Cross-repo PR compatibility
Last updated
Cross-repo dependencies are a known GitHub gap — there's no native way to say "my frontend PR depends on this backend PR in another repo". Argus reads PR links from your PR description and asks an LLM to look for problems that appear only when the changes are combined.
How to trigger
Paste a GitHub PR URL into your PR body, or use the shorthand owner/repo#N. Anywhere in the description is fine. No manifest, no YAML.
## Context This PR updates our frontend to consume the new API from backend-team/api#142. It also depends on infra-team/config#88 for the new feature flag.
What Argus does
- Finds all GitHub PR URLs and
owner/repo#Nreferences in the PR body (up to 5 by default). - After the primary review completes, runs two async stages in parallel:
- Combination-risk judge — hydrates each linked PR's diff + prior findings from their Argus review (if any), asks the LLM to probe 9 categories: schema/migration race, serialization contract drift, type/interface drift, config contradiction, deployment ordering, security posture, enum exhaustiveness, locale/temporal, and propagated findings.
- Joint issue coverage — when 2+ linked PRs share a referenced issue, judges whether the combined change addresses each acceptance criterion with per-criterion evidence (file:line).
- Edits the sticky review comment in place, adding Cross-Repo PR Coverage and, if applicable, Joint Issue Coverage sections.
- When a linked PR's review completes later, re-runs the cross-PR and joint-coverage checks (not the full review) on already-reviewed PRs that link to it, so their sections pick up the sibling's findings.
Inaccessible repos
Argus reads linked PRs through the primary PR's GitHub App installation. If it can't read one (usually because Argus isn't installed on that repo), the Cross-Repo PR Coverage section lists it as Not checked with the reason, for example "not found (Argus may not be installed on this repo)", and asks you to check it by hand. If no linked PR can be read, no cross-repo section is posted. A readable linked PR that Argus hasn't reviewed is still checked on its diff alone, without prior findings. The primary review completes either way. Add the linked repo to the same installation of your Argus GitHub App (same account or org) so its PRs can be read and their findings passed along.
Concurrent reviews
When linked PRs are reviewed at the same time, each initial cross-PR pass may run with partial data (siblings still reviewing). As each sibling completes, Argus re-runs the cross-PR and joint-coverage checks on already-reviewed PRs that link to it, one hop out (not transitively). The per-review refresh cap below still applies, so in a busy PR family a section can predate the last sibling's review. A new review of the PR, or a PR body edit that changes its linked PRs, runs the check again.
Default on
Cross-repo PR checks are enabled by default for new installations. A combination-risk run makes one LLM call and is skipped when the primary PR head and the linked PRs (diffs and findings) are unchanged since the last run. A joint-coverage run makes one LLM call per shared issue, up to 5. Combination-risk runs have a per-review cap of 2 per 10 minutes, and a run past that cap is dropped. Joint-coverage runs have no per-review cap. Disable in Settings → Org defaults → Verification features; the max-linked-PRs cap (default 5, range 1–20) lives there too. Existing installations keep whatever toggle value was stored before the default flip.
Severity policy
Combination risks and joint-coverage gaps are reported informationally in the sticky comment. They don't bump finding severity, count toward the score or verdict, or block a merge. A person decides what to do with them.