Repository navigation
ci: use organization review settings and ARM runners #151
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -8,6 +8,13 @@ concurrency: | |
| group: pr-ci-${{ github.event.pull_request.number }} | ||
| cancel-in-progress: true | ||
|
|
||
| env: | ||
| CODEX_REVIEW_MODEL: ${{ vars.CODEX_REVIEW_MODEL }} | ||
| CODEX_REVIEW_EFFORT: ${{ vars.CODEX_REVIEW_EFFORT }} | ||
| CODEX_CLI_VERSION: ${{ vars.CODEX_CLI_VERSION }} | ||
| CLAUDE_REVIEW_MODEL: ${{ vars.CLAUDE_REVIEW_MODEL }} | ||
| CLAUDE_REVIEW_EFFORT: ${{ vars.CLAUDE_REVIEW_EFFORT }} | ||
|
|
||
| jobs: | ||
| changes: | ||
| runs-on: ubuntu-latest | ||
|
|
@@ -424,7 +431,7 @@ jobs: | |
| claude-review-contracts: | ||
| needs: [changes, contracts-lint] | ||
| if: needs.changes.outputs.contracts_review == 'true' && needs.changes.outputs.can_run_claude_reviews == 'true' | ||
| runs-on: ubuntu-latest | ||
| runs-on: ubuntu-24.04-arm | ||
| timeout-minutes: 20 | ||
| permissions: | ||
| contents: read | ||
|
|
@@ -487,15 +494,25 @@ jobs: | |
| cat /tmp/prompt.txt >> "$GITHUB_OUTPUT" | ||
| echo "${DELIMITER}" >> "$GITHUB_OUTPUT" | ||
|
|
||
| - name: Validate organization review settings | ||
| run: | | ||
| if [[ ! "$CLAUDE_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || | ||
| [[ ! "$CLAUDE_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]]; then | ||
| echo "::error::Configure CLAUDE review model, effort as Actions variables accessible to this repository." | ||
| exit 1 | ||
| fi | ||
| echo "Review configuration: provider=claude model=$CLAUDE_REVIEW_MODEL effort=$CLAUDE_REVIEW_EFFORT" | ||
|
|
||
| - name: Run Claude review | ||
| id: claude | ||
| # v1.0.111 — pin by SHA for security (third-party action with write perms + secrets). | ||
| uses: anthropics/claude-code-action@fefa07e9c665b7320f08c3b525980457f22f58aa | ||
| uses: anthropics/claude-code-action@v1 | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟠 Major | ⚡ Quick win Security Misconfiguration Reachability: External Restore immutable pins for all four Claude action references. If an attacker compromises an upstream maintainer account and retargets Pin the reviewed release to its full commit SHA at Lines 509, 752, 995, and 1239. Keep the release version as a trailing comment. Based on learnings, third-party actions must use full immutable commit SHA references. Also applies to: 752-752, 995-995, 1239-1239 🧰 Tools🪛 zizmor (1.30.0)[warning] 1-1504: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) 🤖 Prompt for AI Agents |
||
| with: | ||
| claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} | ||
| prompt: ${{ steps.build-prompt.outputs.prompt }} | ||
| claude_args: | | ||
| --model claude-opus-4-7 | ||
| --model ${{ env.CLAUDE_REVIEW_MODEL }} | ||
| --effort ${{ env.CLAUDE_REVIEW_EFFORT }} | ||
| --allowedTools "Bash(git diff *),Bash(git log *),Bash(git show *),Read,Glob,Grep" | ||
|
|
||
| - name: Extract review output | ||
|
|
@@ -534,7 +551,7 @@ jobs: | |
| codex-review-contracts: | ||
| needs: [changes, contracts-lint] | ||
| if: needs.changes.outputs.contracts_review == 'true' && needs.changes.outputs.can_run_ai_reviews == 'true' | ||
| runs-on: ubuntu-latest | ||
| runs-on: ubuntu-24.04-arm | ||
| timeout-minutes: 20 | ||
| permissions: | ||
| contents: read | ||
|
|
@@ -595,11 +612,21 @@ jobs: | |
| PROMPT_EOF | ||
| } > /tmp/prompt.txt | ||
|
|
||
| - name: Validate organization review settings | ||
| run: | | ||
| if [[ ! "$CODEX_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || | ||
| [[ ! "$CODEX_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]] || | ||
