Skip to content

fix(cli): the stored gateway key stops travelling, and --force stops … #154

fix(cli): the stored gateway key stops travelling, and --force stops …

fix(cli): the stored gateway key stops travelling, and --force stops … #154

# OrcaCode Review — https://github.com/Continuum-AI-Corp/orca-code-review

Check failure on line 1 in .github/workflows/orca-code-review.yml

View workflow run for this annotation

GitHub Actions / .github/workflows/orca-code-review.yml

Invalid workflow file

(Line: 40, Col: 9): Unrecognized named-value: 'secrets'. Located at position 1 within expression: secrets.ORCAROUTER_API_KEY != '' && ( github.event_name == 'pull_request_target' || (github.event_name == 'issue_comment' && github.event.issue.pull_request && (startsWith(github.event.comment.body, '/orcacode-review') || startsWith(github.event.comment.body, '/orcacode review') || startsWith(github.event.comment.body, '@orcacode-review') || startsWith(github.event.comment.body, '@or[...]
#
# The review logic lives in the published action, so this file never copies
# scripts or config — bump the version tag to update. Add one repository
# secret, ORCAROUTER_API_KEY, and enable the app at
# OrcaRouter -> Apps -> OrcaCode Review.
name: OrcaCode Review
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.event.issue.number || github.ref }}
cancel-in-progress: true
on:
# `synchronize` re-reviews on every new push. `ready_for_review` makes the
# dashboard's trigger=ready_for_review mode fire when a draft becomes ready.
pull_request_target:
types: [opened, synchronize, ready_for_review]
issue_comment:
types: [created]
permissions:
contents: read
pull-requests: write
issues: write # clean/fallback PR comments
jobs:
review:
runs-on: ubuntu-latest
# Run on PR events, or when a trusted user comments the review command on a
# PR. All four spellings are accepted — either prefix (`/` or `@`) with
# either separator (hyphen or space). The command runs this privileged
# `pull_request_target` workflow with the OrcaRouter secret, so only
# maintainers may trigger it — otherwise any participant could burn paid
# quota and spam reviews without pushing new commits.
# `secrets` is readable in a job-level `if`, and without the key the action can only fail.
# A check that is red on every PR because a repository was never given a credential teaches
# people to ignore red checks, which is the opposite of what a review gate is for. A fork's PR
# gets no secrets either, so this also stops it failing there by design.
if: |
secrets.ORCAROUTER_API_KEY != '' && (
github.event_name == 'pull_request_target' ||
(github.event_name == 'issue_comment' &&
github.event.issue.pull_request &&
(startsWith(github.event.comment.body, '/orcacode-review') ||
startsWith(github.event.comment.body, '/orcacode review') ||
startsWith(github.event.comment.body, '@orcacode-review') ||
startsWith(github.event.comment.body, '@orcacode review')) &&
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.comment.author_association)))
steps:
# Pinned to a commit, not to `@v1`. This job runs on `pull_request_target` with a secret
# in scope, so whoever can move that tag can run code here with it — and `v1` is a floating
# alias its own repo repoints. This is the commit `v1` resolved to when it was pinned; to
# update, resolve the tag again and change the SHA in the same commit as the comment.
- uses: Continuum-AI-Corp/orca-code-review@5ecfbf339ccbe5e6a6107259e0369d424846deb4 # v1
with:
orcarouter-api-key: ${{ secrets.ORCAROUTER_API_KEY }}
# This file is authoritative. The dashboard fetch is skipped entirely,
# so workspace defaults and other repos' settings cannot reach this
# repo — and nothing changed in the console applies here.
settings: 'false'
# Every severity blocks the merge, including advisory P2.
block-on: 'P0,P1,P2'