Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
✅ All CI checks and tests passed. 🎉 All green!🧪 All tests passed 🎯 Code Coverage (details) 🔗 Commit SHA: 37629d4 | Docs | View more details | Give us feedback! |
BenchmarksBenchmark execution time: 2026-10-01 09:17:47 Comparing candidate commit 37629d4 in PR branch Found 0 performance improvements and 0 performance regressions! Performance is the same for 340 metrics, 1 unstable metrics, 1 flaky benchmarks without significant changes.
|
|
@codex review |
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 10c4f9fa92
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
- Document the errtrack:ignore classification convention in internal/appsec/README.md, per internal/appsec/AGENTS.md. - Correct the AddEvents rate-limit rationale: op.limiter is the global trace rate limit, not a per-request capacity limit. - Remove the exclusion on the SwapRootOperation failure in onRCRulesUpdate: when a poll only contains ignored or ASM_FEATURES products, statuses is empty and the failure is only logged, so it stays actionable in the audit.
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f06b5bd732
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Startup timing is not a reason to leave a site unclassified: reports before telemetry.StartApp capture their stack eagerly and replay once telemetry starts. The risk is ring-buffer eviction, not a bad stack trace. Align the README guidance with internal/README.md.
|
@codex review |
|
Codex Review: Didn't find any major issues. Already looking forward to the next diff. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
Status
Classify 16 of the 19 AppSec audit sites as ineligible for Error Tracking reporting:
DD_APPSEC_TRACE_RATE_LIMIT) and the per-request WAF event capacity limitThree actionable sites remain intentionally unclassified:
SwapRootOperationfailure inonRCRulesUpdate: when a poll contains only ignored orASM_FEATURESproducts,statusesis empty, so the failure is only logged and cannot be reported through an apply statusThese sites stay unclassified on purpose; this PR does not hide them with exclusion directives. Startup timing is not a blocker for adopting them later — reports before
telemetry.StartAppcapture their stack eagerly and replay; the risk is ring-buffer eviction, not a bad stack trace (seeinternal/README.md). The classification convention and eligibility rules are documented ininternal/appsec/README.md.This branch starts from
mainand is not stacked on another migration PR.Validation
go test ./appsec ./internal/appsec/... ./instrumentation/appsec/... -count=1go vet ./appsec ./internal/appsec/... ./instrumentation/appsec/...go run ./internal/telemetry/log/analyzer/cmd ./appsec/... ./internal/appsec/... ./instrumentation/appsec/...(make lint/errlog)git diff --check