| [[ ! "$CODEX_CLI_VERSION" =~ ^(latest|[0-9]+\.[0-9]+\.[0-9]+)$ ]]; then | ||
| echo "::error::Configure CODEX review model, effort, and CLI version as Actions variables accessible to this repository." | ||
| exit 1 | ||
| fi | ||
| echo "Review configuration: provider=codex model=$CODEX_REVIEW_MODEL effort=$CODEX_REVIEW_EFFORT" | ||
|
|
||
| - name: Run Codex review | ||
| run: | | ||
| npx -y @openai/codex@0.128.0 exec --full-auto \ | ||
| -c 'model="gpt-5.5"' \ | ||
| -c 'model_reasoning_effort="xhigh"' \ | ||
| npx -y "@openai/codex@$CODEX_CLI_VERSION" exec --sandbox read-only \ | ||
| -c "model=\"$CODEX_REVIEW_MODEL\"" \ | ||
| -c "model_reasoning_effort=\"$CODEX_REVIEW_EFFORT\"" \ | ||
| -o /tmp/review.txt \ | ||
| "$(cat /tmp/prompt.txt)" 2>&1 || { | ||
| echo "Review process failed to complete." > /tmp/review.txt | ||
|
|
@@ -647,7 +674,7 @@ jobs: | |
| claude-review-client: | ||
| needs: [changes, client-lint] | ||
| if: needs.changes.outputs.client_review == 'true' && needs.changes.outputs.can_run_claude_reviews == 'true' | ||
| runs-on: ubuntu-latest | ||
| runs-on: ubuntu-24.04-arm | ||
| timeout-minutes: 20 | ||
| permissions: | ||
| contents: read | ||
|
|
@@ -710,15 +737,25 @@ jobs: | |
| cat /tmp/prompt.txt >> "$GITHUB_OUTPUT" | ||
| echo "${DELIMITER}" >> "$GITHUB_OUTPUT" | ||
|
|
||
| - name: Validate organization review settings | ||
| run: | | ||
| if [[ ! "$CLAUDE_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || | ||
| [[ ! "$CLAUDE_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]]; then | ||
| echo "::error::Configure CLAUDE review model, effort as Actions variables accessible to this repository." | ||
| exit 1 | ||
| fi | ||
| echo "Review configuration: provider=claude model=$CLAUDE_REVIEW_MODEL effort=$CLAUDE_REVIEW_EFFORT" | ||
|
|
||
| - name: Run Claude review | ||
| id: claude | ||
| # v1.0.111 — pin by SHA for security (third-party action with write perms + secrets). | ||
| uses: anthropics/claude-code-action@fefa07e9c665b7320f08c3b525980457f22f58aa | ||
| uses: anthropics/claude-code-action@v1 | ||
| with: | ||
| claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} | ||
| prompt: ${{ steps.build-prompt.outputs.prompt }} | ||
| claude_args: | | ||
| --model claude-opus-4-7 | ||
| --model ${{ env.CLAUDE_REVIEW_MODEL }} | ||
| --effort ${{ env.CLAUDE_REVIEW_EFFORT }} | ||
| --allowedTools "Bash(git diff *),Bash(git log *),Bash(git show *),Read,Glob,Grep" | ||
|
|
||
| - name: Extract review output | ||
|
|
@@ -757,7 +794,7 @@ jobs: | |
| codex-review-client: | ||
| needs: [changes, client-lint] | ||
| if: needs.changes.outputs.client_review == 'true' && needs.changes.outputs.can_run_ai_reviews == 'true' | ||
| runs-on: ubuntu-latest | ||
| runs-on: ubuntu-24.04-arm | ||
| timeout-minutes: 20 | ||
| permissions: | ||
| contents: read | ||
|
|
@@ -818,11 +855,21 @@ jobs: | |
| PROMPT_EOF | ||
| } > /tmp/prompt.txt | ||
|
|
||
| - name: Validate organization review settings | ||
| run: | | ||
| if [[ ! "$CODEX_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || | ||
| [[ ! "$CODEX_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]] || | ||
| [[ ! "$CODEX_CLI_VERSION" =~ ^(latest|[0-9]+\.[0-9]+\.[0-9]+)$ ]]; then | ||
| echo "::error::Configure CODEX review model, effort, and CLI version as Actions variables accessible to this repository." | ||
| exit 1 | ||
| fi | ||
| echo "Review configuration: provider=codex model=$CODEX_REVIEW_MODEL effort=$CODEX_REVIEW_EFFORT" | ||
|
|
||
| - name: Run Codex review | ||
| run: | | ||
| npx -y @openai/codex@0.128.0 exec --full-auto \ | ||
