4 Commits

Author SHA1 Message Date
temeddix 95f1bee140 Install superpowers and use its review skill
Check / deno (pull_request) Successful in 34s
2026-09-13 23:28:33 +09:00
temeddix 318b2b0a63 Add the review guide 2026-09-13 23:16:58 +09:00
temeddix e65ac772f6 Rewrite the runner in TypeScript
Check / deno (pull_request) Successful in 45s
2026-09-13 23:09:53 +09:00
temeddix 7182a6f8f4 Split author and reviewer tokens 2026-09-13 22:58:24 +09:00
3 changed files with 37 additions and 160 deletions
-11
View File
@@ -20,20 +20,10 @@ inputs:
bot-token: bot-token:
description: API key or token for the selected bot description: API key or token for the selected bot
required: false required: false
model:
description: >-
Model for the selected bot. Defaults to `claude-sonnet-5` or
`gpt-5.6-terra`, the mid tiers, which cover reviews and fixes.
required: false
runs: runs:
using: composite using: composite
steps: steps:
# The agent works on the event's commit with full history, as the author.
- uses: actions/checkout@v4
with:
fetch-depth: 0
token: ${{ inputs.author-token }}
# This step assumes this is `node:24-bookworm` container. # This step assumes this is `node:24-bookworm` container.
- name: Install dependencies - name: Install dependencies
shell: bash shell: bash
@@ -45,7 +35,6 @@ runs:
ACTION_PATH: ${{ gitea.action_path }} ACTION_PATH: ${{ gitea.action_path }}
BOT_TYPE: ${{ inputs.bot-type }} BOT_TYPE: ${{ inputs.bot-type }}
BOT_TOKEN: ${{ inputs.bot-token }} BOT_TOKEN: ${{ inputs.bot-token }}
MODEL: ${{ inputs.model }}
GITEA_API_URL: ${{ gitea.api_url }} GITEA_API_URL: ${{ gitea.api_url }}
GITEA_REPOSITORY: ${{ gitea.repository }} GITEA_REPOSITORY: ${{ gitea.repository }}
GITEA_TOKEN: ${{ inputs.author-token }} GITEA_TOKEN: ${{ inputs.author-token }}
+10 -43
View File
@@ -13,50 +13,17 @@ response ends, so background monitors, scheduled wake-ups, and queued tasks
never resume. Never promise future action and never claim to be waiting on a never resume. Never promise future action and never claim to be waiting on a
notification. notification.
The repository is checked out in the working directory at the event's commit, For a `pull_request` event, review the PR without changing code, using the
the head of the pull request when there is one, with full history and the
author's push credentials. Read the code there, run its checks and tests when
they bear on the task, and push from there.
For a `pull_request` event, and for a comment on a pull request that asks you to
review it, review the PR without changing code, using the
`requesting-code-review` skill from superpowers: run its code reviewer template `requesting-code-review` skill from superpowers: run its code reviewer template
against the PR's base and head. Run the project's checks on the head and treat a against the PR's base and head, and make its complete output your final response
failure as at least Important. Check the whole repository against the code rules instead of the short comment style above. Check the whole repository against the
at the end of this prompt, not only the diff; a violation is at least Important code rules at the end of this prompt, not only the diff; a violation is at least
even when the diff did not cause it. Write the complete review, and nothing Important even when the diff did not cause it. Your final response is posted as
else, to the file `${REVIEW_PATH}`: it is posted verbatim as a pull request a pull request review from the bot account: it requests changes when it mentions
review from the bot account, and your final response is not posted at all. The `@bot` and approves otherwise, so the assessment instructs `@bot` to make the
file's first line must be exactly the verdict and nothing else: `Approved` when fixes exactly when it is not `Yes`, and Minor issues alone never block. For UI
the template's answer is yes, `Changes requested` otherwise. The mark in front changes, check that the result is aligned, clean, and pixel-perfect, and that
of it is added when posting, so write the words alone; any other first line is included screenshots prove the intended result was achieved.
posted as a plain comment, which wastes the run. Minor issues alone never block,
and neither does a finding the author has answered in the comment history below
as intended or a false alarm, once the code or docs make that clear. When the
verdict is `Changes requested`, the second line names what must change in one
line, addressed to the author; the author's own agent picks the fixes up, so
never ask `@bot` to make them. For UI changes, check that the result is aligned,
clean, and pixel-perfect, and that included screenshots prove the intended
result was achieved.
Every finding that belongs to one line of the diff goes on that line instead of
into the body. Write those to `${ANCHORS_PATH}` as a JSON array, each entry
`{"path": "<path from the repository root>", "line": <number>, "side": "new" |
"old", "body": "<the finding>"}`.
`side` is `new` for a line in the head file and `old` for one only in the base
file; `line` is that file's own line number, and it must be a line the diff
touches, or Gitea refuses the anchor. Write the file only when there is
something to anchor, and keep each body to the what, the why, and the how, with
no `file:line` prefix; the line carries that.
