to push fixes and open a fresh PR (since OSS authors cannot reopen a PR
+# closed by a bot/maintainer) or comment `@agent-shin reconsider` to have
+# Agent Shin re-evaluate.
+#
+# Manual one-off run:
+# gh workflow run "Close Low-Quality PRs" -f close=true
+#
+# Dry-run preview (no PRs are touched):
+# gh workflow run "Close Low-Quality PRs" -f close=false
+
+on:
+ schedule:
+ # Daily at 09:00 UTC. Pairs well with the stale-issue workflow at midnight.
+ - cron: "0 9 * * *"
+ workflow_dispatch:
+ inputs:
+ close:
+ description: "Actually close matching PRs (false = dry run)."
+ required: false
+ default: "false"
+ type: choice
+ options:
+ - "true"
+ - "false"
+ min_age_days:
+ description: "Minimum PR age in days (default 0 = no age filter)."
+ required: false
+ default: "0"
+ min_score:
+ description: "Greptile score below which a PR is closed (1-5)."
+ required: false
+ default: "4"
+ limit:
+ description: "Maximum number of PRs to close in a single run."
+ required: false
+ default: "25"
+
+permissions:
+ contents: read
+ pull-requests: write
+ issues: write
+
+jobs:
+ close-low-quality-prs:
+ if: github.repository == 'BerriAI/litellm'
+ runs-on: ubuntu-latest
+ steps:
+ - name: Checkout triage script
+ uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
+ with:
+ sparse-checkout: .github/scripts
+ persist-credentials: false
+
+ - name: Set up Python
+ uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
+ with:
+ python-version: "3.12"
+
+ - name: Run low-quality PR closer
+ env:
+ GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ # Scheduled runs are ALWAYS dry-run, even when AGENT_SHIN_ENABLED is
+ # "true", so the team can QA the closer's verdicts in step summaries
+ # before any contributor sees a PR closed. Real closures only happen
+ # on manual workflow_dispatch with close=true (and the variable set).
+ CLOSE_FLAG: ${{ github.event.inputs.close || 'false' }}
+ AGENT_SHIN_ENABLED: ${{ vars.AGENT_SHIN_ENABLED }}
+ MIN_AGE_DAYS: ${{ github.event.inputs.min_age_days || '0' }}
+ MIN_SCORE: ${{ github.event.inputs.min_score || '4' }}
+ LIMIT: ${{ github.event.inputs.limit || '25' }}
+ run: |
+ set -euo pipefail
+ ARGS=(
+ --repo "${{ github.repository }}"
+ --min-age-days "${MIN_AGE_DAYS}"
+ --min-score "${MIN_SCORE}"
+ --limit "${LIMIT}"
+ )
+ if [ "${AGENT_SHIN_ENABLED:-false}" != "true" ]; then
+ echo "::notice::AGENT_SHIN_ENABLED is not 'true' -> forcing dry-run regardless of close input."
+ elif [ "${GITHUB_EVENT_NAME:-}" = "workflow_dispatch" ] && [ "${CLOSE_FLAG}" = "true" ]; then
+ ARGS+=(--close)
+ echo "::notice::Running in close-on-fail mode."
+ else
+ echo "::notice::AGENT_SHIN_ENABLED is true but this trigger is dry-run (scheduled event or close=false)."
+ fi
+ python3 .github/scripts/close_low_quality_prs.py "${ARGS[@]}"
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index babe3b62933..d3a165a11da 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -43,14 +43,14 @@ jobs:
persist-credentials: false
- name: Initialize CodeQL
- uses: github/codeql-action/init@ebcb5b36ded6beda4ceefea6a8bc4cc885255bb3 # v3
+ uses: github/codeql-action/init@ebcb5b36ded6beda4ceefea6a8bc4cc885255bb3 # v3.34.1
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
config-file: ./.github/codeql/codeql-config.yml
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@ebcb5b36ded6beda4ceefea6a8bc4cc885255bb3 # v3
+ uses: github/codeql-action/analyze@ebcb5b36ded6beda4ceefea6a8bc4cc885255bb3 # v3.34.1
with:
category: "/language:${{ matrix.language }}"
output: sarif-results
@@ -77,7 +77,7 @@ jobs:
output: sarif-results/python.sarif
- name: Upload SARIF
- uses: github/codeql-action/upload-sarif@ebcb5b36ded6beda4ceefea6a8bc4cc885255bb3 # v3
+ uses: github/codeql-action/upload-sarif@ebcb5b36ded6beda4ceefea6a8bc4cc885255bb3 # v3.34.1
with:
sarif_file: sarif-results
category: "/language:${{ matrix.language }}"
diff --git a/.github/workflows/guard-fork-dependencies.yml b/.github/workflows/guard-fork-dependencies.yml
index bf7282688ef..f4cbdd63cdf 100644
--- a/.github/workflows/guard-fork-dependencies.yml
+++ b/.github/workflows/guard-fork-dependencies.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
paths:
- "uv.lock"
diff --git a/.github/workflows/guard-main-branch.yml b/.github/workflows/guard-main-branch.yml
index 1c1ce0de079..21aad18d298 100644
--- a/.github/workflows/guard-main-branch.yml
+++ b/.github/workflows/guard-main-branch.yml
@@ -31,12 +31,12 @@ jobs:
echo "PR head repo: $HEAD_REPO"
echo "PR head branch: $HEAD_REF"
if [ "$HEAD_REPO" != "$BASE_REPO" ]; then
- echo "::error::PRs to main must originate from the canonical repository ($BASE_REPO), not a fork ($HEAD_REPO). External contributors should open PRs against the 'litellm_oss_branch' branch instead."
+ echo "::error::PRs to main must originate from the canonical repository ($BASE_REPO), not a fork ($HEAD_REPO). External contributors should open PRs against the 'litellm_oss_staging' branch instead."
exit 1
fi
if [ "$HEAD_REF" = "litellm_internal_staging" ] || [[ "$HEAD_REF" == litellm_hotfix_?* ]]; then
echo "Allowed source branch."
exit 0
fi
- echo "::error::PRs to main must originate from 'litellm_internal_staging' or a 'litellm_hotfix_*' branch. Got: '$HEAD_REF'. If this is a contribution, retarget the PR against 'litellm_oss_branch' instead."
+ echo "::error::PRs to main must originate from 'litellm_internal_staging' or a 'litellm_hotfix_*' branch. Got: '$HEAD_REF'. If this is a contribution, retarget the PR against 'litellm_oss_staging' instead."
exit 1
diff --git a/.github/workflows/image-scan.yml b/.github/workflows/image-scan.yml
new file mode 100644
index 00000000000..90ede5a653f
--- /dev/null
+++ b/.github/workflows/image-scan.yml
@@ -0,0 +1,65 @@
+name: Image Scan
+
+on:
+ pull_request:
+ branches:
+ - main
+ - litellm_internal_staging
+ - litellm_oss_branch
+ - "litellm_**"
+ paths:
+ - docker/Dockerfile.non_root
+ - uv.lock
+ - ui/litellm-dashboard/package-lock.json
+ - .github/workflows/image-scan.yml
+ schedule:
+ - cron: "41 6 * * *"
+ workflow_dispatch:
+
+permissions: {}
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
+ cancel-in-progress: true
+
+jobs:
+ image-scan:
+ name: image-scan
+ runs-on: ubuntu-latest
+ if: >-
+ github.event_name != 'pull_request' ||
+ github.event.pull_request.head.repo.full_name == github.repository
+ timeout-minutes: 30
+ permissions:
+ contents: read
+ steps:
+ - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
+ with:
+ persist-credentials: false
+
+ - name: Download Grype v0.114.0
+ run: |
+ curl -fsSL --retry 3 -o "$RUNNER_TEMP/grype.tar.gz" \
+ https://github.com/anchore/grype/releases/download/v0.114.0/grype_0.114.0_linux_amd64.tar.gz
+ echo "edda0968d8827daab01d32b3cd7de192ae0915005e7bbfcfef9e68e79bc43343 $RUNNER_TEMP/grype.tar.gz" | sha256sum -c -
+ tar xzf "$RUNNER_TEMP/grype.tar.gz" -C "$RUNNER_TEMP" grype
+ chmod +x "$RUNNER_TEMP/grype"
+
+ # Dockerfile.non_root is the rootless variant we ship. The other
+ # Dockerfiles share the same wolfi base and apk set, so OS-layer coverage
+ # is the same; matrix-scan if those variants ever diverge.