| -c 'model="gpt-5.5"' \ | ||
| -c 'model_reasoning_effort="xhigh"' \ | ||
| npx -y "@openai/codex@$CODEX_CLI_VERSION" exec --sandbox read-only \ | ||
| -c "model=\"$CODEX_REVIEW_MODEL\"" \ | ||
| -c "model_reasoning_effort=\"$CODEX_REVIEW_EFFORT\"" \ | ||
| -o /tmp/review.txt \ | ||
| "$(cat /tmp/prompt.txt)" 2>&1 || { | ||
| echo "Review process failed to complete." > /tmp/review.txt | ||
|
|
@@ -870,7 +917,7 @@ jobs: | |
| claude-review-indexer-api: | ||
| needs: [changes, indexer-api-lint] | ||
| if: needs.changes.outputs.indexer_api_review == 'true' && needs.changes.outputs.can_run_claude_reviews == 'true' | ||
| runs-on: ubuntu-latest | ||
| runs-on: ubuntu-24.04-arm | ||
| timeout-minutes: 20 | ||
| permissions: | ||
| contents: read | ||
|
|
@@ -933,15 +980,25 @@ jobs: | |
| cat /tmp/prompt.txt >> "$GITHUB_OUTPUT" | ||
| echo "${DELIMITER}" >> "$GITHUB_OUTPUT" | ||
|
|
||
| - name: Validate organization review settings | ||
| run: | | ||
| if [[ ! "$CLAUDE_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || | ||
| [[ ! "$CLAUDE_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]]; then | ||
| echo "::error::Configure CLAUDE review model, effort as Actions variables accessible to this repository." | ||
| exit 1 | ||
| fi | ||
| echo "Review configuration: provider=claude model=$CLAUDE_REVIEW_MODEL effort=$CLAUDE_REVIEW_EFFORT" | ||
|
|
||
| - name: Run Claude review | ||
| id: claude | ||
| # v1.0.111 — pin by SHA for security (third-party action with write perms + secrets). | ||
| uses: anthropics/claude-code-action@fefa07e9c665b7320f08c3b525980457f22f58aa | ||
| uses: anthropics/claude-code-action@v1 | ||
| with: | ||
| claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} | ||
| prompt: ${{ steps.build-prompt.outputs.prompt }} | ||
| claude_args: | | ||
| --model claude-opus-4-7 | ||
| --model ${{ env.CLAUDE_REVIEW_MODEL }} | ||
| --effort ${{ env.CLAUDE_REVIEW_EFFORT }} | ||
| --allowedTools "Bash(git diff *),Bash(git log *),Bash(git show *),Read,Glob,Grep" | ||
|
|
||
| - name: Extract review output | ||
|
|
@@ -980,7 +1037,7 @@ jobs: | |
| codex-review-indexer-api: | ||
| needs: [changes, indexer-api-lint] | ||
| if: needs.changes.outputs.indexer_api_review == 'true' && needs.changes.outputs.can_run_ai_reviews == 'true' | ||
| runs-on: ubuntu-latest | ||
| runs-on: ubuntu-24.04-arm | ||
| timeout-minutes: 20 | ||
| permissions: | ||
| contents: read | ||
|
|
@@ -1041,11 +1098,21 @@ jobs: | |
| PROMPT_EOF | ||
| } > /tmp/prompt.txt | ||
|
|
||
| - name: Validate organization review settings | ||
| run: | | ||
| if [[ ! "$CODEX_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || | ||
| [[ ! "$CODEX_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]] || | ||
| [[ ! "$CODEX_CLI_VERSION" =~ ^(latest|[0-9]+\.[0-9]+\.[0-9]+)$ ]]; then | ||
| echo "::error::Configure CODEX review model, effort, and CLI version as Actions variables accessible to this repository." | ||
| exit 1 | ||
| fi | ||
| echo "Review configuration: provider=codex model=$CODEX_REVIEW_MODEL effort=$CODEX_REVIEW_EFFORT" | ||
|
|
||
| - name: Run Codex review | ||
| run: | | ||
| npx -y @openai/codex@0.128.0 exec --full-auto \ | ||
| -c 'model="gpt-5.5"' \ | ||
| -c 'model_reasoning_effort="xhigh"' \ | ||
| npx -y "@openai/codex@$CODEX_CLI_VERSION" exec --sandbox read-only \ | ||
| -c "model=\"$CODEX_REVIEW_MODEL\"" \ | ||
| -c "model_reasoning_effort=\"$CODEX_REVIEW_EFFORT\"" \ | ||
| -o /tmp/review.txt \ | ||
| "$(cat /tmp/prompt.txt)" 2>&1 || { | ||
| echo "Review process failed to complete." > /tmp/review.txt | ||
|
|
@@ -1093,7 +1160,7 @@ jobs: | |