The review body must read at a glance: everything outside `<details>` blocks
totals under 512 bytes. Only core information stays visible: the verdict, the
summary line, and the section headings. Anything verbose goes into a `<details>`
block whose `<summary>` is a few words, such as the title of an issue with the
what, why, and how inside; the same for each strength, each recommendation, the
reasoning, and any compliance notes. A finding you anchored belongs there only
as its title, since its detail is on the line. Details blocks are top-level,
never inside a list item, because Gitea breaks them there.
For an `issue_comment` or `pull_request_review_comment` event, treat the `body` For an `issue_comment` or `pull_request_review_comment` event, treat the `body`
in the triggering comment payload below as the user's exact instruction. in the triggering comment payload below as the user's exact instruction.
+20 -99
View File
@@ -20,13 +20,6 @@ const EVENT = env("EVENT_NAME");
const AUTHOR_TOKEN = env("GITEA_TOKEN"); const AUTHOR_TOKEN = env("GITEA_TOKEN");
const REVIEWER_TOKEN = env("REVIEWER_TOKEN"); const REVIEWER_TOKEN = env("REVIEWER_TOKEN");
const RULES_PATH = "repos/commons/code-rules/raw/README.md"; const RULES_PATH = "repos/commons/code-rules/raw/README.md";
// The mid tiers: a run follows a fixed template and the project's checks.
const DEFAULT_MODELS: Record<string, string> = {
claude: "claude-sonnet-5",
codex: "gpt-5.6-terra",
};
const model = (bot: string): string =>
Deno.env.get("MODEL") || DEFAULT_MODELS[bot];
// The reviewer token is withheld so the agent cannot approve as the bot. // The reviewer token is withheld so the agent cannot approve as the bot.
const { REVIEWER_TOKEN: _, ...agentEnv } = Deno.env.toObject(); const { REVIEWER_TOKEN: _, ...agentEnv } = Deno.env.toObject();
@@ -59,84 +52,19 @@ async function postComment(body: string): Promise<void> {
}); });
} }
// A review is posted whenever the agent wrote one, whether a review request or // A pull request event is a review request, so the response becomes a review:
// a comment asked for it. It comes through a file, because a final chat message // changes are requested when the agent asked @bot to fix something, a failed
// picks up narration while a file's first line is written on purpose. That line // run only comments, and anything else approves.
// is the verdict, matched whole; anything unexpected only comments, never
// approves. The mark in front is added here, so it is never part of the match.
const REVIEW_DIR = await Deno.makeTempDir();
const REVIEW_PATH = `${REVIEW_DIR}/review.md`;
const VERDICTS: Record<string, [event: string, mark: string]> = {
Approved: ["APPROVED", "✅"],
"Changes requested": ["REQUEST_CHANGES", "🛑"],
};
// A finding about one line is posted on that line of the diff rather than as
// `file:line` prose in the body. Those anchors come as JSON, so the file and
// line are structured instead of parsed back out of English; a malformed entry
// fails the run, because a silently dropped finding is worse than a red run.
const ANCHORS_PATH = `${REVIEW_DIR}/anchors.json`;
type Anchor = { path: string; line: number; side: "new" | "old"; body: string };
function parseAnchors(text: string): Anchor[] {
const entries: unknown = JSON.parse(text);
if (!Array.isArray(entries)) throw new Error(`${ANCHORS_PATH}: not an array`);
return entries.map((entry: unknown, index) => {
const at = `${ANCHORS_PATH}[${index}]`;
if (typeof entry !== "object" || entry === null) {
throw new Error(`${at}: not an object`);
}
const { path, line, side = "new", body } = entry as Record<string, unknown>;
if (typeof path !== "string" || path === "") {
throw new Error(`${at}.path: expected a repository path`);
}
if (typeof line !== "number" || !Number.isInteger(line) || line < 1) {
throw new Error(`${at}.line: expected a line number`);
}
if (side !== "new" && side !== "old") {
throw new Error(`${at}.side: expected "new" or "old"`);
}
if (typeof body !== "string" || body.trim() === "") {
throw new Error(`${at}.body: expected the finding`);
}
return { path, line, side, body };
});
}
async function readAnchors(): Promise<Anchor[]> {
const written = await Deno.readTextFile(ANCHORS_PATH).catch(() => null);
return written === null ? [] : parseAnchors(written);
}
async function postResult(body: string): Promise<void> { async function postResult(body: string): Promise<void> {
const review = await Deno.readTextFile(REVIEW_PATH).catch(() => null); if (EVENT !== "pull_request") return postComment(body);
if (review === null) { const event = body.includes("@bot")
if (EVENT === "pull_request") { ? "REQUEST_CHANGES"
throw new Error(`no review was written to ${REVIEW_PATH}`); : body.startsWith("Bot failed:")
} ? "COMMENT"
return postComment(body); : "APPROVED";
} await gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
const [verdict, ...rest] = review.split("\n");
const [event, mark] = VERDICTS[verdict.trim()] ?? ["COMMENT", "💬"];
const post = (anchors: Anchor[]) =>
gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
body: stripAnsi([`${mark} ${verdict.trim()}`, ...rest].join("\n")),
event,
comments: anchors.map(({ path, line, side, body }) => ({
path,
body: stripAnsi(body), body: stripAnsi(body),
new_position: side === "new" ? line : 0, event,
old_position: side === "old" ? line : 0,
})),
});
const anchors = await readAnchors();
// Gitea rejects the whole review when an anchor names a line outside the
// diff, and a verdict that never lands blocks the pull request, so the body
// goes up alone rather than not at all.