+ - name: Build runtime image
+ run: docker build -f docker/Dockerfile.non_root -t litellm-image-scan:${{ github.sha }} .
+
+ # Scans the whole shipped artifact: OS/apk plus every language package
+ # baked into the image, including ones no lockfile declares (e.g. prisma's
+ # vendored node engine) that osv-scan cannot see. osv-scan stays the fast
+ # source-level gate; this is the customer's-eye-view backstop. Credential-
+ # free OSS, run as a pinned, checksum-verified binary; no GitHub Action
+ # dependency and no vendor SaaS callout.
+ - name: Scan image for fixable HIGH/CRITICAL CVEs
+ run: |
+ "$RUNNER_TEMP/grype" litellm-image-scan:${{ github.sha }} \
+ --only-fixed \
+ --fail-on high \
+ --output table
diff --git a/.github/workflows/mutation-test.yml b/.github/workflows/mutation-test.yml
index 8094ca57467..183f12f969c 100644
--- a/.github/workflows/mutation-test.yml
+++ b/.github/workflows/mutation-test.yml
@@ -55,7 +55,7 @@ jobs:
- name: Install dependencies
run: |
- uv sync --frozen --group ci --group proxy-dev --extra google --extra proxy --extra semantic-router
+ .github/scripts/uv_sync_with_retries.sh --frozen --group ci --group proxy-dev --extra google --extra proxy --extra semantic-router
- name: Generate Prisma client
env:
diff --git a/.github/workflows/osv-scan.yml b/.github/workflows/osv-scan.yml
index 9dd321f88db..31104002dab 100644
--- a/.github/workflows/osv-scan.yml
+++ b/.github/workflows/osv-scan.yml
@@ -5,13 +5,8 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
- paths:
- - uv.lock
- - ui/litellm-dashboard/package-lock.json
- - osv-scanner.toml
- - .github/workflows/osv-scan.yml
schedule:
- cron: "23 6 * * *"
workflow_dispatch:
diff --git a/.github/workflows/test-code-quality.yml b/.github/workflows/test-code-quality.yml
index 4f09857eb1b..872a1799d98 100644
--- a/.github/workflows/test-code-quality.yml
+++ b/.github/workflows/test-code-quality.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
diff --git a/.github/workflows/test-linting.yml b/.github/workflows/test-linting.yml
index 0a80a65cbe6..6deb28c95c7 100644
--- a/.github/workflows/test-linting.yml
+++ b/.github/workflows/test-linting.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
@@ -14,7 +14,7 @@ permissions:
jobs:
lint:
runs-on: ubuntu-latest
- timeout-minutes: 10
+ timeout-minutes: 15
steps:
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
@@ -48,13 +48,27 @@ jobs:
- name: Install dependencies
run: |
- uv sync --frozen
+ uv sync --frozen --group proxy-dev
- - name: Check Black formatting
+ # basedpyright resolves Prisma's generated client (litellm/proxy/schema.prisma)
+ # only after `prisma generate` writes prisma/client.py et al. Without this the
+ # DB wrappers typed against the generated client would degrade to Unknown.
+ - name: Generate Prisma client
+ env:
+ PRISMA_BINARY_CACHE_DIR: ${{ runner.temp }}/prisma-cache
run: |
- cd litellm
- uv run --no-sync black --check --exclude '/enterprise/' .
- cd ..
+ uv run --no-sync prisma generate --schema litellm/proxy/schema.prisma
+
+ - name: Check ruff format
+ env:
+ BASE_SHA: ${{ github.event.pull_request.base.sha }}
+ run: |
+ git diff --name-only "$BASE_SHA"...HEAD -- 'litellm/**/*.py' | grep -v '^litellm/enterprise/' > "$RUNNER_TEMP/ruff_format_files.txt" || true
+ if [ ! -s "$RUNNER_TEMP/ruff_format_files.txt" ]; then
+ echo "No changed litellm Python files to check with ruff format."
+ exit 0
+ fi
+ xargs uv run --no-sync ruff format --check --exclude '/enterprise/' < "$RUNNER_TEMP/ruff_format_files.txt"
- name: Debug - Check file state
run: |
@@ -87,14 +101,11 @@ jobs:
run: |
uv run --no-sync python -c "import openai; print(f'OpenAI version: {openai.__version__}')"
- - name: Run MyPy type checking
+ - name: Check basedpyright budget (delta vs base)
+ env:
+ BASE_SHA: ${{ github.event.pull_request.base.sha }}
run: |
- cd litellm
- (uv run --no-sync mypy . || true) | uv run --no-sync python ../scripts/type_check_gate.py --tool mypy
-
- - name: Run basedpyright type checking
- run: |
- (uv run --no-sync basedpyright --outputjson || true) | uv run --no-sync python scripts/type_check_gate.py --tool basedpyright
+ (uv run --no-sync basedpyright --outputjson || true) | uv run --no-sync python scripts/type_check_gate.py --base "$BASE_SHA"
- name: Check for circular imports
run: |
@@ -133,56 +144,6 @@ jobs:
run: |
python scripts/budget_ratchet_check.py --base "$BASE_SHA"
- any-discipline:
- # Separate job: the first run cold-builds litellm's type cache (~2 min, ~3 GB),
- # so keep it off the main lint job's time budget. Subsequent runs reuse the
- # cached .mypy_cache_any and only re-type-check the changed files.
- runs-on: ubuntu-latest
- timeout-minutes: 10
-
- steps:
- - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
- # Check out the PR head, not the default refs/pull/N/merge: the merge ref
- # folds in newer base commits, which the diff-based gates (ruff delta,
- # Any-discipline) would otherwise blame on this branch.
- with:
- ref: ${{ github.event.pull_request.head.sha }}
- fetch-depth: 0
- clean: true
- persist-credentials: false
-
- - name: Set up Python
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
- with:
- python-version: "3.12"
-
- - name: Set up uv
- uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7
- with:
- version: "0.10.9"
-
- - name: Install dependencies
- run: |
- uv sync --frozen
-
- # Keyed on deps + mypy config (which fix the type cache's validity), not on
- # source content, so changed files always differ from the restored cache.
- # The gate also defensively invalidates each target's cache entry, so
- # correctness never depends on cache freshness -- this is purely for speed.