| claude-review-general: | ||
| needs: [changes] | ||
| if: needs.changes.outputs.general_review == 'true' && needs.changes.outputs.can_run_claude_reviews == 'true' | ||
| runs-on: ubuntu-latest | ||
| runs-on: ubuntu-24.04-arm | ||
| timeout-minutes: 20 | ||
| permissions: | ||
| contents: read | ||
|
|
@@ -1157,15 +1224,25 @@ jobs: | |
| cat /tmp/prompt.txt >> "$GITHUB_OUTPUT" | ||
| echo "${DELIMITER}" >> "$GITHUB_OUTPUT" | ||
|
|
||
| - name: Validate organization review settings | ||
| run: | | ||
| if [[ ! "$CLAUDE_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || | ||
| [[ ! "$CLAUDE_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]]; then | ||
| echo "::error::Configure CLAUDE review model, effort as Actions variables accessible to this repository." | ||
| exit 1 | ||
| fi | ||
| echo "Review configuration: provider=claude model=$CLAUDE_REVIEW_MODEL effort=$CLAUDE_REVIEW_EFFORT" | ||
|
|
||
| - name: Run Claude review | ||
| id: claude | ||
| # v1.0.111 — pin by SHA for security (third-party action with write perms + secrets). | ||
| uses: anthropics/claude-code-action@fefa07e9c665b7320f08c3b525980457f22f58aa | ||
| uses: anthropics/claude-code-action@v1 | ||
| with: | ||
| claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} | ||
| prompt: ${{ steps.build-prompt.outputs.prompt }} | ||
| claude_args: | | ||
| --model claude-opus-4-7 | ||
| --model ${{ env.CLAUDE_REVIEW_MODEL }} | ||
| --effort ${{ env.CLAUDE_REVIEW_EFFORT }} | ||
| --allowedTools "Bash(git diff *),Bash(git log *),Bash(git show *),Read,Glob,Grep" | ||
|
|
||
| - name: Extract review output | ||
|
|
@@ -1204,7 +1281,7 @@ jobs: | |
| codex-review-general: | ||
| needs: [changes] | ||
| if: needs.changes.outputs.general_review == 'true' && needs.changes.outputs.can_run_ai_reviews == 'true' | ||
| runs-on: ubuntu-latest | ||
| runs-on: ubuntu-24.04-arm | ||
| timeout-minutes: 20 | ||
| permissions: | ||
| contents: read | ||
|
|
@@ -1266,11 +1343,21 @@ jobs: | |
| PROMPT_EOF | ||
| } > /tmp/prompt.txt | ||
|
|
||
| - name: Validate organization review settings | ||
| run: | | ||
| if [[ ! "$CODEX_REVIEW_MODEL" =~ ^[a-zA-Z0-9][a-zA-Z0-9._-]*$ ]] || | ||
| [[ ! "$CODEX_REVIEW_EFFORT" =~ ^[a-zA-Z0-9][a-zA-Z0-9_-]*$ ]] || | ||
| [[ ! "$CODEX_CLI_VERSION" =~ ^(latest|[0-9]+\.[0-9]+\.[0-9]+)$ ]]; then | ||
| echo "::error::Configure CODEX review model, effort, and CLI version as Actions variables accessible to this repository." | ||
| exit 1 | ||
| fi | ||
| echo "Review configuration: provider=codex model=$CODEX_REVIEW_MODEL effort=$CODEX_REVIEW_EFFORT" | ||
|
|
||
| - name: Run Codex review | ||
| run: | | ||
| npx -y @openai/codex@0.128.0 exec --full-auto \ | ||
| -c 'model="gpt-5.5"' \ | ||
| -c 'model_reasoning_effort="xhigh"' \ | ||
| npx -y "@openai/codex@$CODEX_CLI_VERSION" exec --sandbox read-only \ | ||
| -c "model=\"$CODEX_REVIEW_MODEL\"" \ | ||
| -c "model_reasoning_effort=\"$CODEX_REVIEW_EFFORT\"" \ | ||
| -o /tmp/review.txt \ | ||
| "$(cat /tmp/prompt.txt)" 2>&1 || { | ||
| echo "Review process failed to complete." > /tmp/review.txt | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pin each Claude review job to a full commit SHA rather than the mutable
@v1tag. If that tag is moved to an incompatible or compromised release, these jobs will immediately execute unreviewed third-party code withCLAUDE_CODE_OAUTH_TOKEN, pull-request/issue write permissions, and an OIDC token; the adjacent comment and previous value show that the SHA pin specifically protected this boundary. Update to the desired v1 release's immutable SHA instead.Useful? React with 👍 / 👎.