Compare commits
2 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| e65ac772f6 | |||
| 7182a6f8f4 |
-11
@@ -20,20 +20,10 @@ inputs:
|
||||
bot-token:
|
||||
description: API key or token for the selected bot
|
||||
required: false
|
||||
model:
|
||||
description: >-
|
||||
Model for the selected bot. Defaults to `claude-sonnet-5` or
|
||||
`gpt-5.6-terra`, the mid tiers, which cover reviews and fixes.
|
||||
required: false
|
||||
|
||||
runs:
|
||||
using: composite
|
||||
steps:
|
||||
# The agent works on the event's commit with full history, as the author.
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
token: ${{ inputs.author-token }}
|
||||
# This step assumes this is `node:24-bookworm` container.
|
||||
- name: Install dependencies
|
||||
shell: bash
|
||||
@@ -45,7 +35,6 @@ runs:
|
||||
ACTION_PATH: ${{ gitea.action_path }}
|
||||
BOT_TYPE: ${{ inputs.bot-type }}
|
||||
BOT_TOKEN: ${{ inputs.bot-token }}
|
||||
MODEL: ${{ inputs.model }}
|
||||
GITEA_API_URL: ${{ gitea.api_url }}
|
||||
GITEA_REPOSITORY: ${{ gitea.repository }}
|
||||
GITEA_TOKEN: ${{ inputs.author-token }}
|
||||
|
||||
@@ -13,39 +13,15 @@ response ends, so background monitors, scheduled wake-ups, and queued tasks
|
||||
never resume. Never promise future action and never claim to be waiting on a
|
||||
notification.
|
||||
|
||||
The repository is checked out in the working directory at the event's commit,
|
||||
the head of the pull request when there is one, with full history and the
|
||||
author's push credentials. Read the code there, run its checks and tests when
|
||||
they bear on the task, and push from there.
|
||||
|
||||
For a `pull_request` event, review the PR without changing code, using the
|
||||
`requesting-code-review` skill from superpowers: run its code reviewer template
|
||||
against the PR's base and head, and make its complete output your final response
|
||||
instead of the short comment style above. Run the project's checks on the head
|
||||
and treat a failure as at least Important. Check the whole repository against
|
||||
the code rules at the end of this prompt, not only the diff; a violation is at
|
||||
least Important even when the diff did not cause it. Your final response is
|
||||
posted verbatim as a pull request review from the bot account, so it is the
|
||||
review text and nothing else: no narration about what you did, verified, or are
|
||||
about to post, whether you reviewed yourself or relayed a reviewer subagent. Its
|
||||
first line must be exactly the template's verdict and nothing else: `Yes`, `No`,
|
||||
or `With fixes`. `Yes` approves and the other two request changes; any other
|
||||
first line is posted as a plain comment, which wastes the run. Minor issues
|
||||
alone never block, and neither does a finding the author has answered in the
|
||||
comment history below as intended or a false alarm, once the code or docs make
|
||||
that clear. When the verdict is not `Yes`, the second line names what must
|
||||
change in one line, addressed to the author; the author's own agent picks the
|
||||
fixes up, so never ask `@bot` to make them. For UI changes, check that the
|
||||
result is aligned, clean, and pixel-perfect, and that included screenshots prove
|
||||
the intended result was achieved.
|
||||
|
||||
The review must read at a glance: everything outside `<details>` blocks totals
|
||||
under 512 bytes. Only core information stays visible: the verdict, the summary
|
||||
line, and the section headings. Anything verbose goes into a `<details>` block
|
||||
whose `<summary>` is a few words, such as the `file:line` and title of an issue
|
||||
with the what, why, and how inside; the same for each strength, each
|
||||
recommendation, the reasoning, and any compliance notes. Details blocks are
|
||||
top-level, never inside a list item, because Gitea breaks them there.
