Skip to content

ci: soft-skip self-review on missing key / billing - #4

Merged
aisona-lab merged 2 commits into
mainfrom
ci/self-review-soft-skip-no-key
Sep 29, 2026
Merged

aisona-lab merged 2 commits into
mainfrom
ci/self-review-soft-skip-no-key

Conversation

@aisona-lab

Copy link
Copy Markdown
Owner

Summary

  • .github/workflows/self-review.yml: `if: ${{ secrets.ANTHROPIC_API_KEY != '' }}` so empty/missing secret skips the job (not a red check). Keep `fail-on: never`.
  • `action.yml`: when `fail-on=never`, Anthropic auth/billing/empty-credits soft-skips with a warning instead of failing on operational exit 3 (root cause of prior red self-review runs).
  • README / AGENTS / FEATURE_MAP: one key or no key — gate is auth engine; lazycoder LLM optional; never claim two keys. Document untrusted data + offline prove/replay.

Proof (local, no key)

```bash
env -u ANTHROPIC_API_KEY uv run pytest -q

EXIT 0 — 114 passed, 1 deselected

env -u ANTHROPIC_API_KEY uv run python scripts/corpus_cli.py prove corpus/seed.jsonl

EXIT 0 — OFFLINE_PROVE: PASS

env -u ANTHROPIC_API_KEY uv run pytest -q \
tests/test_cli.py::test_cli_replay_matches_recorded_verdict_without_model \
tests/test_decision_log.py::test_verdict_replays_from_the_record_alone

EXIT 0

uv run ruff check . && uv run black --check . && uv run mypy src

EXIT 0

```

Test plan

  • pytest / prove / replay offline exit 0 without `ANTHROPIC_API_KEY`
  • `test` workflow green
  • `self-review` skips or soft-passes (not hard-red) when secret empty or credits empty

Skip the self-review job when secrets.ANTHROPIC_API_KEY is empty so missing
secret never fails the PR check. Keep fail-on: never. When fail-on=never,
action.yml soft-skips Anthropic auth/billing (empty credits) instead of
hard-failing operational exit 3. Docs: one-key or no-key path; gate is auth
engine; never claim two keys. No real keys in git.
GitHub Actions no longer allows `secrets` in jobs.<id>.if (only
github/needs/vars/inputs), so the preferred one-liner fails the workflow
file. Replace with a key-gate job that outputs has_key; the review job
runs only when the secret is non-empty. Missing secret -> skipped job,
not a red check. Keep fail-on: never; billing soft-skip stays in action.yml.
@github-actions

Copy link
Copy Markdown

lazycoder review — 💥 ERROR

Downloading pydantic-core (2.0MiB)
Downloading anthropic (1.3MiB)
 Downloaded pydantic-core
 Downloaded anthropic
Installed 16 packages in 35ms
error: Error code: 400 - {'type': 'error', 'error': {'type': 'invalid_request_error', 'message': 'Your credit balance is too low to access the Anthropic API. Please go to Plans & Billing to upgrade or purchase credits.'}, 'request_id': 'req_011CfXk8cStqg6xQXwuqDB3B'}

0 finding(s), 0 abstention(s), 0 rule error(s) — R1..R17 rubric via lazycoder

@aisona-lab
aisona-lab merged commit d230fff into main Sep 29, 2026
3 checks passed
@aisona-lab
aisona-lab deleted the ci/self-review-soft-skip-no-key branch September 29, 2026 12:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant