fix(cli): the stored gateway key stops travelling, and --force stops … #154
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # OrcaCode Review — https://github.com/Continuum-AI-Corp/orca-code-review | ||
|
Check failure on line 1 in .github/workflows/orca-code-review.yml
|
||
| # | ||
| # The review logic lives in the published action, so this file never copies | ||
| # scripts or config — bump the version tag to update. Add one repository | ||
| # secret, ORCAROUTER_API_KEY, and enable the app at | ||
| # OrcaRouter -> Apps -> OrcaCode Review. | ||
| name: OrcaCode Review | ||
| concurrency: | ||
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.event.issue.number || github.ref }} | ||
| cancel-in-progress: true | ||
| on: | ||
| # `synchronize` re-reviews on every new push. `ready_for_review` makes the | ||
| # dashboard's trigger=ready_for_review mode fire when a draft becomes ready. | ||
| pull_request_target: | ||
| types: [opened, synchronize, ready_for_review] | ||
| issue_comment: | ||
| types: [created] | ||
| permissions: | ||
| contents: read | ||
| pull-requests: write | ||
| issues: write # clean/fallback PR comments | ||
| jobs: | ||
| review: | ||
| runs-on: ubuntu-latest | ||
| # Run on PR events, or when a trusted user comments the review command on a | ||
| # PR. All four spellings are accepted — either prefix (`/` or `@`) with | ||
| # either separator (hyphen or space). The command runs this privileged | ||
| # `pull_request_target` workflow with the OrcaRouter secret, so only | ||
| # maintainers may trigger it — otherwise any participant could burn paid | ||
| # quota and spam reviews without pushing new commits. | ||
| # `secrets` is readable in a job-level `if`, and without the key the action can only fail. | ||
| # A check that is red on every PR because a repository was never given a credential teaches | ||
| # people to ignore red checks, which is the opposite of what a review gate is for. A fork's PR | ||
| # gets no secrets either, so this also stops it failing there by design. | ||
| if: | | ||
| secrets.ORCAROUTER_API_KEY != '' && ( | ||
| github.event_name == 'pull_request_target' || | ||
| (github.event_name == 'issue_comment' && | ||
| github.event.issue.pull_request && | ||
| (startsWith(github.event.comment.body, '/orcacode-review') || | ||
| startsWith(github.event.comment.body, '/orcacode review') || | ||
| startsWith(github.event.comment.body, '@orcacode-review') || | ||
| startsWith(github.event.comment.body, '@orcacode review')) && | ||
| contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.comment.author_association))) | ||
| steps: | ||
| # Pinned to a commit, not to `@v1`. This job runs on `pull_request_target` with a secret | ||
| # in scope, so whoever can move that tag can run code here with it — and `v1` is a floating | ||
| # alias its own repo repoints. This is the commit `v1` resolved to when it was pinned; to | ||
| # update, resolve the tag again and change the SHA in the same commit as the comment. | ||
| - uses: Continuum-AI-Corp/orca-code-review@5ecfbf339ccbe5e6a6107259e0369d424846deb4 # v1 | ||
| with: | ||
| orcarouter-api-key: ${{ secrets.ORCAROUTER_API_KEY }} | ||
| # This file is authoritative. The dashboard fetch is skipped entirely, | ||
| # so workspace defaults and other repos' settings cannot reach this | ||
| # repo — and nothing changed in the console applies here. | ||
| settings: 'false' | ||
| # Every severity blocks the merge, including advisory P2. | ||
| block-on: 'P0,P1,P2' | ||