|
||||
For a `pull_request` event, review the PR without changing code. Your final
|
||||
response is posted as a pull request review from the bot account: it requests
|
||||
changes when it mentions `@bot` and approves otherwise. So include `@bot` with
|
||||
instructions to fix the findings exactly when changes are needed, and never
|
||||
mention `@bot` when the PR is ready. For UI changes, check that the result is
|
||||
aligned, clean, and pixel-perfect, and that included screenshots prove the
|
||||
intended result was achieved. Also check the whole repository, not only the
|
||||
diff, against the code rules at the end of this prompt, and request changes for
|
||||
every violation you find even when the diff did not cause it.
|
||||
|
||||
For an `issue_comment` or `pull_request_review_comment` event, treat the `body`
|
||||
in the triggering comment payload below as the user's exact instruction.
|
||||
|
||||
@@ -20,13 +20,6 @@ const EVENT = env("EVENT_NAME");
|
||||
const AUTHOR_TOKEN = env("GITEA_TOKEN");
|
||||
const REVIEWER_TOKEN = env("REVIEWER_TOKEN");
|
||||
const RULES_PATH = "repos/commons/code-rules/raw/README.md";
|
||||
// The mid tiers: a run follows a fixed template and the project's checks.
|
||||
const DEFAULT_MODELS: Record<string, string> = {
|
||||
claude: "claude-sonnet-5",
|
||||
codex: "gpt-5.6-terra",
|
||||
};
|
||||
const model = (bot: string): string =>
|
||||
Deno.env.get("MODEL") || DEFAULT_MODELS[bot];
|
||||
|
||||
// The reviewer token is withheld so the agent cannot approve as the bot.
|
||||
const { REVIEWER_TOKEN: _, ...agentEnv } = Deno.env.toObject();
|
||||
@@ -59,50 +52,32 @@ async function postComment(body: string): Promise<void> {
|
||||
});
|
||||
}
|
||||
|
||||
// A pull request event is a review request, so the response becomes a review.
|
||||
// Its first line is the verdict; anything unexpected only comments, never
|
||||
// approves.
|
||||
const VERDICTS: Record<string, string> = {
|
||||
Yes: "APPROVED",
|
||||
No: "REQUEST_CHANGES",
|
||||
"With fixes": "REQUEST_CHANGES",
|
||||
};
|
||||
|
||||
// A pull request event is a review request, so the response becomes a review:
|
||||
// changes are requested when the agent asked @bot to fix something, a failed
|
||||
// run only comments, and anything else approves.
|
||||
async function postResult(body: string): Promise<void> {
|
||||
if (EVENT !== "pull_request") return postComment(body);
|
||||
const [verdict] = body.split("\n", 1);
|
||||
const event = body.includes("@bot")
|
||||
? "REQUEST_CHANGES"
|
||||
: body.startsWith("Bot failed:")
|
||||
? "COMMENT"
|
||||
: "APPROVED";
|
||||
await gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
|
||||
body: stripAnsi(body),
|
||||
event: VERDICTS[verdict.trim()] ?? "COMMENT",
|
||||
event,
|
||||
});
|
||||
}
|
||||
|
||||
async function run(command: string, args: string[]): Promise<void> {
|
||||
const { success, code } = await new Deno.Command(command, { args }).output();
|
||||
if (!success) throw new Error(`${command} ${args[0]} exited with ${code}`);
|
||||
}
|
||||
|
||||
// Commits belong to the same account as the pull request they end up in.
|
||||
async function configureGitAuthor(): Promise<void> {
|
||||
const user: GiteaUser = await (await gitea(AUTHOR_TOKEN, "user")).json();
|
||||
for (const [key, value] of [["name", user.login], ["email", user.email]]) {
|
||||
await run("git", ["config", "--global", `user.${key}`, value]);
|
||||
await new Deno.Command("git", {
|
||||
args: ["config", "--global", `user.${key}`, value],
|
||||
}).output();
|
||||
}
|
||||
}
|
||||
|
||||
// The superpowers plugin gives the agent its skills, including the code review
|
||||
// one that the prompt asks for. Both installs are idempotent on the persisted
|
||||
// home.