- - name: Restore Any-gate type cache
- uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
- with:
- path: .mypy_cache_any
- key: any-mypy-cache-${{ runner.os }}-py3.12-${{ hashFiles('uv.lock', 'litellm/mypy.ini') }}
- restore-keys: |
- any-mypy-cache-${{ runner.os }}-py3.12-
-
- - name: Check Any discipline (per-file budget on changed files)
- env:
- BASE_SHA: ${{ github.event.pull_request.base.sha }}
- run: |
- uv run --no-sync python scripts/check_any_discipline.py --changed --base "$BASE_SHA"
-
secret-scan:
runs-on: ubuntu-latest
timeout-minutes: 5
diff --git a/.github/workflows/test-litellm-ui-build.yml b/.github/workflows/test-litellm-ui-build.yml
index 68497b10dbb..ce8d8cb9c95 100644
--- a/.github/workflows/test-litellm-ui-build.yml
+++ b/.github/workflows/test-litellm-ui-build.yml
@@ -7,7 +7,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
jobs:
@@ -25,7 +25,7 @@ jobs:
persist-credentials: false
- name: Setup Node.js
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0
+ uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
with:
node-version: "20"
cache: "npm"
@@ -77,7 +77,7 @@ jobs:
- name: Setup Node.js
if: steps.changed.outputs.has_files == 'true'
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0
+ uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
with:
node-version: "20"
cache: "npm"
@@ -111,4 +111,4 @@ jobs:
if: ${{ !cancelled() && steps.changed.outputs.has_files == 'true' }}
run: |
npx eslint . -f json -o "$RUNNER_TEMP/lint-report.json" || true
- node scripts/check-lint-budgets.mjs "$RUNNER_TEMP/lint-report.json" eslint-budgets.json
+ node scripts/check-lint-budgets.mjs "$RUNNER_TEMP/lint-report.json" eslint-budgets.json --check eslint-metrics.json
diff --git a/.github/workflows/test-mcp.yml b/.github/workflows/test-mcp.yml
index 2ae60951afc..5b5290880c1 100644
--- a/.github/workflows/test-mcp.yml
+++ b/.github/workflows/test-mcp.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
@@ -39,7 +39,7 @@ jobs:
- name: Install dependencies
run: |
uv lock --check
- uv sync --frozen --group proxy-dev --extra proxy --extra semantic-router
+ .github/scripts/uv_sync_with_retries.sh --frozen --group proxy-dev --extra proxy --extra semantic-router
- name: Run MCP tests
run: |
diff --git a/.github/workflows/test-model-map.yaml b/.github/workflows/test-model-map.yaml
index 49821fca3a8..b2170d9f6a4 100644
--- a/.github/workflows/test-model-map.yaml
+++ b/.github/workflows/test-model-map.yaml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
diff --git a/.github/workflows/test-rust.yml b/.github/workflows/test-rust.yml
new file mode 100644
index 00000000000..13e1dc4ad5e
--- /dev/null
+++ b/.github/workflows/test-rust.yml
@@ -0,0 +1,65 @@
+name: LiteLLM Rust
+
+on:
+ push:
+ paths:
+ - "litellm-rust/**"
+ - ".github/workflows/test-rust.yml"
+ pull_request:
+ branches:
+ - main
+ - litellm_internal_staging
+ - litellm_oss_staging
+ - "litellm_**"
+ paths:
+ - "litellm-rust/**"
+ - ".github/workflows/test-rust.yml"
+
+permissions:
+ contents: read
+
+concurrency:
+ group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
+ cancel-in-progress: true
+
+jobs:
+ rust-checks:
+ name: rustfmt, clippy, test
+ runs-on: ubuntu-latest
+ timeout-minutes: 10
+ defaults:
+ run:
+ working-directory: litellm-rust
+ env:
+ CARGO_TERM_COLOR: always
+
+ steps:
+ - name: Checkout repository
+ uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
+ with:
+ persist-credentials: false
+
+ - name: Set up Rust
+ run: |
+ rustup toolchain install stable --profile minimal --component clippy,rustfmt
+ rustup default stable
+
+ - name: Cache Cargo registry and target
+ uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
+ with:
+ path: |
+ ~/.cargo/registry
+ ~/.cargo/git
+ litellm-rust/target
+ key: ${{ runner.os }}-cargo-${{ hashFiles('litellm-rust/Cargo.lock') }}
+ restore-keys: |
+ ${{ runner.os }}-cargo-
+
+ - name: Check Rust formatting
+ run: cargo fmt --check
+
+ - name: Run Clippy
+ run: cargo clippy --workspace --all-targets --locked -- -D warnings
+
+ - name: Run Rust tests
+ run: cargo test --workspace --locked
diff --git a/.github/workflows/test-semgrep.yml b/.github/workflows/test-semgrep.yml
index 2ba23e44da8..f0dcb9887be 100644
--- a/.github/workflows/test-semgrep.yml
+++ b/.github/workflows/test-semgrep.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
diff --git a/.github/workflows/test-unit-core-utils.yml b/.github/workflows/test-unit-core-utils.yml
index da1267756cd..d6d6353238f 100644
--- a/.github/workflows/test-unit-core-utils.yml
+++ b/.github/workflows/test-unit-core-utils.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
diff --git a/.github/workflows/test-unit-documentation.yml b/.github/workflows/test-unit-documentation.yml
index b2a8640223a..4cef791a9b3 100644
--- a/.github/workflows/test-unit-documentation.yml
+++ b/.github/workflows/test-unit-documentation.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
@@ -54,7 +54,7 @@ jobs:
- name: Install dependencies
run: |
- uv sync --frozen --group ci --group proxy-dev --extra google --extra proxy --extra semantic-router
+ .github/scripts/uv_sync_with_retries.sh --frozen --group ci --group proxy-dev --extra google --extra proxy --extra semantic-router
- name: Generate Prisma client
env:
diff --git a/.github/workflows/test-unit-enterprise-routing.yml b/.github/workflows/test-unit-enterprise-routing.yml
index ffc09dd8f94..13136c968d1 100644
--- a/.github/workflows/test-unit-enterprise-routing.yml
+++ b/.github/workflows/test-unit-enterprise-routing.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
diff --git a/.github/workflows/test-unit-integrations.yml b/.github/workflows/test-unit-integrations.yml
index b316ad5dfdf..c95ed4e7c24 100644
--- a/.github/workflows/test-unit-integrations.yml
+++ b/.github/workflows/test-unit-integrations.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
diff --git a/.github/workflows/test-unit-llm-providers.yml b/.github/workflows/test-unit-llm-providers.yml
index 2a1912ce92d..df78564ab0c 100644
--- a/.github/workflows/test-unit-llm-providers.yml
+++ b/.github/workflows/test-unit-llm-providers.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
diff --git a/.github/workflows/test-unit-misc.yml b/.github/workflows/test-unit-misc.yml
index a7363ac3b43..7c3b195f0ad 100644
--- a/.github/workflows/test-unit-misc.yml
+++ b/.github/workflows/test-unit-misc.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
@@ -22,6 +22,7 @@ jobs:
uses: ./.github/workflows/_test-unit-base.yml
with:
test-path: >-
+ tests/test_litellm/batches
tests/test_litellm/secret_managers
tests/test_litellm/a2a_protocol
tests/test_litellm/anthropic_interface
@@ -32,8 +33,11 @@ jobs:
tests/test_litellm/repositories
tests/test_litellm/images
tests/test_litellm/interactions
+ tests/test_litellm/ocr
tests/test_litellm/passthrough
+ tests/test_litellm/sandbox
tests/test_litellm/vector_stores
+ tests/test_litellm/videos
tests/test_litellm/test_*.py
workers: 2
reruns: 2
diff --git a/.github/workflows/test-unit-proxy-auth.yml b/.github/workflows/test-unit-proxy-auth.yml
index 99882066a8e..97dfaed6e81 100644
--- a/.github/workflows/test-unit-proxy-auth.yml
+++ b/.github/workflows/test-unit-proxy-auth.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
diff --git a/.github/workflows/test-unit-proxy-endpoints.yml b/.github/workflows/test-unit-proxy-endpoints.yml
index 0a9513ec024..cbb36eebdb9 100644
--- a/.github/workflows/test-unit-proxy-endpoints.yml
+++ b/.github/workflows/test-unit-proxy-endpoints.yml
@@ -5,14 +5,12 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
workflow_dispatch:
permissions:
contents: read
- id-token: write
- pull-requests: write
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
@@ -20,6 +18,10 @@ concurrency:
jobs:
proxy-endpoints:
+ permissions:
+ contents: read
+ id-token: write
+ pull-requests: write
uses: ./.github/workflows/_test-unit-base.yml
with:
test-path: >-
@@ -29,6 +31,8 @@ jobs:
tests/test_litellm/proxy/anthropic_endpoints
tests/test_litellm/proxy/google_endpoints
tests/test_litellm/proxy/openai_files_endpoint
+ tests/test_litellm/proxy/batches_endpoints
+ tests/test_litellm/proxy/video_endpoints
tests/test_litellm/proxy/response_api_endpoints
tests/test_litellm/proxy/image_endpoints
tests/test_litellm/proxy/vector_store_endpoints
@@ -52,6 +56,10 @@ jobs:
