Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
47 changes: 29 additions & 18 deletions .github/workflows/code-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,26 +13,37 @@ jobs:
runs-on: ubuntu-latest
# Same-repo PRs only: fork PRs don't receive secrets on pull_request.
if: github.event.pull_request.head.repo.full_name == github.repository
# The review settings, the provider credentials and the OpenTelemetry
# configuration all reach the CLI as ambient environment: it reads
# CODE_REVIEW_* directly and de-prefixes CODE_REVIEW_<PROVIDER>_* creds.
# They are declared here, at the job, rather than on the step, because a
# composite action's own steps inherit the job environment.
#
# Each value is named. An earlier version serialised the whole `vars` and
# `secrets` contexts with `toJSON()` and appended the result to
# $GITHUB_ENV, so that a new option could be added at the org level with no
# change here. GitHub's workflow scanning reads "dump every secret into the
# environment" as an exfiltration attempt, flags the file, and holds every
# run as `action_required` until someone with write access approves it by
# hand — which is why no review ran on a pull request after 2026-09-03. The
# cost of naming each value is one line here when the org gains an option.
env:
CODE_REVIEW_DEPTH: ${{ vars.CODE_REVIEW_DEPTH }}
CODE_REVIEW_THINKING_LEVEL: ${{ vars.CODE_REVIEW_THINKING_LEVEL }}
CODE_REVIEW_VERIFY_MODEL: ${{ vars.CODE_REVIEW_VERIFY_MODEL }}
CODE_REVIEW_OTEL: ${{ vars.CODE_REVIEW_OTEL }}
CODE_REVIEW_OTEL_EXPORTER_OTLP_ENDPOINT: ${{ vars.CODE_REVIEW_OTEL_EXPORTER_OTLP_ENDPOINT }}
CODE_REVIEW_OTEL_EXPORTER_OTLP_PROTOCOL: ${{ vars.CODE_REVIEW_OTEL_EXPORTER_OTLP_PROTOCOL }}
CODE_REVIEW_OTEL_SEMCONV_STABILITY_OPT_IN: ${{ vars.CODE_REVIEW_OTEL_SEMCONV_STABILITY_OPT_IN }}
CODE_REVIEW_CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CODE_REVIEW_CLOUDFLARE_ACCOUNT_ID }}
CODE_REVIEW_CLOUDFLARE_API_KEY: ${{ secrets.CODE_REVIEW_CLOUDFLARE_API_KEY }}
CODE_REVIEW_CLOUDFLARE_GATEWAY_ID: ${{ secrets.CODE_REVIEW_CLOUDFLARE_GATEWAY_ID }}
CODE_REVIEW_OPENROUTER_API_KEY: ${{ secrets.CODE_REVIEW_OPENROUTER_API_KEY }}
CODE_REVIEW_OTEL_EXPORTER_OTLP_HEADERS: ${{ secrets.CODE_REVIEW_OTEL_EXPORTER_OTLP_HEADERS }}
steps:
# Forward the whole CODE_REVIEW_* / OTEL_* namespace (review settings,
# provider credentials, OpenTelemetry) from org/repo variables + secrets.
# GitHub doesn't auto-inject org config as env (unlike GitLab CI); the
# composite action inherits whatever lands in $GITHUB_ENV. New options are
# configured purely at the org level with no change here. The CLI reads
# CODE_REVIEW_* directly and de-prefixes CODE_REVIEW_<PROVIDER>_* creds.
- name: Forward CODE_REVIEW_* / OTEL_* config
env:
CR_VARS: ${{ toJSON(vars) }}
CR_SECRETS: ${{ toJSON(secrets) }}
run: |
emit() {
jq -r 'to_entries[]
| select(.key | test("^CODE_REVIEW_"; "i"))
| "\(.key)<<CR_EOF\n\(.value)\nCR_EOF"' <<<"$1" >> "$GITHUB_ENV"
}
emit "$CR_VARS"
emit "$CR_SECRETS"
# The composite action checks out the repo itself (checkout: true default).
# `model` is an input rather than an env entry because the action sets
# CODE_REVIEW_MODEL from it.
- uses: weareikko/code-review@0.8.2
with:
model: ${{ vars.CODE_REVIEW_MODEL }}
Loading