|
||||
async function installSuperpowers(bot: string): Promise<void> {
|
||||
const commands = bot === "claude"
|
||||
? [
|
||||
["plugin", "marketplace", "add", "obra/superpowers-marketplace"],
|
||||
["plugin", "install", "-y", "superpowers@superpowers-marketplace"],
|
||||
]
|
||||
: [["plugin", "add", "superpowers@openai-curated-remote"]];
|
||||
for (const args of commands) await run(bot, args);
|
||||
}
|
||||
|
||||
async function renderPrompt(): Promise<string> {
|
||||
const comments: GiteaComment[] = await (await gitea(
|
||||
REVIEWER_TOKEN,
|
||||
@@ -131,17 +106,17 @@ async function renderPrompt(): Promise<string> {
|
||||
async function runClaude(prompt: string): Promise<string> {
|
||||
const token = Deno.env.get("BOT_TOKEN");
|
||||
if (!token) {
|
||||
throw new Error(
|
||||
await postComment(
|
||||
"Run `claude setup-token` locally and set the `bot-token` action input.",
|
||||
);
|
||||
Deno.exit(1);
|
||||
}
|
||||
await installSuperpowers("claude");
|
||||
const claude = new Deno.Command("claude", {
|
||||
args: [
|
||||
"--print",
|
||||
"--dangerously-skip-permissions",
|
||||
"--model",
|
||||
model("claude"),
|
||||
"claude-fable-5",
|
||||
"--output-format",
|
||||
"stream-json",
|
||||
"--verbose",
|
||||
@@ -152,7 +127,7 @@ async function runClaude(prompt: string): Promise<string> {
|
||||
clearEnv: true,
|
||||
stdout: "piped",
|
||||
}).spawn();
|
||||
let result: { result?: string; subtype: string } | undefined;
|
||||
let result = "Bot failed: no result";
|
||||
// Print events as they stream so the runner does not kill the job as a zombie.
|
||||
const lines = claude.stdout
|
||||
.pipeThrough(new TextDecoderStream())
|
||||
@@ -164,13 +139,12 @@ async function runClaude(prompt: string): Promise<string> {
|
||||
const text = part.thinking ?? part.text ?? part.name;
|
||||
if (text) console.log(text);
|
||||
}
|
||||
if (event.type === "result") result = event;
|
||||
if (event.type === "result") {
|
||||
result = event.result ?? `Bot failed: ${event.subtype}`;
|
||||
}
|
||||
}
|
||||
await claude.status;
|
||||
if (result?.result === undefined) {
|
||||
throw new Error(`claude ended with ${result?.subtype ?? "no result"}`);
|
||||
}
|
||||
return result.result;
|
||||
return result;
|
||||
}
|
||||
|
||||
// Posts the device code so a human can finish the login on the persisted home.
|
||||
@@ -200,13 +174,12 @@ async function runCodex(prompt: string): Promise<string> {
|
||||
})
|
||||
.output();
|
||||
if (!loggedIn.success) await codexDeviceLogin();
|
||||
await installSuperpowers("codex");
|
||||
const file = await Deno.makeTempFile();
|
||||
const status = await new Deno.Command("codex", {
|
||||
args: [
|
||||
"exec",
|
||||
"--model",
|
||||
model("codex"),
|
||||
"gpt-5.5",
|
||||
"--dangerously-bypass-approvals-and-sandbox",
|
||||
"--output-last-message",
|
||||
file,
|
||||
@@ -221,14 +194,9 @@ async function runCodex(prompt: string): Promise<string> {
|
||||
return await Deno.readTextFile(file);
|
||||
}
|
||||
|
||||
try {
|
||||
await configureGitAuthor();
|
||||
const prompt = await renderPrompt();
|
||||
const result = env("BOT_TYPE") === "claude"
|
||||
? await runClaude(prompt)
|
||||
: await runCodex(prompt);
|
||||
await postResult(result);
|
||||
} catch (error) {
|
||||
await postComment(`Bot failed: ${error}`);
|
||||
throw error;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user