diff --git a/.github/workflows/code-review.yml b/.github/workflows/code-review.yml index 92d1eb67..bd29777e 100644 --- a/.github/workflows/code-review.yml +++ b/.github/workflows/code-review.yml @@ -13,26 +13,37 @@ jobs: runs-on: ubuntu-latest # Same-repo PRs only: fork PRs don't receive secrets on pull_request. if: github.event.pull_request.head.repo.full_name == github.repository + # The review settings, the provider credentials and the OpenTelemetry + # configuration all reach the CLI as ambient environment: it reads + # CODE_REVIEW_* directly and de-prefixes CODE_REVIEW__* creds. + # They are declared here, at the job, rather than on the step, because a + # composite action's own steps inherit the job environment. + # + # Each value is named. An earlier version serialised the whole `vars` and + # `secrets` contexts with `toJSON()` and appended the result to + # $GITHUB_ENV, so that a new option could be added at the org level with no + # change here. GitHub's workflow scanning reads "dump every secret into the + # environment" as an exfiltration attempt, flags the file, and holds every + # run as `action_required` until someone with write access approves it by + # hand — which is why no review ran on a pull request after 2026-09-03. The + # cost of naming each value is one line here when the org gains an option. + env: + CODE_REVIEW_DEPTH: ${{ vars.CODE_REVIEW_DEPTH }} + CODE_REVIEW_THINKING_LEVEL: ${{ vars.CODE_REVIEW_THINKING_LEVEL }} + CODE_REVIEW_VERIFY_MODEL: ${{ vars.CODE_REVIEW_VERIFY_MODEL }} + CODE_REVIEW_OTEL: ${{ vars.CODE_REVIEW_OTEL }} + CODE_REVIEW_OTEL_EXPORTER_OTLP_ENDPOINT: ${{ vars.CODE_REVIEW_OTEL_EXPORTER_OTLP_ENDPOINT }} + CODE_REVIEW_OTEL_EXPORTER_OTLP_PROTOCOL: ${{ vars.CODE_REVIEW_OTEL_EXPORTER_OTLP_PROTOCOL }} + CODE_REVIEW_OTEL_SEMCONV_STABILITY_OPT_IN: ${{ vars.CODE_REVIEW_OTEL_SEMCONV_STABILITY_OPT_IN }} + CODE_REVIEW_CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CODE_REVIEW_CLOUDFLARE_ACCOUNT_ID }} + CODE_REVIEW_CLOUDFLARE_API_KEY: ${{ secrets.CODE_REVIEW_CLOUDFLARE_API_KEY }} + CODE_REVIEW_CLOUDFLARE_GATEWAY_ID: ${{ secrets.CODE_REVIEW_CLOUDFLARE_GATEWAY_ID }} + CODE_REVIEW_OPENROUTER_API_KEY: ${{ secrets.CODE_REVIEW_OPENROUTER_API_KEY }} + CODE_REVIEW_OTEL_EXPORTER_OTLP_HEADERS: ${{ secrets.CODE_REVIEW_OTEL_EXPORTER_OTLP_HEADERS }} steps: - # Forward the whole CODE_REVIEW_* / OTEL_* namespace (review settings, - # provider credentials, OpenTelemetry) from org/repo variables + secrets. - # GitHub doesn't auto-inject org config as env (unlike GitLab CI); the - # composite action inherits whatever lands in $GITHUB_ENV. New options are - # configured purely at the org level with no change here. The CLI reads - # CODE_REVIEW_* directly and de-prefixes CODE_REVIEW__* creds. - - name: Forward CODE_REVIEW_* / OTEL_* config - env: - CR_VARS: ${{ toJSON(vars) }} - CR_SECRETS: ${{ toJSON(secrets) }} - run: | - emit() { - jq -r 'to_entries[] - | select(.key | test("^CODE_REVIEW_"; "i")) - | "\(.key)<> "$GITHUB_ENV" - } - emit "$CR_VARS" - emit "$CR_SECRETS" # The composite action checks out the repo itself (checkout: true default). + # `model` is an input rather than an env entry because the action sets + # CODE_REVIEW_MODEL from it. - uses: weareikko/code-review@0.8.2 with: model: ${{ vars.CODE_REVIEW_MODEL }}