-
Notifications
You must be signed in to change notification settings - Fork 2
Add CodeBoarding architecture analysis #103
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -2,113 +2,42 @@ name: CodeBoarding review | |
|
|
||
| on: | ||
| pull_request: | ||
| # Generate once, when the PR becomes reviewable. Reusing this PR's previous | ||
| # analysis makes per-push runs affordable, so `synchronize` is a reasonable | ||
| # addition now; /codeboarding still refreshes on demand. 'closed' only | ||
| # cancels an in-flight review (see concurrency), it doesn't start one. | ||
| types: [opened, reopened, ready_for_review, closed] | ||
| types: [opened, reopened, ready_for_review, closed, synchronize] | ||
| issue_comment: | ||
| types: [created] | ||
|
|
||
| # No workflow-level permissions: the single job below requests only what it | ||
| # needs (least privilege), so the default token starts with none. | ||
| # No workflow-level permissions: each job requests only what it needs (least | ||
| # privilege), so the default token starts with none. | ||
| permissions: {} | ||
|
|
||
| concurrency: | ||
| group: codeboarding-${{ github.event.pull_request.number || github.event.issue.number }} | ||
| # Cancel only when the PR closes — bot comments (issue_comment) and re-triggers | ||
| # must not cancel a running review; they queue behind it instead. | ||
| cancel-in-progress: ${{ github.event_name == 'pull_request' && github.event.action == 'closed' }} | ||
|
|
||
| jobs: | ||
| review: | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 60 | ||
| permissions: | ||
| # Review mode reads the repo + committed baseline and posts a PR comment; | ||
| # it does NOT commit generated files back to the branch (that is sync mode | ||
| # only — see action.yml `mode` input). So contents stays read-only. | ||
| contents: read | ||
| actions: read # download the analysis an earlier run published | ||
| pull-requests: write # post / update the architecture-diff PR comment | ||
| contents: read # check out the repo + read the committed baseline (no writes in review mode) | ||
| pull-requests: write # post the architecture-diff PR comment | ||
| issues: write # the /codeboarding issue_comment trigger + comment API | ||
| id-token: write # mint per-request OIDC credentials for the relay | ||
| # Never auto-review the fixed machine-owned 'codeboarding/sync' PR: it only | ||
| # changes generated files, so a diff comment would be noise. Scope this to | ||
| # this repository so a fork using the same branch name is still reviewed. | ||
| id-token: write # mint a GitHub OIDC token for the free hosted tier (write is the only level for id-token) | ||
| actions: read # let a repeat review download the analysis an earlier run published, instead of re-deriving the whole PR | ||
| if: > | ||
| (github.event_name == 'pull_request' && github.event.action != 'closed' && github.event.pull_request.draft == false && | ||
| github.event.pull_request.head.repo.full_name == github.repository && | ||
| !(github.head_ref == 'codeboarding/sync' && github.event.pull_request.head.repo.full_name == github.repository)) || | ||
| (github.event_name == 'pull_request' && github.event.action != 'closed' && | ||
| github.event.pull_request.draft == false && | ||
| github.event.pull_request.head.repo.full_name == github.repository) || | ||
| (github.event_name == 'issue_comment' && github.event.issue.pull_request != null && | ||
| startsWith(github.event.comment.body, '/codeboarding') && | ||
| contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association)) | ||
| steps: | ||
| # Automatic same-repo reviews dogfood the PR action. Slash commands use the | ||
| # trusted default-branch action, which can safely analyze a fork's head | ||
| # without executing its action.yml with this job's OIDC permission. | ||
| - uses: actions/checkout@v4 | ||
| - uses: CodeBoarding/CodeBoarding-action@v1 | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
For same-repository pull requests that modify AGENTS.md reference: AGENTS.md:L12-L16 Useful? React with 👍 / 👎. |
||
| with: | ||
| ref: ${{ github.event_name == 'issue_comment' && github.event.repository.default_branch || '' }} | ||
| - name: Detect CodeBoarding GitHub App credentials | ||
| id: codeboarding-app-config | ||
| shell: bash | ||
| env: | ||
| CLIENT_ID: ${{ vars.CODEBOARDING_APP_CLIENT_ID }} | ||
| APP_ID: ${{ vars.CODEBOARDING_APP_ID }} | ||
| PRIVATE_KEY: ${{ secrets.CODEBOARDING_APP_PRIVATE_KEY }} | ||
| run: | | ||
| client_id="${CLIENT_ID:-}" | ||
| app_id="${APP_ID:-}" | ||
|
|
||
| # GitHub App client IDs start with "Iv". If that value was stored in | ||
| # CODEBOARDING_APP_ID, use it as a client ID to avoid the deprecated | ||
| # app-id input path. | ||
| if [ -z "$client_id" ] && [ "${app_id#Iv}" != "$app_id" ]; then | ||
| client_id="$app_id" | ||
| app_id="" | ||
| fi | ||
|
|
||
| has_private_key=false | ||
| private_key_valid=false | ||
| if [ -n "$PRIVATE_KEY" ]; then | ||
| has_private_key=true | ||
| if printf '%s' "$PRIVATE_KEY" | openssl pkey -noout >/dev/null 2>&1; then | ||
| private_key_valid=true | ||
| else | ||
| echo "::warning::CODEBOARDING_APP_PRIVATE_KEY is not a valid PEM private key, so CodeBoarding will fall back to github-actions[bot]." | ||
| if printf '%b' "$PRIVATE_KEY" | openssl pkey -noout >/dev/null 2>&1; then | ||
| printf '%s\n' "::warning::CODEBOARDING_APP_PRIVATE_KEY looks like it contains literal \\n escapes. Store the downloaded PEM as multi-line secret text instead." | ||
| fi | ||
| fi | ||
| fi | ||
|
|
||
| { | ||
| [ -n "$client_id" ] && echo "has_client_id=true" || echo "has_client_id=false" | ||
| [ -n "$app_id" ] && echo "has_app_id=true" || echo "has_app_id=false" | ||
| echo "client_id=$client_id" | ||
| echo "has_private_key=$has_private_key" | ||
| echo "private_key_valid=$private_key_valid" | ||
| } >> "$GITHUB_OUTPUT" | ||
| - uses: actions/create-github-app-token@v3 | ||
| id: codeboarding-app-token-client | ||
| if: steps.codeboarding-app-config.outputs.has_client_id == 'true' && steps.codeboarding-app-config.outputs.private_key_valid == 'true' | ||
| continue-on-error: true | ||
| with: | ||
| client-id: ${{ steps.codeboarding-app-config.outputs.client_id }} | ||
| private-key: ${{ secrets.CODEBOARDING_APP_PRIVATE_KEY }} | ||
| - uses: actions/create-github-app-token@v3 | ||
| id: codeboarding-app-token-app | ||
| if: steps.codeboarding-app-config.outputs.has_client_id != 'true' && steps.codeboarding-app-config.outputs.has_app_id == 'true' && steps.codeboarding-app-config.outputs.private_key_valid == 'true' | ||
| continue-on-error: true | ||
| with: | ||
| app-id: ${{ vars.CODEBOARDING_APP_ID }} | ||
| private-key: ${{ secrets.CODEBOARDING_APP_PRIVATE_KEY }} | ||
| - name: Warn when CodeBoarding App token is unavailable | ||
| if: steps.codeboarding-app-token-client.outputs.token == '' && steps.codeboarding-app-token-app.outputs.token == '' | ||
| shell: bash | ||
| run: | | ||
| echo "::warning::CodeBoarding GitHub App token is unavailable; falling back to github-actions[bot]. Check CODEBOARDING_APP_PRIVATE_KEY formatting if app credentials are configured." | ||
| - uses: ./ | ||
| with: | ||
| github_token: ${{ steps.codeboarding-app-token-client.outputs.token || steps.codeboarding-app-token-app.outputs.token || github.token }} | ||
| # Your own Anthropic key. Add ANTHROPIC_API_KEY under Settings → Secrets and | ||
| # variables → Actions and every run calls Anthropic directly with it. | ||
| # Until that secret exists this is an empty string and the run falls back to | ||
| # CodeBoarding's free hosted tier (what id-token: write above is for). | ||
| llm_provider: anthropic | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
When Useful? React with 👍 / 👎. |
||
| llm_api_key: ${{ secrets.ANTHROPIC_API_KEY }} # your Anthropic key | ||
| license_key: ${{ secrets.CODEBOARDING_LICENSE }} # CodeBoarding paid plan (used only when no key is set) | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
When this commit is merged without being reworded or squash-merged under a compliant PR title, the subject
Add CodeBoarding architecture analysishas no Conventional Commits prefix, so release-please treats it as unparseable and omits it from its automated release bookkeeping. Reword the commit and PR title with the appropriate prefix, such asci: add CodeBoarding architecture workflows.AGENTS.md reference: AGENTS.md:L52-L53
Useful? React with 👍 / 👎.