# is independent and its coverage artifact is uploaded separately.
# See: https://www.notion.so/36c43b8acdab81ee845fd5365128a2fc
proxy-server:
+ permissions:
+ contents: read
+ id-token: write
+ pull-requests: write
uses: ./.github/workflows/_test-unit-base.yml
with:
test-path: tests/test_litellm/proxy/proxy_server
diff --git a/.github/workflows/test-unit-proxy-infra.yml b/.github/workflows/test-unit-proxy-infra.yml
index 336e53ee3d7..884d62289b9 100644
--- a/.github/workflows/test-unit-proxy-infra.yml
+++ b/.github/workflows/test-unit-proxy-infra.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
@@ -29,6 +29,7 @@ jobs:
tests/test_litellm/proxy/_experimental
tests/test_litellm/proxy/experimental
tests/test_litellm/proxy/common_utils
+ tests/test_litellm/proxy/logging_endpoints
tests/test_litellm/proxy/test_*.py
workers: 2
reruns: 2
diff --git a/.github/workflows/test-unit-proxy-legacy.yml b/.github/workflows/test-unit-proxy-legacy.yml
index 5768551f9b0..8db218cd1fc 100644
--- a/.github/workflows/test-unit-proxy-legacy.yml
+++ b/.github/workflows/test-unit-proxy-legacy.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
@@ -71,7 +71,7 @@ jobs:
- name: Install dependencies
run: |
- uv sync --frozen --group ci --group proxy-dev --extra google --extra proxy --extra semantic-router
+ .github/scripts/uv_sync_with_retries.sh --frozen --group ci --group proxy-dev --extra google --extra proxy --extra semantic-router
- name: Generate Prisma client
env:
diff --git a/.github/workflows/test-unit-responses-caching-types.yml b/.github/workflows/test-unit-responses-caching-types.yml
index 13069be9e3a..2f177587997 100644
--- a/.github/workflows/test-unit-responses-caching-types.yml
+++ b/.github/workflows/test-unit-responses-caching-types.yml
@@ -5,7 +5,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
permissions:
diff --git a/.github/workflows/test_server_root_path.yml b/.github/workflows/test_server_root_path.yml
index 57ff746c9c8..ac363071d55 100644
--- a/.github/workflows/test_server_root_path.yml
+++ b/.github/workflows/test_server_root_path.yml
@@ -7,7 +7,7 @@ on:
branches:
- main
- litellm_internal_staging
- - litellm_oss_branch
+ - litellm_oss_staging
- "litellm_**"
jobs:
@@ -32,17 +32,16 @@ jobs:
df -h /
- name: Set up Docker Buildx
- uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12
+ uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
- name: Build Docker image
- uses: docker/build-push-action@0adf9959216b96bec444f325f1e493d4aa344497 #v6.14
+ uses: docker/build-push-action@0adf9959216b96bec444f325f1e493d4aa344497 # v6.14.0
with:
context: .
file: ./docker/Dockerfile.non_root
tags: litellm-test:${{ github.sha }}
load: true
- cache-from: type=gha
- cache-to: type=gha,mode=max
+ push: false
- name: Start LiteLLM container with SERVER_ROOT_PATH
run: |
diff --git a/.github/workflows/triage_issue_with_llm.yml b/.github/workflows/triage_issue_with_llm.yml
new file mode 100644
index 00000000000..765453cf2c6
--- /dev/null
+++ b/.github/workflows/triage_issue_with_llm.yml
@@ -0,0 +1,96 @@
+name: Agent Shin — Issue triage
+
+# LLM-as-judge triage for external GitHub issues.
+#
+# DRY-RUN BY DEFAULT. See .github/workflows/triage_pr_with_llm.yml for the
+# enablement procedure — same repo variable (`AGENT_SHIN_ENABLED=true`)
+# unlocks the PR and issue triage flows together.
+
+on:
+ issues:
+ types: [opened, reopened]
+ workflow_dispatch:
+ inputs:
+ issue_number:
+ description: "Issue number to triage manually."
+ required: true
+ close:
+ description: "If true and AGENT_SHIN_ENABLED=true, actually close on fail."
+ required: false
+ default: "false"
+ type: choice
+ options:
+ - "true"
+ - "false"
+
+permissions:
+ contents: read
+ issues: write
+
+jobs:
+ triage:
+ if: github.repository == 'BerriAI/litellm'
+ runs-on: ubuntu-latest
+ steps:
+ - name: Checkout triage script
+ uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
+ with:
+ sparse-checkout: .github/scripts
+ persist-credentials: false
+
+ - name: Set up Python
+ uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
+ with:
+ python-version: "3.12"
+
+ - name: Install LLM client
+ run: pip install --no-cache-dir --require-hashes -r .github/scripts/triage-requirements.txt
+
+ - name: Run Agent Shin
+ env:
+ GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ # Only expose the LLM key when the bot is enabled or a collaborator
+ # triggers it manually, so an external user can't force paid LLM
+ # calls by churning issues while the bot is still in dry-run.
+ # The Python script calls the LLM whenever this var is set
+ # (regardless of `--close`); stripping `--close` doesn't suppress
+ # the API call, only the destructive side effects.
+ OPENAI_API_KEY: ${{ (vars.AGENT_SHIN_ENABLED == 'true' || github.event_name == 'workflow_dispatch') && secrets.OPENAI_API_KEY || '' }}
+ OPENAI_BASE_URL: ${{ vars.OPENAI_BASE_URL }}
+ TRIAGE_MODEL: ${{ vars.TRIAGE_MODEL }}
+ AGENT_SHIN_ENABLED: ${{ vars.AGENT_SHIN_ENABLED }}
+ DISPATCH_CLOSE: ${{ github.event.inputs.close }}
+ ISSUE_NUMBER: ${{ github.event.issue.number || github.event.inputs.issue_number }}
+ run: |
+ set -euo pipefail
+ ARGS=(--repo "${{ github.repository }}" --issue "${ISSUE_NUMBER}")
+ # Fail-safe gating: only the EXACT string "true" enables the
+ # destructive --close path. The workflow_dispatch input is a
+ # `choice` dropdown of "true"/"false" so the UI is constrained,
+ # but the API (`gh workflow run -f close=...`) accepts any
+ # string, and a `!= "false"` check would treat "True", "yes",
+ # "1", "TRUE", typos, and accidental whitespace as enabling
+ # closure. Mirror the Greptile closer's `= "true"` pattern.
+ if [ "${AGENT_SHIN_ENABLED:-false}" = "true" ] && [ "${DISPATCH_CLOSE:-false}" = "true" ]; then
+ ARGS+=(--close)
+ echo "::notice::Agent Shin is ENABLED and running in close-on-fail mode."
+ elif [ "${AGENT_SHIN_ENABLED:-false}" = "true" ]; then
+ echo "::notice::Agent Shin is ENABLED but this trigger is dry-run (workflow_dispatch close != 'true')."
+ else
+ echo "::notice::Agent Shin is in DRY-RUN mode (AGENT_SHIN_ENABLED is not 'true'). No comments will be posted; no issues will be closed."
+ fi
+ # Automatic `issues` events stay dry-run regardless until the team
+ # explicitly invokes workflow_dispatch with close=true.
+ if [ "${GITHUB_EVENT_NAME:-}" = "issues" ]; then
+ # filter out --close rather than substituting to "" (which would
+ # leave an empty positional arg that argparse rejects)
+ FILTERED=()
+ for arg in "${ARGS[@]}"; do
+ if [ "${arg}" != "--close" ]; then
+ FILTERED+=("${arg}")
+ fi
+ done
+ ARGS=("${FILTERED[@]}")
+ echo "::notice::issues trigger -> forcing dry-run."
+ fi
+ python3 .github/scripts/triage_with_llm.py "${ARGS[@]}"
diff --git a/.github/workflows/triage_reconsider.yml b/.github/workflows/triage_reconsider.yml
new file mode 100644
index 00000000000..f35f681d09a
--- /dev/null
+++ b/.github/workflows/triage_reconsider.yml
@@ -0,0 +1,172 @@
+name: Agent Shin — reconsider
+
+# Comment-trigger workflow: when the PR/issue author (or an internal
+# collaborator) comments `@agent-shin reconsider` on a CLOSED PR/issue,
+# Agent Shin re-runs LLM-judge triage on the current title+body and:
+#
+# - on PASS: posts a "re-evaluated and reopened" comment + reopens.
+# - on FAIL: posts a "still missing X" comment and leaves it closed,
+# so the contributor can iterate again.
+#
+# This exists because GitHub does NOT let an external (non-write-access)
+# OSS contributor reopen a PR/issue closed by a bot or maintainer. Without
+# this comment trigger, a contributor whose PR Agent Shin auto-closed
+# would have no path back into the review queue except opening a fresh PR
+# (which loses the original PR's history). The bot, on the other hand,
+# has write access via GH_TOKEN and can reopen on their behalf.
