Heal pull requests for sharded runs and GitLab

Every shard of a CI run now publishes its fixes into one heal pull request, GitLab gets merge requests with no token setup, and stale heal pull requests close themselves.

The heal agent now fits the way large suites actually run.

  • Sharded runs: the first shard to finish opens the pull request, and each later shard adds its fix and its verified results as a comment. A run on a newer commit closes the old pull request and opens a fresh one.
  • GitLab: heal merge requests are pushed with the job's own token. Turn on "Allow Git push requests to the repository" for job tokens; no access token or extra tool is needed.
  • Self-closing: when the base branch passes without the fix, for example because someone fixed the test by hand, the heal pull request is closed with a comment and a link to the run.
  • Live app access: the agent can open a headless browser on your app to check the current page instead of guessing from a screenshot.
  • Private artifacts: the agent's session logs are kept in a hidden folder, so default CI artifact uploads leave them out.

Studio's CI export now generates the matching workflow.