Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 9 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,8 +32,16 @@ jobs:
# Catches invalid workflow files (e.g. a non-existent permission scope),
# which GitHub rejects wholesale — the run then never starts and the only
# trace is a failed "workflow file issue" run.
#
# actionlint 1.7.12 predates the concurrency `queue` key. GitHub accepts
# it (SchemaStore knows it), so dotbot-act.yml legitimately uses
# `queue: max` to let back-to-back /dotbot runs queue instead of
# cancelling each other. Ignore just that diagnostic until actionlint
# ships the schema — everything else stays enforced.
- name: Lint workflows (actionlint)
run: uvx --from actionlint-py==1.7.12.25 actionlint
run: |
uvx --from actionlint-py==1.7.12.25 actionlint \
-ignore 'unexpected key "queue" for "concurrency" section'

- name: Run tests
run: uv run pytest -q
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/dotbot-act.yml
Original file line number Diff line number Diff line change
Expand Up @@ -101,10 +101,10 @@ jobs:
echo "Rendered act model config from DOTBOT_ACT_MODEL:"
cat "$RUNNER_TEMP/dotbot-act-model.yml"
- name: dotbot autonomous edits
# Trusted main ref, NOT the PR-head checkout. This repo is the canonical
# home, so the pin points at itself (kept in lockstep with the review
# workflow). 3f4cfa1 = v1.3.1 / v1 / latest.
uses: dotCMS/openrouter-code-review-action@3f4cfa1356843d7ac3e764f331f88a883f5bf44b
# Trusted ref, NOT the PR-head checkout. This repo is the canonical home,
# so `latest` points at ourselves (kept in lockstep with the review
# workflow) — enforced by tests/test_module_coverage.py.
uses: dotCMS/openrouter-code-review-action@latest
with:
mode: act
# DOTBOT_ACT_MODEL wins when set; otherwise the in-repo config file.
Expand Down
24 changes: 8 additions & 16 deletions .github/workflows/dotbot-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,24 +78,16 @@ jobs:
} > .openrouter-review.yml
echo "Rendered .openrouter-review.yml from DOTBOT_REVIEW_MODELS:"
cat .openrouter-review.yml
# Always run the action's latest release via the @latest ref (2026-09-03,
# was pinned to SHA a716ed1 = v1.0.1-era). Pinning is the audit-friendly
# choice; we deliberately trade that for freshness here — the action only
# holds read creds + posts review comments, and stale pins caused the
# roster/attestation debugging on PR #860 to run against old code.
# Always run the action's latest release via the @latest ref. Pinning to a
# SHA is the more audit-friendly choice, but we own this repo and cut every
# release here (auto-release.yml), so the moving `latest` tag is equally
# trusted — and it can never lag an input the workflow passes (a stale pin
# silently drops inputs; that is how github_approval_token was ignored).
- name: dotbot autonomous review
id: dotbot
# Trusted ref, NOT the PR-head checkout. Update this SHA on each
# release (matches the v1/latest tag) — enforced by
# tests/test_module_coverage.py.
#
# This repo is the canonical home (releases are cut here by
# auto-release.yml), so the pin points at itself: the upstream
# wezell/openrouter-code-review-action has no release carrying the
# github_approval_token input, and the old wezell@d68edbb pin predated it,
# so GitHub silently dropped the input and auto-approval never fired.
# 3f4cfa1 = v1.3.1 / v1 / latest.
uses: dotCMS/openrouter-code-review-action@3f4cfa1356843d7ac3e764f331f88a883f5bf44b
# Trusted ref, NOT the PR-head checkout. `latest` tracks the newest
# release cut from this repo — enforced by tests/test_module_coverage.py.
uses: dotCMS/openrouter-code-review-action@latest
with:
mode: review
openrouter_api_key: ${{ secrets.OPENROUTER_API_KEY }}
Expand Down
12 changes: 7 additions & 5 deletions tests/test_module_coverage.py
Original file line number Diff line number Diff line change
Expand Up @@ -789,11 +789,13 @@ def test_review_action_and_workflow_use_expected_resume_guard_and_model() -> Non
# predates the github_approval_token input.
assert "dotCMS/openrouter-code-review-action@" in review_workflow
assert "dotCMS/openrouter-code-review-action@" in act_workflow
# Both workflows must pin the SAME released commit, and it must be a release
# that carries every input the workflows pass: a pin predating an input makes
# GitHub silently drop it (that is how github_approval_token was ignored and
# dotbot never approved a PR). Bump this constant with the pins on release.
expected_action_pin = "3f4cfa1356843d7ac3e764f331f88a883f5bf44b"
# Both workflows track the same moving `latest` tag instead of a frozen
# SHA. dotCMS owns this repo and cuts every release here (auto-release.yml),
# so the tag is as trusted as a SHA — and it can never lag an input the
# workflows pass. A pin predating an input makes GitHub silently drop it
# (that is how github_approval_token was ignored and dotbot never approved a
# PR), which is exactly why we float on `latest` rather than bump a SHA.
expected_action_pin = "latest"
pins = {
line.split("dotCMS/openrouter-code-review-action@", 1)[1].strip()
for line in (review_workflow + act_workflow).splitlines()
Expand Down
Loading