+#
+# DRY-RUN BY DEFAULT — gated on `vars.AGENT_SHIN_ENABLED == 'true'` just
+# like the other Agent Shin workflows. The workflow also gates on the
+# commenter being either the PR/issue author or an internal collaborator
+# (OWNER/MEMBER/COLLABORATOR) so random commenters cannot DOS the LLM
+# judge or force a reopen.
+
+on:
+ issue_comment:
+ types: [created]
+
+permissions:
+ contents: read
+ issues: write
+ pull-requests: write
+
+jobs:
+ reconsider:
+ if: |
+ github.repository == 'BerriAI/litellm'
+ && contains(github.event.comment.body, '@agent-shin reconsider')
+ runs-on: ubuntu-latest
+ steps:
+ - name: Authorize commenter
+ # Only the PR/issue author OR an internal collaborator may trigger
+ # a reconsider. Outside random commenters could otherwise spam the
+ # phrase to burn LLM budget or, if a fail-open bug were ever
+ # introduced, force a reopen on someone else's behalf.
+ #
+ # We expose the authorization decision as a step output and gate
+ # every subsequent (potentially destructive) step on it. A `run:`
+ # step with `exit 0` would NOT stop the job — only `if:` gating
+ # on a known-true output is safe here.
+ id: auth
+ env:
+ COMMENTER: ${{ github.event.comment.user.login }}
+ AUTHOR: ${{ github.event.issue.user.login }}
+ ASSOCIATION: ${{ github.event.comment.author_association }}
+ run: |
+ set -euo pipefail
+ if [ "${COMMENTER}" = "${AUTHOR}" ]; then
+ echo "::notice::Authorized: commenter is the PR/issue author."
+ echo "authorized=true" >> "$GITHUB_OUTPUT"
+ exit 0
+ fi
+ case "${ASSOCIATION}" in
+ OWNER|MEMBER|COLLABORATOR)
+ echo "::notice::Authorized: commenter is an internal collaborator (${ASSOCIATION})."
+ echo "authorized=true" >> "$GITHUB_OUTPUT"
+ ;;
+ *)
+ echo "::notice::Commenter '${COMMENTER}' (${ASSOCIATION}) is not authorized to trigger reconsider; skipping subsequent steps."
+ echo "authorized=false" >> "$GITHUB_OUTPUT"
+ ;;
+ esac
+
+ - name: React 👀 to acknowledge the reconsider
+ # Add an eyes reaction to the triggering comment the moment we accept
+ # it, so the contributor gets instant feedback that the bot saw their
+ # `@agent-shin reconsider` before the slower triage steps run. Gated on
+ # AGENT_SHIN_ENABLED so dry-run leaves no visible trace. Best-effort:
+ # a reactions API hiccup must never fail the actual reconsider.
+ if: steps.auth.outputs.authorized == 'true' && vars.AGENT_SHIN_ENABLED == 'true'
+ env:
+ GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ COMMENT_ID: ${{ github.event.comment.id }}
+ run: |
+ set -euo pipefail
+ gh api --method POST \
+ -H "Accept: application/vnd.github+json" \
+ "repos/${{ github.repository }}/issues/comments/${COMMENT_ID}/reactions" \
+ -f content=eyes \
+ || echo "::warning::failed to add 👀 reaction (non-fatal)"
+
+ - name: Checkout triage script
+ if: steps.auth.outputs.authorized == 'true'
+ uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
+ with:
+ sparse-checkout: .github/scripts
+ persist-credentials: false
+
+ - name: Set up Python
+ if: steps.auth.outputs.authorized == 'true'
+ uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
+ with:
+ python-version: "3.12"
+
+ - name: Install LLM client
+ if: steps.auth.outputs.authorized == 'true'
+ run: pip install --no-cache-dir --require-hashes -r .github/scripts/triage-requirements.txt
+
+ - name: Run Agent Shin reconsider
+ if: steps.auth.outputs.authorized == 'true'
+ env:
+ GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ # Only expose the LLM key when the bot is enabled, so a PR/issue
+ # author can't force paid LLM calls by spamming `@agent-shin
+ # reconsider` while the bot is still in dry-run. The Python script
+ # calls the LLM whenever this var is set (regardless of `--close`);
+ # stripping `--close` doesn't suppress the API call, only the
+ # destructive side effects. Mirror the gating used by every other
+ # Agent Shin workflow (triage_pr_with_llm.yml, review_gate.yml, ...).
+ OPENAI_API_KEY: ${{ vars.AGENT_SHIN_ENABLED == 'true' && secrets.OPENAI_API_KEY || '' }}
+ OPENAI_BASE_URL: ${{ vars.OPENAI_BASE_URL }}
+ TRIAGE_MODEL: ${{ vars.TRIAGE_MODEL }}
+ AGENT_SHIN_ENABLED: ${{ vars.AGENT_SHIN_ENABLED }}
+ # `issue_comment` events fire for both issues and PR comments.
+ # `issue.pull_request` is set iff this is a PR comment, so we use
+ # its presence to decide whether to invoke `--pr N` or `--issue N`.
+ IS_PR: ${{ github.event.issue.pull_request != null }}
+ NUMBER: ${{ github.event.issue.number }}
+ run: |
+ set -euo pipefail
+ if [ "${IS_PR}" = "true" ]; then
+ ARGS=(--repo "${{ github.repository }}" --pr "${NUMBER}" --reconsider)
+ else
+ ARGS=(--repo "${{ github.repository }}" --issue "${NUMBER}" --reconsider)
+ fi
+ # Reconsider's destructive actions (post comment + reopen) are
+ # gated on `--close`, mirroring the regular triage workflows.
+ # When AGENT_SHIN_ENABLED is not the EXACT string "true", we
+ # still run the script so its verdict + would-X action lands in
+ # the step summary for QA — but without `--close`, the script
+ # returns `would-reopen` / `would-reconsider-still-failing`
+ # instead of touching GitHub state.
+ #
+ # Use the positive `= "true"` gate (not `!= "true" -> exit`) so
+ # the workflow guardrails in
+ # tests/test_litellm/test_github_triage_workflows.py see the
+ # canonical fail-safe enable pattern. Unknown values like
+ # "True", "yes", "1", or typos fall through to the dry-run
+ # branch, which is the safe default.
+ if [ "${AGENT_SHIN_ENABLED:-false}" = "true" ]; then
+ ARGS+=(--close)
+ echo "::notice::Agent Shin reconsider ENABLED — running real triage (close=true)."
+ else
+ echo "::notice::AGENT_SHIN_ENABLED is not 'true' -> reconsider stays in dry-run (no comment, no reopen)."
+ fi
+ python3 .github/scripts/triage_with_llm.py "${ARGS[@]}"
+
+ - name: React 👍 when the reconsider finishes
+ # Once the reconsider run has completed successfully, add a thumbs-up so
+ # the contributor sees the bot is done (the 👀 stays, signalling
+ # seen -> handled). `success()` keeps this from firing if the run
+ # errored, and the AGENT_SHIN_ENABLED gate keeps dry-run inert.
+ if: success() && steps.auth.outputs.authorized == 'true' && vars.AGENT_SHIN_ENABLED == 'true'
+ env:
+ GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ COMMENT_ID: ${{ github.event.comment.id }}
+ run: |
+ set -euo pipefail
+ gh api --method POST \
+ -H "Accept: application/vnd.github+json" \
+ "repos/${{ github.repository }}/issues/comments/${COMMENT_ID}/reactions" \
+ -f content=+1 \
+ || echo "::warning::failed to add 👍 reaction (non-fatal)"
diff --git a/.github/workflows/triage_rollout_heads_up.yml b/.github/workflows/triage_rollout_heads_up.yml
new file mode 100644
index 00000000000..903960151e2
--- /dev/null
+++ b/.github/workflows/triage_rollout_heads_up.yml
@@ -0,0 +1,92 @@
+name: Agent Shin — rollout heads-up (one-shot)
+
+# Fires the 7-day heads-up comment on every open external PR/issue that the
+# new triage bot would auto-close. The real sweep is a deliberate one-shot:
+# trigger it at rollout via a manual `workflow_dispatch` with `dry_run=false`.
+# The script is idempotent (skips items that already carry the
+# `` marker), so a re-run is harmless.
