+1 to this. Should the prompts, workflows, or harnesses be maintained in the open? It could be useful to have a custom built pi.dev (https://pi.dev/) harness for druid development which can be made available for a more consistent experience.
On Fri, Jul 31, 2026 at 12:01 AM Frank Chen <[email protected]> wrote: > Hi everyone, > > Previously I set up a local pipeline to use my Codex subscription to review > all open PRs on a daily basis. It's really helpful as I see authors of PRs > accept most of the comments raised by AI. > > Now I'm using Codex to address two recurring maintenance challenges in > Apache Druid. > > First, Dependabot raises many dependency-upgrade PRs, most of them related > to security vulnerabilities. Java dependency PRs frequently fail CI because > the upgrade also requires updates to license declarations such as > licenses.yaml. When this happens, the PR waits for human intervention. > > Second, although CodeQL is configured, we rarely have enough time to > investigate and resolve its findings. GitHub currently records > approximately 3,900 security and code-quality findings. Some are false > positives, but many are valid issues, and it is difficult to determine > which findings should be addressed first. > > This is where AI assistance can help. Thanks to the generous and frequent > usage reset from OpenAI recently, I now have enough token budget to help > address these problems. > > Another local Codex-driven pipeline is set up to inspect Dependabot > compatibility, investigate CI failures, propose or implement focused fixes, > and run targeted validation. > > For Dependabot PRs, the operating principles are: > > - Java and web-console dependency updates will generally be *APPROVED* > after CI passes and compatibility checks confirm that the upgrade is > safe. > - Large or breaking upgrades will be *CLOSED* automatically. For > example, #19799 <https://github.com/apache/druid/pull/19799>, the Guice > 6-to-7 upgrade, was closed because it would require a broader Jakarta > migration(even though we can use AI to help the migration but it would > require some extra work) > - Website dependency updates should follow #19788 > <https://github.com/apache/druid/pull/19788>, which changes validation > to npm ci. Therefore, #19814 < > https://github.com/apache/druid/pull/19814> > should be merged only after #19788. > > Recently, I reviewed and merged the following 36 Dependabot PRs. > Merged Java/Maven Dependabot PRs > > - #19794 <https://github.com/apache/druid/pull/19794> — > proto-google-common-protos 2.48.0 → 2.73.0 > - #19795 <https://github.com/apache/druid/pull/19795> — JDBI 2.63.1 → > 2.78 > - #19796 <https://github.com/apache/druid/pull/19796> — AWS SDK 2.40.0 > → > 2.49.6 > - #19797 <https://github.com/apache/druid/pull/19797> — Hamcrest 2.2 → > 3.0 > - #19798 <https://github.com/apache/druid/pull/19798> — Scrooge 19.10.0 > → 21.2.0 > - #19800 <https://github.com/apache/druid/pull/19800> — Rhino Engine > 1.8.1 → 1.9.1 > - #19777 <https://github.com/apache/druid/pull/19777> — Animal Sniffer > Maven Plugin 1.23 → 1.27 > - #19780 <https://github.com/apache/druid/pull/19780> — Curator 5.8.0 → > 5.9.0 > - #19781 <https://github.com/apache/druid/pull/19781> — Quidem 0.11 → > 0.12 > - #19783 <https://github.com/apache/druid/pull/19783> — Avatica 1.27.0 > → > 1.28.0 > - #19784 <https://github.com/apache/druid/pull/19784> — Async HTTP > Client 3.0.10 → 3.0.11 > - #19785 <https://github.com/apache/druid/pull/19785> — Maven Assembly > Plugin 3.1.0 → 3.8.0 > - #19786 <https://github.com/apache/druid/pull/19786> — Protobuf 4.33.0 > → 4.35.1 > - #18588 <https://github.com/apache/druid/pull/18588> — gRPC Netty > Shaded 1.65.1 → 1.75.0 > - #18650 <https://github.com/apache/druid/pull/18650> — Protobuf 3.25.8 > → 4.33.0 > - #18714 <https://github.com/apache/druid/pull/18714> — Protobuf Maven > Plugin 3.7.0 → 3.10.2 > - #18271 <https://github.com/apache/druid/pull/18271> — Maven Artifact > 3.6.0 → 3.9.11 > - #19756 <https://github.com/apache/druid/pull/19756> — LZ4 Java 1.10.2 > → 1.11.1 > - #19757 <https://github.com/apache/druid/pull/19757> — Jetty 12.1.8 → > 12.1.11 > - #19763 <https://github.com/apache/druid/pull/19763> — Thrift 0.13.0 → > 0.23.0 > - #19760 <https://github.com/apache/druid/pull/19760> — PostgreSQL > 42.7.11 → 42.7.12 > - #19764 <https://github.com/apache/druid/pull/19764> — Thrift 0.13.0 → > 0.23.0 > - #19546 <https://github.com/apache/druid/pull/19546> — Vert.x 4.5.24 → > 4.5.27 > - #19490 <https://github.com/apache/druid/pull/19490> — Commons > Configuration 2.10.1 → 2.15.0 > - #19476 <https://github.com/apache/druid/pull/19476> — Async HTTP > Client 3.0.2 → 3.0.10 > - #18956 <https://github.com/apache/druid/pull/18956> — AssertJ Core > 3.24.2 → 3.27.7 > > Merged web-console Dependabot PRs > > - #19506 <https://github.com/apache/druid/pull/19506> — > serialize-javascript and terser-webpack-plugin > - #19708 <https://github.com/apache/druid/pull/19708> — Axios 1.15.2 → > 1.18.0 > - #19610 <https://github.com/apache/druid/pull/19610> — Webpack Dev > Server 5.2.2 → 5.2.6 > - #19256 <https://github.com/apache/druid/pull/19256> — Lodash 4.17.21 > → > 4.18.1 > - #19621 <https://github.com/apache/druid/pull/19621> — Form Data 4.0.5 > → 4.0.6 > - #19694 <https://github.com/apache/druid/pull/19694> — Websocket > Driver > 0.7.4 → 0.7.5 > - #19710 <https://github.com/apache/druid/pull/19710> — Shell Quote > 1.8.1 → 1.10.0 > - #19733 <https://github.com/apache/druid/pull/19733> — Immutable 4.3.0 > → 4.3.9 > - #19761 <https://github.com/apache/druid/pull/19761> — ws > - #19762 <https://github.com/apache/druid/pull/19762> — HTTP Proxy > Middleware 2.0.9 → 2.0.10 > > I also used a one-time pipeline to raise PRs to address CodeQL problems. > Besides addressing existing problems, some static checks rules have also > been updated to prevent some problems in future.These PRs are listed as > follows. If anyone can approve them, I will appreciate it.Security and > dependency vulnerabilities > > - #19806 <https://github.com/apache/druid/pull/19806> — Exclude > vulnerable SnakeYAML from Cassandra storage > - #19807 <https://github.com/apache/druid/pull/19807> — Upgrade Nimbus > JOSE JWT > - #19808 <https://github.com/apache/druid/pull/19808> — Address Jackson > 1 and Netty vulnerabilities > - #19809 <https://github.com/apache/druid/pull/19809> — Remove > vulnerable legacy LZ4 dependency > - #19812 <https://github.com/apache/druid/pull/19812> — Reject newlines > in redirect locations > - #19813 <https://github.com/apache/druid/pull/19813> — Guard segment > info paths against traversal > - #19814 <https://github.com/apache/druid/pull/19814> — Address website > dependency vulnerabilities > - #19815 <https://github.com/apache/druid/pull/19815> — Address > web-console dependency vulnerabilities > - #19822 <https://github.com/apache/druid/pull/19822> — Secure > temporary > files and resource lookups > - #19828 <https://github.com/apache/druid/pull/19828> — Strengthen > cryptographic operations > > CodeQL and code-quality improvements > > - #19816 <https://github.com/apache/druid/pull/19816> — Address > resource-lifetime warnings > - #19818 <https://github.com/apache/druid/pull/19818> — Harden > arithmetic and bounds checks > - #19819 <https://github.com/apache/druid/pull/19819> — Replace > deprecated JUnit assertions > - #19820 <https://github.com/apache/druid/pull/19820> — Address > control-flow and API warnings > - #19821 <https://github.com/apache/druid/pull/19821> — Detect unused > parameters and local variables > - #19823 <https://github.com/apache/druid/pull/19823> — Address > nullness > and type warnings > - #19825 <https://github.com/apache/druid/pull/19825> — Disambiguate > method names and overloads > - #19826 <https://github.com/apache/druid/pull/19826> — Address > formatting warnings > - #19827 <https://github.com/apache/druid/pull/19827> — Address > concurrency warnings > - #19829 <https://github.com/apache/druid/pull/19829> — Remove > redundant > Python assignments > > Reliability and supporting work > > - #19810 <https://github.com/apache/druid/pull/19810> — Avoid sleeping > while holding lifecycle locks > - #19811 <https://github.com/apache/druid/pull/19811> — Release the > record-supplier lock on validation failure > - #19817 <https://github.com/apache/druid/pull/19817> — Wait for Kafka > partitions before publishing > - #19788 <https://github.com/apache/druid/pull/19788> — Use npm ci for > website checks > - #18301 <https://github.com/apache/druid/pull/18301> — Improve offset > auto-reset behavior > > The goal is to make dependency and security maintenance more continuous and > scalable while keeping compatibility assessment, breaking-change decisions, > and final responsibility with human maintainers. > > Best regards, > Frank > -- RAZIN BOUZAR Monitoring Cloud | Salesforce Mobile: 317-502-8995 <https://smart.salesforce.com/sig/rbouzar//us_mb/default/link.html>
