feat: ACNA-4515 add pr-reviewer workflow - #96
Conversation
There was a problem hiding this comment.
🤖 PR Reviewer
The workflow is well-structured with clear security gating and good use of environment variables to avoid injection. Two moderate issues exist: the reusable workflow is pinned to a mutable main ref rather than a commit SHA (supply chain risk), and the gh api call for PR data is unquoted/unvalidated before piping to jq, though the latter is low risk given the prior permission check.
📝 2 suggestion(s) - Please review inline comments below.
💡 How to re-trigger
Comment /review or /pr-reviewer on this PR
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Proposed changes not required
shazron
left a comment
There was a problem hiding this comment.
Update the required checks in Settings -> Branches. Remove the node 18 checks, add the 22, 24 checks.
Description
Adds an AI-powered PR reviewer workflow that automatically reviews pull requests using Claude via AWS Bedrock. Triggers on PR open/reopen/synchronize and on
/reviewor/pr-reviewercomments by admins or maintainers.Related Issue
ACNA-4515
Motivation and Context
Reduces code review toil by providing automated first-pass reviews with inline suggestions. Part of a broader rollout across App Builder repos.
How Has This Been Tested?
Tested end-to-end in
adobe/generator-aio-app— workflow triggers correctly on PR events and/reviewcomments, posts inline suggestions and summary reviews viagithub-actions[bot].Screenshots (if appropriate):
N/A
Types of changes
Checklist: