From 8e5b5b5df42a45c5dd791a15d850de50fb729d04 Mon Sep 17 00:00:00 2001 From: loothero Date: Tue, 29 Sep 2026 21:15:37 -0700 Subject: [PATCH] ci: use organization review settings and ARM runners --- .github/workflows/pr-ci.yml | 143 +++++++++++++++++++++++++++++------- 1 file changed, 115 insertions(+), 28 deletions(-) diff --git a/.github/workflows/pr-ci.yml b/.github/workflows/pr-ci.yml index fa707c71..67040acb 100644 --- a/.github/workflows/pr-ci.yml +++ b/.github/workflows/pr-ci.yml @@ -8,6 +8,13 @@ concurrency: group: pr-ci-${{ github.event.pull_request.number }} cancel-in-progress: true +env: + CODEX_REVIEW_MODEL: ${{ vars.CODEX_REVIEW_MODEL }} + CODEX_REVIEW_EFFORT: ${{ vars.CODEX_REVIEW_EFFORT }} + CODEX_CLI_VERSION: ${{ vars.CODEX_CLI_VERSION }} + CLAUDE_REVIEW_MODEL: ${{ vars.CLAUDE_REVIEW_MODEL }} + CLAUDE_REVIEW_EFFORT: ${{ vars.CLAUDE_REVIEW_EFFORT }} + jobs: changes: runs-on: ubuntu-latest @@ -424,7 +431,7 @@ jobs: claude-review-contracts: needs: [changes, contracts-lint] if: needs.changes.outputs.contracts_review == 'true' && needs.changes.outputs.can_run_claude_reviews == 'true' - runs-on: ubuntu-latest + runs-on: ubuntu-24.04-arm timeout-minutes: 20 permissions: contents: read @@ -487,15 +494,25 @@ jobs: cat /tmp/prompt.txt >> "$GITHUB_OUTPUT" echo "${DELIMITER}" >> "$GITHUB_OUTPUT" + - name: Validate organization review settings + run: | + if [[ ! "$CLAUDE_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || + [[ ! "$CLAUDE_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]]; then + echo "::error::Configure CLAUDE review model, effort as Actions variables accessible to this repository." + exit 1 + fi + echo "Review configuration: provider=claude model=$CLAUDE_REVIEW_MODEL effort=$CLAUDE_REVIEW_EFFORT" + - name: Run Claude review id: claude # v1.0.111 — pin by SHA for security (third-party action with write perms + secrets). - uses: anthropics/claude-code-action@fefa07e9c665b7320f08c3b525980457f22f58aa + uses: anthropics/claude-code-action@v1 with: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} prompt: ${{ steps.build-prompt.outputs.prompt }} claude_args: | - --model claude-opus-4-7 + --model ${{ env.CLAUDE_REVIEW_MODEL }} + --effort ${{ env.CLAUDE_REVIEW_EFFORT }} --allowedTools "Bash(git diff *),Bash(git log *),Bash(git show *),Read,Glob,Grep" - name: Extract review output @@ -534,7 +551,7 @@ jobs: codex-review-contracts: needs: [changes, contracts-lint] if: needs.changes.outputs.contracts_review == 'true' && needs.changes.outputs.can_run_ai_reviews == 'true' - runs-on: ubuntu-latest + runs-on: ubuntu-24.04-arm timeout-minutes: 20 permissions: contents: read @@ -595,11 +612,21 @@ jobs: PROMPT_EOF } > /tmp/prompt.txt + - name: Validate organization review settings + run: | + if [[ ! "$CODEX_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || + [[ ! "$CODEX_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]] || + [[ ! "$CODEX_CLI_VERSION" =~ ^(latest|[0-9]+\.[0-9]+\.[0-9]+)$ ]]; then + echo "::error::Configure CODEX review model, effort, and CLI version as Actions variables accessible to this repository." + exit 1 + fi + echo "Review configuration: provider=codex model=$CODEX_REVIEW_MODEL effort=$CODEX_REVIEW_EFFORT" + - name: Run Codex review run: | - npx -y @openai/codex@0.128.0 exec --full-auto \ - -c 'model="gpt-5.5"' \ - -c 'model_reasoning_effort="xhigh"' \ + npx -y "@openai/codex@$CODEX_CLI_VERSION" exec --sandbox read-only \ + -c "model=\"$CODEX_REVIEW_MODEL\"" \ + -c "model_reasoning_effort=\"$CODEX_REVIEW_EFFORT\"" \ -o /tmp/review.txt \ "$(cat /tmp/prompt.txt)" 2>&1 || { echo "Review process failed to complete." > /tmp/review.txt @@ -647,7 +674,7 @@ jobs: claude-review-client: needs: [changes, client-lint] if: needs.changes.outputs.client_review == 'true' && needs.changes.outputs.can_run_claude_reviews == 'true' - runs-on: ubuntu-latest + runs-on: ubuntu-24.04-arm timeout-minutes: 20 permissions: contents: read @@ -710,15 +737,25 @@ jobs: cat /tmp/prompt.txt >> "$GITHUB_OUTPUT" echo "${DELIMITER}" >> "$GITHUB_OUTPUT" + - name: Validate organization review settings + run: | + if [[ ! "$CLAUDE_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || + [[ ! "$CLAUDE_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]]; then + echo "::error::Configure CLAUDE review model, effort as Actions variables accessible to this repository." + exit 1 + fi + echo "Review configuration: provider=claude model=$CLAUDE_REVIEW_MODEL effort=$CLAUDE_REVIEW_EFFORT" + - name: Run Claude review id: claude # v1.0.111 — pin by SHA for security (third-party action with write perms + secrets). - uses: anthropics/claude-code-action@fefa07e9c665b7320f08c3b525980457f22f58aa + uses: anthropics/claude-code-action@v1 with: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} prompt: ${{ steps.build-prompt.outputs.prompt }} claude_args: | - --model claude-opus-4-7 + --model ${{ env.CLAUDE_REVIEW_MODEL }} + --effort ${{ env.CLAUDE_REVIEW_EFFORT }} --allowedTools "Bash(git diff *),Bash(git log *),Bash(git show *),Read,Glob,Grep" - name: Extract review output @@ -757,7 +794,7 @@ jobs: codex-review-client: needs: [changes, client-lint] if: needs.changes.outputs.client_review == 'true' && needs.changes.outputs.can_run_ai_reviews == 'true' - runs-on: ubuntu-latest + runs-on: ubuntu-24.04-arm timeout-minutes: 20 permissions: contents: read @@ -818,11 +855,21 @@ jobs: PROMPT_EOF } > /tmp/prompt.txt + - name: Validate organization review settings + run: | + if [[ ! "$CODEX_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || + [[ ! "$CODEX_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]] || + [[ ! "$CODEX_CLI_VERSION" =~ ^(latest|[0-9]+\.[0-9]+\.[0-9]+)$ ]]; then + echo "::error::Configure CODEX review model, effort, and CLI version as Actions variables accessible to this repository." + exit 1 + fi + echo "Review configuration: provider=codex model=$CODEX_REVIEW_MODEL effort=$CODEX_REVIEW_EFFORT" + - name: Run Codex review run: | - npx -y @openai/codex@0.128.0 exec --full-auto \ - -c 'model="gpt-5.5"' \ - -c 'model_reasoning_effort="xhigh"' \ + npx -y "@openai/codex@$CODEX_CLI_VERSION" exec --sandbox read-only \ + -c "model=\"$CODEX_REVIEW_MODEL\"" \ + -c "model_reasoning_effort=\"$CODEX_REVIEW_EFFORT\"" \ -o /tmp/review.txt \ "$(cat /tmp/prompt.txt)" 2>&1 || { echo "Review process failed to complete." > /tmp/review.txt @@ -870,7 +917,7 @@ jobs: claude-review-indexer-api: needs: [changes, indexer-api-lint] if: needs.changes.outputs.indexer_api_review == 'true' && needs.changes.outputs.can_run_claude_reviews == 'true' - runs-on: ubuntu-latest + runs-on: ubuntu-24.04-arm timeout-minutes: 20 permissions: contents: read @@ -933,15 +980,25 @@ jobs: cat /tmp/prompt.txt >> "$GITHUB_OUTPUT" echo "${DELIMITER}" >> "$GITHUB_OUTPUT" + - name: Validate organization review settings + run: | + if [[ ! "$CLAUDE_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || + [[ ! "$CLAUDE_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]]; then + echo "::error::Configure CLAUDE review model, effort as Actions variables accessible to this repository." + exit 1 + fi + echo "Review configuration: provider=claude model=$CLAUDE_REVIEW_MODEL effort=$CLAUDE_REVIEW_EFFORT" + - name: Run Claude review id: claude # v1.0.111 — pin by SHA for security (third-party action with write perms + secrets). - uses: anthropics/claude-code-action@fefa07e9c665b7320f08c3b525980457f22f58aa + uses: anthropics/claude-code-action@v1 with: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} prompt: ${{ steps.build-prompt.outputs.prompt }} claude_args: | - --model claude-opus-4-7 + --model ${{ env.CLAUDE_REVIEW_MODEL }} + --effort ${{ env.CLAUDE_REVIEW_EFFORT }} --allowedTools "Bash(git diff *),Bash(git log *),Bash(git show *),Read,Glob,Grep" - name: Extract review output @@ -980,7 +1037,7 @@ jobs: codex-review-indexer-api: needs: [changes, indexer-api-lint] if: needs.changes.outputs.indexer_api_review == 'true' && needs.changes.outputs.can_run_ai_reviews == 'true' - runs-on: ubuntu-latest + runs-on: ubuntu-24.04-arm timeout-minutes: 20 permissions: contents: read @@ -1041,11 +1098,21 @@ jobs: PROMPT_EOF } > /tmp/prompt.txt + - name: Validate organization review settings + run: | + if [[ ! "$CODEX_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || + [[ ! "$CODEX_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]] || + [[ ! "$CODEX_CLI_VERSION" =~ ^(latest|[0-9]+\.