Skip to content

Management SDK review fails to publish no-findings report with unanchored citations #49209

Description

@xirzec

Describe the bug
The management SDK review run completed its analysis of #49163 and submitted a structured review with findings: [] and all seven checks marked completed. The safe_outputs job then failed in Validate and render management SDK review before publishing any comment:

Management SDK review rejected: data.packages[sdk/compute/azure-mgmt-computeworkloadmanager].checks[Preview version].sources[0]: verified lines require an anchor and an empty reason.

The first offending source was an immutable _metadata.json blob URL with line_status: "verified" and an empty reason, but no #L... line anchor. The retained agent output has four more verified citations lacking anchors: pyproject.toml for Stability flags and Client name consistency, and README.md for Client name consistency and README snippets. The absence of findings is valid; the malformed check citations caused the failure. The agent trace reports no substantive SDK issues that were omitted from publication.

To Reproduce
Steps to reproduce the behavior:

  1. Run the management SDK PR review on [AutoPR azure-mgmt-computeworkloadmanager]-generated-from-SDK Generation - Python-6876016 #49163, as in the linked run.
  2. Have the agent submit a reviewed payload with findings: [] and a completed Preview version check whose _metadata.json source is marked verified but has no line anchor.
  3. Observe that the trusted safe_outputs publisher rejects the payload and posts no review.

Expected behavior
The agent should cite exact, verified 1-based #L... anchors from files at the trusted immutable revision. If it cannot verify a line, it should mark the source unavailable, omit the anchor, and supply a concrete reason. A well-formed no-findings review should publish successfully; keep the publisher's fail-closed validation for malformed citations.

Screenshots
N/A; the run log linked above contains the rejection.

Additional context
This is a different failure from the _version.py exclusion addressed by #49208. Improve the workflow's evidence collection/instructions for _metadata.json, pyproject.toml, and README.md so citations satisfy .github/workflows/scripts/mgmt_sdk_review_contract.py's source contract; add a regression case using the retained output shape to ensure valid no-findings reviews publish while unanchored verified sources remain rejected.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions