| 1 | name: Codewhale PR Review |
| 2 | |
| 3 | # Account-backed, advisory findings. Failed execution stays visibly failed; |
| 4 | # do not make this optional review job a required merge check. |
| 5 | on: |
| 6 | pull_request: |
| 7 | types: [opened, synchronize, reopened, ready_for_review] |
| 8 | branches: [main, master] |
| 9 | workflow_dispatch: |
| 10 | inputs: |
| 11 | pr-number: |
| 12 | description: Same-repository PR to review at its current revision |
| 13 | required: true |
| 14 | type: string |
| 15 | |
| 16 | concurrency: |
| 17 | group: codewhale-review-${{ github.event.pull_request.number || inputs.pr-number }} |
| 18 | cancel-in-progress: true |
| 19 | |
| 20 | jobs: |
| 21 | codewhale-review: |
| 22 | name: Codewhale review |
| 23 | runs-on: ubuntu-latest |
| 24 | timeout-minutes: 25 |
| 25 | permissions: |
| 26 | contents: read |
| 27 | pull-requests: write |
| 28 | env: |
| 29 | HAS_APP_KEY: ${{ secrets.CODEWHALE_APP_PRIVATE_KEY != '' }} |
| 30 | steps: |
| 31 | # The local action is trusted base/default-branch source. Candidate PR |
| 32 | # source is fetched as Git objects by the action and is never executed. |
| 33 | - uses: actions/checkout@v7 |
| 34 | with: |
| 35 | ref: ${{ github.event.pull_request.base.sha || github.sha }} |
| 36 | persist-credentials: false |
| 37 | - uses: actions/setup-node@v7 |
| 38 | with: |
| 39 | node-version: '22' |
| 40 | - name: Mint Codewhale Agent token |
| 41 | if: env.HAS_APP_KEY == 'true' && vars.CODEWHALE_APP_ID != '' && (github.event_name == 'workflow_dispatch' || (github.event.pull_request.head.repo.full_name == github.repository && !github.event.pull_request.draft)) |
| 42 | id: app-token |
| 43 | uses: actions/create-github-app-token@v3 |
| 44 | with: |
| 45 | app-id: ${{ vars.CODEWHALE_APP_ID }} |
| 46 | private-key: ${{ secrets.CODEWHALE_APP_PRIVATE_KEY }} |
| 47 | permission-contents: read |
| 48 | permission-pull-requests: write |
| 49 | - name: Review with the account model |
| 50 | id: review |
| 51 | uses: ./ |
| 52 | with: |
| 53 | version: ${{ vars.CODEWHALE_REVIEW_VERSION || 'v0.10.0' }} |
| 54 | provider: codewhale |
| 55 | model: ${{ vars.CODEWHALE_REVIEW_MODEL }} |
| 56 | pr-number: ${{ inputs.pr-number }} |
| 57 | github-token: ${{ steps.app-token.outputs.token || github.token }} |
| 58 | max-chars: ${{ vars.CODEWHALE_REVIEW_MAX_CHARS || '200000' }} |
| 59 | max-passes: ${{ vars.CODEWHALE_REVIEW_MAX_PASSES || '1' }} |
| 60 | max-output-tokens: ${{ vars.CODEWHALE_REVIEW_MAX_OUTPUT_TOKENS }} |
| 61 | env: |
| 62 | CODEWHALE_API_KEY: ${{ (github.event_name == 'workflow_dispatch' || github.event.pull_request.head.repo.full_name == github.repository) && secrets.CODEWHALE_API_KEY || '' }} |
| 63 | - name: Save review outcome |
| 64 | if: always() && steps.review.outputs.receipt != '' |
| 65 | uses: actions/upload-artifact@v7 |
| 66 | with: |
| 67 | name: codewhale-review-${{ github.run_id }}-${{ github.run_attempt }} |
| 68 | path: ${{ steps.review.outputs.receipt }} |
| 69 | retention-days: 14 |
| 70 | if-no-files-found: error |
| 71 |