[0-9]+\.[0-9]+)$ ]]; then + echo "::error::Configure CODEX review model, effort, and CLI version as Actions variables accessible to this repository." + exit 1 + fi + echo "Review configuration: provider=codex model=$CODEX_REVIEW_MODEL effort=$CODEX_REVIEW_EFFORT" + - name: Run Codex review run: | - npx -y @openai/codex@0.128.0 exec --full-auto \ - -c 'model="gpt-5.5"' \ - -c 'model_reasoning_effort="xhigh"' \ + npx -y "@openai/codex@$CODEX_CLI_VERSION" exec --sandbox read-only \ + -c "model=\"$CODEX_REVIEW_MODEL\"" \ + -c "model_reasoning_effort=\"$CODEX_REVIEW_EFFORT\"" \ -o /tmp/review.txt \ "$(cat /tmp/prompt.txt)" 2>&1 || { echo "Review process failed to complete." > /tmp/review.txt @@ -1093,7 +1160,7 @@ jobs: claude-review-general: needs: [changes] if: needs.changes.outputs.general_review == 'true' && needs.changes.outputs.can_run_claude_reviews == 'true' - runs-on: ubuntu-latest + runs-on: ubuntu-24.04-arm timeout-minutes: 20 permissions: contents: read @@ -1157,15 +1224,25 @@ jobs: cat /tmp/prompt.txt >> "$GITHUB_OUTPUT" echo "${DELIMITER}" >> "$GITHUB_OUTPUT" + - name: Validate organization review settings + run: | + if [[ ! "$CLAUDE_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || + [[ ! "$CLAUDE_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]]; then + echo "::error::Configure CLAUDE review model, effort as Actions variables accessible to this repository." + exit 1 + fi + echo "Review configuration: provider=claude model=$CLAUDE_REVIEW_MODEL effort=$CLAUDE_REVIEW_EFFORT" + - name: Run Claude review id: claude # v1.0.111 — pin by SHA for security (third-party action with write perms + secrets). - uses: anthropics/claude-code-action@fefa07e9c665b7320f08c3b525980457f22f58aa + uses: anthropics/claude-code-action@v1 with: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} prompt: ${{ steps.build-prompt.outputs.prompt }} claude_args: | - --model claude-opus-4-7 + --model ${{ env.CLAUDE_REVIEW_MODEL }} + --effort ${{ env.CLAUDE_REVIEW_EFFORT }} --allowedTools "Bash(git diff *),Bash(git log *),Bash(git show *),Read,Glob,Grep" - name: Extract review output @@ -1204,7 +1281,7 @@ jobs: codex-review-general: needs: [changes] if: needs.changes.outputs.general_review == 'true' && needs.changes.outputs.can_run_ai_reviews == 'true' - runs-on: ubuntu-latest + runs-on: ubuntu-24.04-arm timeout-minutes: 20 permissions: contents: read @@ -1266,11 +1343,21 @@ jobs: PROMPT_EOF } > /tmp/prompt.txt + - name: Validate organization review settings + run: | + if [[ ! "$CODEX_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || + [[ ! "$CODEX_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]] || + [[ ! "$CODEX_CLI_VERSION" =~ ^(latest|[0-9]+\.[0-9]+\.[0-9]+)$ ]]; then + echo "::error::Configure CODEX review model, effort, and CLI version as Actions variables accessible to this repository." + exit 1 + fi + echo "Review configuration: provider=codex model=$CODEX_REVIEW_MODEL effort=$CODEX_REVIEW_EFFORT" + - name: Run Codex review run: | - npx -y @openai/codex@0.128.0 exec --full-auto \ - -c 'model="gpt-5.5"' \ - -c 'model_reasoning_effort="xhigh"' \ + npx -y "@openai/codex@$CODEX_CLI_VERSION" exec --sandbox read-only \ + -c "model=\"$CODEX_REVIEW_MODEL\"" \ + -c "model_reasoning_effort=\"$CODEX_REVIEW_EFFORT\"" \ -o /tmp/review.txt \ "$(cat /tmp/prompt.txt)" 2>&1 || { echo "Review process failed to complete." > /tmp/review.txt