+#
+# The automatic push trigger runs DRY-RUN only, so merging the script to
+# `litellm_internal_staging` never posts a comment; it just confirms the
+# workflow is wired up. Posting real comments requires the manual dispatch,
+# which is also the only trigger that exposes `OPENAI_API_KEY`. The heads-up
+# is intentionally NOT gated on `AGENT_SHIN_ENABLED`: it has to warn
+# contributors while that flag is still off, ahead of the flip that turns on
+# auto-closing.
+#
+# The workflow is a thin shell over `.github/scripts/triage_rollout_heads_up.py`.
+# Dry-run vs. real run differ in EXACTLY one CLI flag (`--close`), added only
+# on a manual dispatch with `dry_run=false`.
+
+on:
+ push:
+ branches:
+ - litellm_internal_staging
+ paths:
+ # The presence of this script on staging IS the rollout merge marker.
+ # Editing the file later would re-fire the workflow; that's safe because
+ # the script skips PRs/issues that already have the heads-up marker.
+ - ".github/scripts/triage_rollout_heads_up.py"
+ workflow_dispatch:
+ inputs:
+ dry_run:
+ description: "Dry run (true = preview only, false = actually post comments)."
+ required: false
+ default: "true"
+ type: choice
+ options:
+ - "true"
+ - "false"
+
+permissions:
+ contents: read
+ issues: write
+ pull-requests: write
+
+jobs:
+ heads-up:
+ if: github.repository == 'BerriAI/litellm'
+ runs-on: ubuntu-latest
+ steps:
+ - name: Checkout triage scripts
+ uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
+ with:
+ sparse-checkout: .github/scripts
+ persist-credentials: false
+
+ - name: Set up Python
+ uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
+ with:
+ python-version: "3.12"
+
+ - name: Install LLM client
+ run: pip install --no-cache-dir --require-hashes -r .github/scripts/triage-requirements.txt
+
+ - name: Run heads-up sweep
+ env:
+ GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ # Only the manual dispatch (the real-run trigger) needs the LLM key.
+ # The automatic push trigger runs dry-run and never posts, so it gets
+ # no key. Mirrors the sibling triage workflows, which expose the key
+ # only on an enabled/dispatched run rather than unconditionally.
+ OPENAI_API_KEY: ${{ github.event_name == 'workflow_dispatch' && secrets.OPENAI_API_KEY || '' }}
+ OPENAI_BASE_URL: ${{ vars.OPENAI_BASE_URL }}
+ TRIAGE_MODEL: ${{ vars.TRIAGE_MODEL }}
+ # The real run is a deliberate manual dispatch with dry_run=false.
+ # Use the EXACT "false" comparison so any unexpected input value
+ # fail-closes to dry-run (mirrors the AGENT_SHIN_ENABLED pattern in
+ # the sibling workflows). The automatic push trigger always stays
+ # dry-run, so merging the script never posts.
+ DRY_RUN_INPUT: ${{ github.event.inputs.dry_run }}
+ run: |
+ set -euo pipefail
+ ARGS=(--repo "${{ github.repository }}")
+ if [ "${GITHUB_EVENT_NAME:-}" = "workflow_dispatch" ] && [ "${DRY_RUN_INPUT:-true}" = "false" ]; then
+ ARGS+=(--close)
+ echo "::notice::Manual rollout dispatch with dry_run=false -> heads-up comments WILL be posted."
+ elif [ "${GITHUB_EVENT_NAME:-}" = "workflow_dispatch" ]; then
+ echo "::notice::Manual dispatch in dry-run mode -> previewing only, no comments will be posted."
+ else
+ echo "::notice::Automatic push trigger -> dry-run preview only. Fire the real rollout sweep with a manual workflow_dispatch (dry_run=false)."
+ fi
+ python3 .github/scripts/triage_rollout_heads_up.py "${ARGS[@]}"
diff --git a/.github/workflows/zizmor.yml b/.github/workflows/zizmor.yml
index 9a1e899fed5..db79fe43038 100644
--- a/.github/workflows/zizmor.yml
+++ b/.github/workflows/zizmor.yml
@@ -2,9 +2,9 @@ name: GitHub Actions Security Analysis
on:
push:
- branches: [main]
+ branches: [main, litellm_internal_staging]
pull_request:
- branches: [main]
+ branches: [main, litellm_internal_staging]
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
@@ -18,9 +18,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
- security-events: write
contents: read
- actions: read
steps:
- name: Checkout repository
uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
@@ -28,4 +26,9 @@ jobs:
persist-credentials: false
- name: Run zizmor
- uses: zizmorcore/zizmor-action@71321a20a9ded102f6e9ce5718a2fcec2c4f70d8 # v0.5.2
+ uses: zizmorcore/zizmor-action@5f14fd08f7cf1cb1609c1e344975f152c7ee938d # v0.5.6
+ with:
+ version: "1.24.1"
+ min-severity: medium
+ advanced-security: false
+ annotations: true
diff --git a/.gitignore b/.gitignore
index 54ae53bb2c9..5b7c6e5585b 100644
--- a/.gitignore
+++ b/.gitignore
@@ -9,12 +9,17 @@ litellm/proxy/myenv/*
litellm_uuid.txt
__pycache__/
*.pyc
+
+# Rust bridge build artifacts (compiled, platform-specific; regenerated by maturin/cargo)
+litellm/rust_bridge/_native*.so
+litellm/rust_bridge/_native*.pyd
+litellm-rust/target/
+
bun.lockb
**/.DS_Store
.aider*
litellm_results.jsonl
secrets.toml
-.gitignore
litellm/proxy/litellm_secrets.toml
litellm/proxy/api_log.json
.idea/
@@ -36,7 +41,6 @@ litellm/tests/dynamo*.log
.vscode/settings.json
litellm/proxy/log.txt
proxy_server_config_@.yaml
-.gitignore
proxy_server_config_2.yaml
litellm/proxy/secret_managers/credentials.json
hosted_config.yaml
@@ -46,8 +50,6 @@ litellm/proxy/tests/package-lock.json
ui/litellm-dashboard/.next
ui/litellm-dashboard/node_modules
ui/litellm-dashboard/next-env.d.ts
-ui/litellm-dashboard/package.json
-ui/litellm-dashboard/package-lock.json
deploy/charts/litellm/*.tgz
deploy/charts/litellm/charts/*
deploy/charts/*.tgz
@@ -74,8 +76,6 @@ tests/local_testing/log.txt
.codegpt
litellm/proxy/_new_new_secret_config.yaml
litellm/proxy/custom_guardrail.py
-**/.mypy_cache/
-**/.mypy_cache_any/
litellm/proxy/application.log
tests/llm_translation/vertex_test_account.json
tests/llm_translation/test_vertex_key.json
@@ -85,17 +85,12 @@ litellm/proxy/db/migrations/*
litellm/proxy/migrations/*config.yaml
litellm/proxy/migrations/*
litellm/proxy/to_delete_loadtest_work/*
-config.yaml
tests/litellm/litellm_core_utils/llm_cost_calc/log.txt
tests/test_custom_dir/*
-test.py
-litellm_config.yaml
-!.github/observatory/litellm_config.yaml
.cursor
litellm/proxy/to_delete_loadtest_work/*
update_model_cost_map.py
-tests/test_litellm/proxy/_experimental/mcp_server/test_mcp_server_manager.py
scripts/test_vertex_ai_search.py
LAZY_LOADING_IMPROVEMENTS.md
STABILIZATION_TODO.md
@@ -125,3 +120,10 @@ crash.*.log
# and should be committed.
.vscode
.pin_list.txt
+
+# pytest coverage data
+.coverage
+
+# _experimental/out UI build output
+# (both componentized and non-componentized build the UI on project release)
+litellm/proxy/_experimental/out/
\ No newline at end of file
diff --git a/CLAUDE.md b/CLAUDE.md
index 95904ef8abd..eb32c2cd6da 100644
--- a/CLAUDE.md
+++ b/CLAUDE.md
@@ -29,18 +29,16 @@ If you ever make public-facing PR descriptions, comments, issues, commit message
- don't use "—". Instead, reach for ";", ".", etc.
- don't use the pattern "It's not X, it's Y", "You're not X, you're Y", etc.
