From bda9039641f40fff147b6d8ab6e7363f1048f048 Mon Sep 17 00:00:00 2001 From: Titouan Mathis Date: Thu, 17 Sep 2026 11:59:56 +0200 Subject: [PATCH] ci: name the code-review config instead of dumping every secret The workflow serialised the whole `vars` and `secrets` contexts with `toJSON()` and appended the result to $GITHUB_ENV, so that a new review option could be configured at the org level with no change here. GitHub's workflow scanning reads that as an exfiltration attempt. It flags the file and holds every run as `action_required` with no job ever created, until someone with write access approves that run by hand. No review has run on a pull request since 2026-09-03 for that reason, while every other workflow on the same pull requests ran normally. Declare each value instead, at the job rather than the step, because a composite action's own steps inherit the job environment. The CLI still reads CODE_REVIEW_* from ambient environment, so the action needs no change. The cost is one line here when the org gains an option. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01LMSCm41fm3g7chxD728vAu --- .github/workflows/code-review.yml | 47 +++++++++++++++++++------------ 1 file changed, 29 insertions(+), 18 deletions(-) diff --git a/.github/workflows/code-review.yml b/.github/workflows/code-review.yml index 92d1eb67..bd29777e 100644 --- a/.github/workflows/code-review.yml +++ b/.github/workflows/code-review.yml @@ -13,26 +13,37 @@ jobs: runs-on: ubuntu-latest # Same-repo PRs only: fork PRs don't receive secrets on pull_request. if: github.event.pull_request.head.repo.full_name == github.repository + # The review settings, the provider credentials and the OpenTelemetry + # configuration all reach the CLI as ambient environment: it reads + # CODE_REVIEW_* directly and de-prefixes CODE_REVIEW__* creds. + # They are declared here, at the job, rather than on the step, because a + # composite action's own steps inherit the job environment. + # + # Each value is named. An earlier version serialised the whole `vars` and + # `secrets` contexts with `toJSON()` and appended the result to + # $GITHUB_ENV, so that a new option could be added at the org level with no + # change here. GitHub's workflow scanning reads "dump every secret into the + # environment" as an exfiltration attempt, flags the file, and holds every + # run as `action_required` until someone with write access approves it by + # hand — which is why no review ran on a pull request after 2026-09-03. The + # cost of naming each value is one line here when the org gains an option. + env: + CODE_REVIEW_DEPTH: ${{ vars.CODE_REVIEW_DEPTH }} + CODE_REVIEW_THINKING_LEVEL: ${{ vars.CODE_REVIEW_THINKING_LEVEL }} + CODE_REVIEW_VERIFY_MODEL: ${{ vars.CODE_REVIEW_VERIFY_MODEL }} + CODE_REVIEW_OTEL: ${{ vars.CODE_REVIEW_OTEL }} + CODE_REVIEW_OTEL_EXPORTER_OTLP_ENDPOINT: ${{ vars.CODE_REVIEW_OTEL_EXPORTER_OTLP_ENDPOINT }} + CODE_REVIEW_OTEL_EXPORTER_OTLP_PROTOCOL: ${{ vars.CODE_REVIEW_OTEL_EXPORTER_OTLP_PROTOCOL }} + CODE_REVIEW_OTEL_SEMCONV_STABILITY_OPT_IN: ${{ vars.CODE_REVIEW_OTEL_SEMCONV_STABILITY_OPT_IN }} + CODE_REVIEW_CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CODE_REVIEW_CLOUDFLARE_ACCOUNT_ID }} + CODE_REVIEW_CLOUDFLARE_API_KEY: ${{ secrets.CODE_REVIEW_CLOUDFLARE_API_KEY }} + CODE_REVIEW_CLOUDFLARE_GATEWAY_ID: ${{ secrets.CODE_REVIEW_CLOUDFLARE_GATEWAY_ID }} + CODE_REVIEW_OPENROUTER_API_KEY: ${{ secrets.CODE_REVIEW_OPENROUTER_API_KEY }} + CODE_REVIEW_OTEL_EXPORTER_OTLP_HEADERS: ${{ secrets.CODE_REVIEW_OTEL_EXPORTER_OTLP_HEADERS }} steps: - # Forward the whole CODE_REVIEW_* / OTEL_* namespace (review settings, - # provider credentials, OpenTelemetry) from org/repo variables + secrets. - # GitHub doesn't auto-inject org config as env (unlike GitLab CI); the - # composite action inherits whatever lands in $GITHUB_ENV. New options are - # configured purely at the org level with no change here. The CLI reads - # CODE_REVIEW_* directly and de-prefixes CODE_REVIEW__* creds. - - name: Forward CODE_REVIEW_* / OTEL_* config - env: - CR_VARS: ${{ toJSON(vars) }} - CR_SECRETS: ${{ toJSON(secrets) }} - run: | - emit() { - jq -r 'to_entries[] - | select(.key | test("^CODE_REVIEW_"; "i")) - | "\(.key)<> "$GITHUB_ENV" - } - emit "$CR_VARS" - emit "$CR_SECRETS" # The composite action checks out the repo itself (checkout: true default). + # `model` is an input rather than an env entry because the action sets + # CODE_REVIEW_MODEL from it. - uses: weareikko/code-review@0.8.2 with: model: ${{ vars.CODE_REVIEW_MODEL }}