await post(anchors).catch(async (error: Error) => {
if (anchors.length === 0) throw error;
console.error(`inline comments rejected: ${error.message}`);
await post([]);
}); });
} }
@@ -181,8 +109,6 @@ async function renderPrompt(): Promise<string> {
GITEA_API_URL: API, GITEA_API_URL: API,
GITEA_REPOSITORY: REPO, GITEA_REPOSITORY: REPO,
ISSUE_INDEX: INDEX, ISSUE_INDEX: INDEX,
REVIEW_PATH,
ANCHORS_PATH,
}; };
const template = await Deno.readTextFile( const template = await Deno.readTextFile(
new URL("prompt.md", import.meta.url), new URL("prompt.md", import.meta.url),
@@ -196,9 +122,10 @@ async function renderPrompt(): Promise<string> {
async function runClaude(prompt: string): Promise<string> { async function runClaude(prompt: string): Promise<string> {
const token = Deno.env.get("BOT_TOKEN"); const token = Deno.env.get("BOT_TOKEN");
if (!token) { if (!token) {
throw new Error( await postComment(
"Run `claude setup-token` locally and set the `bot-token` action input.", "Run `claude setup-token` locally and set the `bot-token` action input.",
); );
Deno.exit(1);
} }
await installSuperpowers("claude"); await installSuperpowers("claude");
const claude = new Deno.Command("claude", { const claude = new Deno.Command("claude", {
@@ -206,7 +133,7 @@ async function runClaude(prompt: string): Promise<string> {
"--print", "--print",
"--dangerously-skip-permissions", "--dangerously-skip-permissions",
"--model", "--model",
model("claude"), "claude-fable-5",
"--output-format", "--output-format",
"stream-json", "stream-json",
"--verbose", "--verbose",
@@ -217,7 +144,7 @@ async function runClaude(prompt: string): Promise<string> {
clearEnv: true, clearEnv: true,
stdout: "piped", stdout: "piped",
}).spawn(); }).spawn();
let result: { result?: string; subtype: string } | undefined; let result = "Bot failed: no result";
// Print events as they stream so the runner does not kill the job as a zombie. // Print events as they stream so the runner does not kill the job as a zombie.
const lines = claude.stdout const lines = claude.stdout
.pipeThrough(new TextDecoderStream()) .pipeThrough(new TextDecoderStream())
@@ -229,13 +156,12 @@ async function runClaude(prompt: string): Promise<string> {
const text = part.thinking ?? part.text ?? part.name; const text = part.thinking ?? part.text ?? part.name;
if (text) console.log(text); if (text) console.log(text);
} }
if (event.type === "result") result = event; if (event.type === "result") {
result = event.result ?? `Bot failed: ${event.subtype}`;
}
} }
await claude.status; await claude.status;
if (result?.result === undefined) { return result;
throw new Error(`claude ended with ${result?.subtype ?? "no result"}`);
}
return result.result;
} }
// Posts the device code so a human can finish the login on the persisted home. // Posts the device code so a human can finish the login on the persisted home.
@@ -271,7 +197,7 @@ async function runCodex(prompt: string): Promise<string> {
args: [ args: [
"exec", "exec",
"--model", "--model",
model("codex"), "gpt-5.5",
"--dangerously-bypass-approvals-and-sandbox", "--dangerously-bypass-approvals-and-sandbox",
"--output-last-message", "--output-last-message",
file, file,
@@ -286,14 +212,9 @@ async function runCodex(prompt: string): Promise<string> {
return await Deno.readTextFile(file); return await Deno.readTextFile(file);
} }
try {
await configureGitAuthor(); await configureGitAuthor();
const prompt = await renderPrompt(); const prompt = await renderPrompt();
const result = env("BOT_TYPE") === "claude" const result = env("BOT_TYPE") === "claude"
? await runClaude(prompt) ? await runClaude(prompt)
: await runCodex(prompt); : await runCodex(prompt);
await postResult(result); await postResult(result);
} catch (error) {
await postComment(`Bot failed: ${error}`);
throw error;
}