- don't use bulleted or numbered lists unless it would be nonsensical not to. Instead, prefer prose
-- don't add a trailing "." at the end of paragraphs (just like this file)
+- don't add a trailing "." at the end of paragraphs (just like this file). That means every paragraph, not just the last one (of the markdown file, PR description, GitHub comment, etc.). Rule of thumb: if you're adding new line(s) before the next sentence, don't add a "."
- don't use →. Instead, prefer not to use arrows, and if need be, use -> instead
Don't hesitate to use values in .env to get needed API keys and other secrets, as long as you never add them to conversation history, commit them, or include them in GitHub issues / PRs
Run tests, format your code, and lint your code before each commit
-When you fix violations gated by `ruff-strict-budget.json`, `mypy-code-budget.json`, `basedpyright-code-budget.json`, or `any-discipline-budget.json`, run `make lint-budget-update` and commit the lowered baselines so the ceilings ratchet down instead of leaving stale headroom
+When you fix violations gated by `ruff-strict-budget.json` or `basedpyright-code-budget.json`, run `make lint-budget-update` and commit the lowered baselines so the ceilings ratchet down instead of leaving stale headroom
-If you're trying to create a new function that relies on untyped stuff, instead of adding more Any's and bringing it closer to the max, just validate it in the caller with Pydantic (a model or `TypeAdapter` that returns the typed thing or raises will do) and then pass the now typed variable in
-
-The Any-discipline gate (`make lint-any`, also a CI job) fails when a changed file under `litellm/` carries more `Any`-typed values than its grandfathered ceiling in `any-discipline-budget.json` (each file's captured count plus 50% headroom). It flags values whose inferred type *contains* `Any`, including the `X | Any` unions mypy/basedpyright accept. Editing a legacy file is fine as long as you don't push its `Any` count past the ceiling; a brand-new file must be `Any`-free. Fix a value by giving it a concrete type (if you're given untyped input, validate with Pydantic). Ideally `# any-ok: ` is never used; treat it as a last resort for a genuine typed/untyped boundary that Pydantic truly can't model
+If you're trying to create a new function that relies on untyped stuff, instead of adding more Any's and pushing `reportAny` / `reportExplicitAny` closer to their basedpyright ceilings, just validate it in the caller with Pydantic (a model or `TypeAdapter` that returns the typed thing or raises will do) and then pass the now typed variable in
If you get an LIT001 or LIT002 fail, refactor the code to follow functional programming best practices rather than introducing mutable data structures. For example, build values in one shot with comprehensions or generators wrapped in `tuple()` / `frozenset()` instead of seeding an empty `list`/`dict`/`set` and mutating it over time. Ideally `# mutable-ok` is never used; reach for it only as a genuine last resort when an immutable rewrite is truly impossible, and always pair it with a real reason
@@ -56,7 +54,7 @@ When working on a PR, keep the PR description in sync with new commits being mad
Monkeypatching attributes of a class to do testing is an anti-pattern. Prefer dependency-injecting things into classes. That way, at unit test time, you can pass a mocked dependency in
-Do not put names of customers or customer company names in code, PRs, and issues. The codebase is public
+Do not put names of customers or customer company names in code, PR descriptions, issue bodies, etc. This means never mention literally any company name. Especially if you're about to say a sentence mentioning that the reason the PR exists was a feature/model/bug fix/etc. requested by a company. That's the indication that you should replace that company name with "the customer". e.g. not "Model request from Acme (Pylon #1234)" but "Model request from a customer (Pylon #1234)". This is because the codebase is public. The only exception is for publicly known providers or vendors such as OpenAI, Anthropic, AWS Bedrock, etc. only IF we're adding support for that provider/vendor in general and NOT if that PR or whatnot was a request by one of them, and they're actually one of our customers.
CI supply-chain safety: Never pipe a remote script into a shell (`curl ... | bash`, `wget ... | sh`); download the artifact to a file, verify its SHA-256 checksum, then install. Pin every external tool to a specific version with a full URL (not `latest` or `stable`). Verify checksums for all downloaded binaries, using the provider's official `.sha256` / `.sha256sum` sidecar when available. These rules apply to every download in CI
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
index 9643a58742c..1080579d0fa 100644
--- a/CONTRIBUTING.md
+++ b/CONTRIBUTING.md
@@ -154,8 +154,7 @@ Individual linting commands:
```bash
make format-check # Check Black formatting
make lint-ruff # Run Ruff linting
-make lint-mypy # Run MyPy type checking
-make lint-any # Gate changed files against their per-file Any budget
+make lint-basedpyright # Run basedpyright type checking
make check-circular-imports # Check for circular imports
make check-import-safety # Check import safety
```
@@ -217,7 +216,7 @@ LiteLLM follows the [Google Python Style Guide](https://google.github.io/stylegu
Our automated quality checks include:
- **Black** for consistent code formatting
- **Ruff** for linting and code quality
-- **MyPy** for static type checking
+- **basedpyright** for static type checking
- **Circular import detection**
- **Import safety validation**
@@ -231,7 +230,7 @@ If `make lint` fails:
1. **Formatting issues**: Run `make format` to auto-fix
2. **Ruff issues**: Check the output and fix manually
-3. **MyPy issues**: Add proper type hints
+3. **basedpyright issues**: Add proper type hints
4. **Circular imports**: Refactor import dependencies
5. **Import safety**: Fix any unprotected imports
@@ -246,7 +245,7 @@ If `make test-unit` fails:
### 3. Common Development Tips
-- **Use type hints**: MyPy requires proper type annotations
+- **Use type hints**: basedpyright requires proper type annotations
- **Write descriptive commit messages**: Help reviewers understand your changes
- **Keep PRs focused**: One feature/fix per PR
- **Test edge cases**: Don't just test the happy path
diff --git a/Dockerfile b/Dockerfile
index 4d55148ff89..b6fef1a21fc 100644
--- a/Dockerfile
+++ b/Dockerfile
@@ -1,12 +1,33 @@
+# syntax=docker/dockerfile:1.7
+
# Base image for building
-ARG LITELLM_BUILD_IMAGE=cgr.dev/chainguard/wolfi-base@sha256:31da6565f35af6401031c1d7aa91dc84ac76c5c48edd17fb90f0ed9e3173c7a9
+ARG LITELLM_BUILD_IMAGE=cgr.dev/chainguard/wolfi-base@sha256:c61ac6919b811ea53c4782d69f1fe05218ba3c25d53f01b6ab7892e621bd4370
# Runtime image
-ARG LITELLM_RUNTIME_IMAGE=cgr.dev/chainguard/wolfi-base@sha256:31da6565f35af6401031c1d7aa91dc84ac76c5c48edd17fb90f0ed9e3173c7a9
+ARG LITELLM_RUNTIME_IMAGE=cgr.dev/chainguard/wolfi-base@sha256:c61ac6919b811ea53c4782d69f1fe05218ba3c25d53f01b6ab7892e621bd4370
ARG UV_IMAGE=ghcr.io/astral-sh/uv:0.11.7@sha256:240fb85ab0f263ef12f492d8476aa3a2e4e1e333f7d67fbdd923d00a506a516a
+# Pinned by digest like the other base images; bump explicitly on Node upgrades.
+ARG UI_BUILD_IMAGE=node:20.18-alpine3.20@sha256:3488b10bf958af7125a176419d2d8a9937d895bf124012aae811651988d2ffe6
FROM $UV_IMAGE AS uvbin
+# Admin UI builder. Pinned to the build platform so the architecture-independent
+# Next.js static export compiles once natively even in a multi-arch build,
+# instead of once per target arch under QEMU.
+FROM --platform=$BUILDPLATFORM $UI_BUILD_IMAGE AS ui-builder
+
+ENV NEXT_TELEMETRY_DISABLED=1 \
+ npm_config_fund=false \
+ npm_config_audit=false
+
+WORKDIR /ui
+
+COPY ui/litellm-dashboard/package.json ui/litellm-dashboard/package-lock.json ./
+RUN --mount=type=cache,target=/root/.npm npm ci --prefer-offline
+
+COPY ui/litellm-dashboard/ ./
+RUN npm run build
+
# Builder stage
FROM $LITELLM_BUILD_IMAGE AS builder
@@ -21,6 +42,7 @@ RUN apk add --no-cache \
gcc \
python3 \
python3-dev \
+ rust \
openssl \
openssl-dev \
nodejs \
@@ -47,7 +69,13 @@ RUN uv sync --frozen --no-install-project --no-install-workspace --no-default-gr
# Copy full source tree
COPY . .
