Skip to content

Upgrade vulnerable dependencies flagged in security scan (netty, commons-fileupload, grpc) #3057

Upgrade vulnerable dependencies flagged in security scan (netty, commons-fileupload, grpc)

Upgrade vulnerable dependencies flagged in security scan (netty, commons-fileupload, grpc) #3057

Workflow file for this run

name: dotbot code act
on:
issue_comment:
types: [created]
pull_request_review_comment:
types: [created]
concurrency:
group: dotbot-act-${{ github.event.issue.number || github.event.pull_request.number || github.ref }}
cancel-in-progress: false
jobs:
act:
name: Act on /dotbot comments
# Authorization gate: only repo owners, org members, and collaborators may
# trigger the autonomous agent. Without this, any GitHub user could comment
# `/dotbot` on a PR and launch a write-privileged agent (privilege escalation).
if: >-
(
(
github.event_name == 'issue_comment' &&
startsWith(github.event.comment.body, '/dotbot') &&
github.event.issue.pull_request
) || (
github.event_name == 'pull_request_review_comment' &&
startsWith(github.event.comment.body, '/dotbot')
)
) &&
github.actor != 'dependabot[bot]' &&
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.comment.author_association)
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
issues: write
steps:
# Pinned to a full commit SHA: a mutable tag could be repointed to run
# attacker-controlled code with this job's write-scoped GITHUB_TOKEN.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
# The action code must be loaded from the pinned release SHA, not this
# checkout (untrusted PR head), so `uses:` points at a fixed commit.
# Note: the checkout is still the PR head by design (the agent edits it),
# which is why the authorization gate above is critical.
ref: ${{ github.event.pull_request.head.sha || format('refs/pull/{0}/head', github.event.issue.number) }}
- name: dotbot autonomous edits
uses: wezell/openrouter-code-review-action@34ee169dd9f35bf20a6b358b902c6c76e5df3a14
with:
mode: act
openrouter_api_key: ${{ secrets.OPENROUTER_API_KEY }}
model: deepseek/deepseek-v4-pro-0813
reasoning_effort: high
web_search_mode: cached
debug_level: 1