Repository navigation
Upgrade vulnerable dependencies flagged in security scan (netty, commons-fileupload, grpc) #3057
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: dotbot code act | |
| on: | |
| issue_comment: | |
| types: [created] | |
| pull_request_review_comment: | |
| types: [created] | |
| concurrency: | |
| group: dotbot-act-${{ github.event.issue.number || github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: false | |
| jobs: | |
| act: | |
| name: Act on /dotbot comments | |
| # Authorization gate: only repo owners, org members, and collaborators may | |
| # trigger the autonomous agent. Without this, any GitHub user could comment | |
| # `/dotbot` on a PR and launch a write-privileged agent (privilege escalation). | |
| if: >- | |
| ( | |
| ( | |
| github.event_name == 'issue_comment' && | |
| startsWith(github.event.comment.body, '/dotbot') && | |
| github.event.issue.pull_request | |
| ) || ( | |
| github.event_name == 'pull_request_review_comment' && | |
| startsWith(github.event.comment.body, '/dotbot') | |
| ) | |
| ) && | |
| github.actor != 'dependabot[bot]' && | |
| contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.comment.author_association) | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| issues: write | |
| steps: | |
| # Pinned to a full commit SHA: a mutable tag could be repointed to run | |
| # attacker-controlled code with this job's write-scoped GITHUB_TOKEN. | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| # The action code must be loaded from the pinned release SHA, not this | |
| # checkout (untrusted PR head), so `uses:` points at a fixed commit. | |
| # Note: the checkout is still the PR head by design (the agent edits it), | |
| # which is why the authorization gate above is critical. | |
| ref: ${{ github.event.pull_request.head.sha || format('refs/pull/{0}/head', github.event.issue.number) }} | |
| - name: dotbot autonomous edits | |
| uses: wezell/openrouter-code-review-action@34ee169dd9f35bf20a6b358b902c6c76e5df3a14 | |
| with: | |
| mode: act | |
| openrouter_api_key: ${{ secrets.OPENROUTER_API_KEY }} | |
| model: deepseek/deepseek-v4-pro-0813 | |
| reasoning_effort: high | |
| web_search_mode: cached | |
| debug_level: 1 |