-# Build Admin UI before final sync
+# Replace the committed UI bundle with the one built from this exact source.
+# Clearing first drops the committed bundle's content-hashed chunks that COPY
+# would otherwise leave behind alongside the fresh ones.
+RUN rm -rf litellm/proxy/_experimental/out
+COPY --from=ui-builder /ui/out/. litellm/proxy/_experimental/out/
+
+# Build Admin UI before final sync (applies the enterprise color override when present)
RUN sed -i 's/\r$//' docker/build_admin_ui.sh && chmod +x docker/build_admin_ui.sh && ./docker/build_admin_ui.sh
# Install project and workspace packages (fast - deps already cached)
diff --git a/Makefile b/Makefile
index 0a6d612e8b8..7701f54e15c 100644
--- a/Makefile
+++ b/Makefile
@@ -5,8 +5,8 @@
test-unit-integrations test-unit-core-utils test-unit-other test-unit-root \
test-proxy-unit-a test-proxy-unit-b test-integration test-unit-helm \
info lint lint-dev format \
- lint-mypy lint-mypy-budget-update lint-basedpyright lint-basedpyright-budget-update \
- lint-ruff-budget lint-any lint-ruff-budget-update lint-budget-update lint-any-budget-update \
+ lint-basedpyright lint-basedpyright-budget-update \
+ lint-ruff-budget lint-ruff-budget-update lint-budget-update lint-gate \
install-dev install-proxy-dev install-test-deps install-hooks \
install-helm-unittest check-circular-imports check-import-safety
@@ -20,20 +20,17 @@ help:
@echo " make install-test-deps - Install the full local test environment"
@echo " make install-helm-unittest - Install helm unittest plugin"
@echo " make install-hooks - Install git hooks (Conventional Commits + Branches)"
- @echo " make format - Apply Black code formatting"
- @echo " make format-check - Check Black code formatting (matches CI)"
- @echo " make lint - Run all linting (Ruff, MyPy, Black check, circular imports, import safety)"
+ @echo " make format - Apply ruff format code formatting"
+ @echo " make format-check - Check ruff format code formatting (matches CI)"
+ @echo " make lint - Run all linting (Ruff, basedpyright, format check, circular imports, import safety)"
@echo " make lint-ruff - Run Ruff linting only"
- @echo " make lint-mypy - Run MyPy (disallow_untyped_defs), gated by per-rule error counts"
- @echo " make lint-mypy-budget-update - Re-capture the MyPy per-rule budget (ratchet)"
@echo " make lint-basedpyright - Run basedpyright strict, gated by per-rule error counts"
@echo " make lint-basedpyright-budget-update - Re-capture the basedpyright per-rule budget (ratchet)"
- @echo " make lint-black - Check Black formatting (matches CI)"
+ @echo " make lint-format - Check ruff format formatting (matches CI)"
@echo " make lint-ruff-budget - Gate the codebase total of each strict ruff rule against its ceiling"
- @echo " make lint-any - Gate changed files under litellm/ against their per-file Any budget"
+ @echo " make lint-gate - Strict ruff gate in CI-parity mode (fetches staging, simulates the merge)"
@echo " make lint-ruff-budget-update - Re-capture per-rule baselines in ruff-strict-budget.json (ratchet)"
- @echo " make lint-budget-update - Re-capture all four ratchet budgets (ruff + mypy + basedpyright + any)"
- @echo " make lint-any-budget-update - Re-capture the per-file Any budget across the whole tree (ratchet)"
+ @echo " make lint-budget-update - Re-capture all ratchet budgets (ruff + basedpyright)"
@echo " make check-circular-imports - Check for circular imports"
@echo " make check-import-safety - Check import safety"
@echo " make test - Run all tests"
@@ -85,11 +82,13 @@ install-hooks:
./scripts/install_git_hooks.sh
# Formatting
+# Wrap width is ruff.toml's single source of truth (line-length = 120), shared by the
+# formatter, E501, and the import sorter so there's no 88-vs-120 split to reconcile.
format: install-dev
- cd litellm && $(UV_RUN) black . && cd ..
+ cd litellm && $(UV_RUN) ruff format --exclude '/enterprise/' . && cd ..
format-check: install-dev
- cd litellm && $(UV_RUN) black --check . && cd ..
+ cd litellm && $(UV_RUN) ruff format --check --exclude '/enterprise/' . && cd ..
# Linting targets
lint-ruff: install-dev
@@ -127,34 +126,29 @@ lint-ruff-FULL-dev: install-dev
if [ -n "$$files" ]; then echo "$$files" | xargs $(UV_RUN) ruff check; \
else echo "No changed .py files to check."; fi
-lint-mypy: install-dev
- cd litellm && ($(UV_RUN) mypy . || true) | $(UV_RUN) python ../scripts/type_check_gate.py --tool mypy
-
-lint-mypy-budget-update: install-dev
- cd litellm && ($(UV_RUN) mypy . || true) | $(UV_RUN) python ../scripts/type_check_gate.py --tool mypy --update
-
lint-basedpyright: install-dev
- ($(UV_RUN) basedpyright --outputjson || true) | $(UV_RUN) python scripts/type_check_gate.py --tool basedpyright
+ git fetch origin litellm_internal_staging
+ ($(UV_RUN) basedpyright --outputjson || true) | $(UV_RUN) python scripts/type_check_gate.py --base origin/litellm_internal_staging
lint-basedpyright-budget-update: install-dev
- ($(UV_RUN) basedpyright --outputjson || true) | $(UV_RUN) python scripts/type_check_gate.py --tool basedpyright --update
+ ($(UV_RUN) basedpyright --outputjson || true) | $(UV_RUN) python scripts/type_check_gate.py --update
-lint-black: format-check
+lint-format: format-check
lint-ruff-budget: install-dev
$(UV_RUN) python scripts/ruff_strict_gate.py
+# Strict gate, invoked the same way CI does in test-linting.yml so a local pass
+# means the CI check will pass too.
+lint-gate: install-dev
+ git fetch origin litellm_internal_staging
+ $(UV_RUN) python scripts/ruff_strict_gate.py --base origin/litellm_internal_staging
+
lint-ruff-budget-update: install-dev
$(UV_RUN) python scripts/ruff_strict_gate.py --update
-# Ratchet all four budgets in one shot (ruff strict + mypy + basedpyright + any)
-lint-budget-update: lint-ruff-budget-update lint-mypy-budget-update lint-basedpyright-budget-update lint-any-budget-update
-
-lint-any: install-dev
- $(UV_RUN) python scripts/check_any_discipline.py --changed
-
-lint-any-budget-update: install-dev
- $(UV_RUN) python scripts/check_any_discipline.py --update
+# Ratchet all budgets in one shot (ruff strict + basedpyright)
+lint-budget-update: lint-ruff-budget-update lint-basedpyright-budget-update
check-circular-imports: install-dev
cd litellm && $(UV_RUN) python ../tests/documentation_tests/test_circular_imports.py && cd ..
@@ -163,10 +157,10 @@ check-import-safety: install-dev
@$(UV_RUN) python -c "from litellm import *; print('[from litellm import *] OK! no issues!');" || (echo '🚨 import failed, this means you introduced unprotected imports! 🚨'; exit 1)
# Combined linting (matches test-linting.yml workflow)
-lint: format-check lint-ruff lint-mypy lint-basedpyright check-circular-imports check-import-safety lint-ruff-budget lint-any
+lint: format-check lint-ruff lint-basedpyright check-circular-imports check-import-safety lint-ruff-budget
# Faster linting for local development (only checks changed code)
-lint-dev: lint-format-changed lint-mypy lint-any check-circular-imports check-import-safety
+lint-dev: lint-format-changed check-circular-imports check-import-safety
# Testing targets
test: install-test-deps
diff --git a/README.md b/README.md
index d7dc665dcec..90d3e944fcc 100644
--- a/README.md
+++ b/README.md
@@ -6,10 +6,10 @@
Open Source AI Gateway for 100+ LLMs. Self-hosted. Enterprise-ready. Call any LLM in OpenAI format.