Compare commits
8 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| d1eaa7dbe0 | |||
| 0d109ebec8 | |||
| a2bc4c9541 | |||
| 75d3593376 | |||
| 439f2b4e77 | |||
| f0506adfea | |||
| b8d0093ef2 | |||
| 8c2041bbc5 |
+11
@@ -20,10 +20,20 @@ inputs:
|
|||||||
bot-token:
|
bot-token:
|
||||||
description: API key or token for the selected bot
|
description: API key or token for the selected bot
|
||||||
required: false
|
required: false
|
||||||
|
model:
|
||||||
|
description: >-
|
||||||
|
Model for the selected bot. Defaults to `claude-sonnet-5` or
|
||||||
|
`gpt-5.6-terra`, the mid tiers, which cover reviews and fixes.
|
||||||
|
required: false
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: composite
|
using: composite
|
||||||
steps:
|
steps:
|
||||||
|
# The agent works on the event's commit with full history, as the author.
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
token: ${{ inputs.author-token }}
|
||||||
# This step assumes this is `node:24-bookworm` container.
|
# This step assumes this is `node:24-bookworm` container.
|
||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
shell: bash
|
shell: bash
|
||||||
@@ -35,6 +45,7 @@ runs:
|
|||||||
ACTION_PATH: ${{ gitea.action_path }}
|
ACTION_PATH: ${{ gitea.action_path }}
|
||||||
BOT_TYPE: ${{ inputs.bot-type }}
|
BOT_TYPE: ${{ inputs.bot-type }}
|
||||||
BOT_TOKEN: ${{ inputs.bot-token }}
|
BOT_TOKEN: ${{ inputs.bot-token }}
|
||||||
|
MODEL: ${{ inputs.model }}
|
||||||
GITEA_API_URL: ${{ gitea.api_url }}
|
GITEA_API_URL: ${{ gitea.api_url }}
|
||||||
GITEA_REPOSITORY: ${{ gitea.repository }}
|
GITEA_REPOSITORY: ${{ gitea.repository }}
|
||||||
GITEA_TOKEN: ${{ inputs.author-token }}
|
GITEA_TOKEN: ${{ inputs.author-token }}
|
||||||
|
|||||||
@@ -13,15 +13,38 @@ response ends, so background monitors, scheduled wake-ups, and queued tasks
|
|||||||
never resume. Never promise future action and never claim to be waiting on a
|
never resume. Never promise future action and never claim to be waiting on a
|
||||||
notification.
|
notification.
|
||||||
|
|
||||||
For a `pull_request` event, review the PR without changing code. Your final
|
The repository is checked out in the working directory at the event's commit,
|
||||||
response is posted as a pull request review from the bot account: it requests
|
the head of the pull request when there is one, with full history and the
|
||||||
changes when it mentions `@bot` and approves otherwise. So include `@bot` with
|
author's push credentials. Read the code there, run its checks and tests when
|
||||||
instructions to fix the findings exactly when changes are needed, and never
|
they bear on the task, and push from there.
|
||||||
mention `@bot` when the PR is ready. For UI changes, check that the result is
|
|
||||||
aligned, clean, and pixel-perfect, and that included screenshots prove the
|
For a `pull_request` event, review the PR without changing code, using the
|
||||||
intended result was achieved. Also check the whole repository, not only the
|
`requesting-code-review` skill from superpowers: run its code reviewer template
|
||||||
diff, against the code rules at the end of this prompt, and request changes for
|
against the PR's base and head. Run the project's checks on the head and treat a
|
||||||
every violation you find even when the diff did not cause it.
|
failure as at least Important. Check the whole repository against the code rules
|
||||||
|
at the end of this prompt, not only the diff; a violation is at least Important
|
||||||
|
even when the diff did not cause it. Write the complete review, and nothing
|
||||||
|
else, to the file `${REVIEW_PATH}`: it is posted verbatim as a pull request
|
||||||
|
review from the bot account, and your final response is not posted at all. The
|
||||||
|
file's first line must be exactly the verdict and nothing else: `Approved` when
|
||||||
|
the template's answer is yes, `Changes requested` otherwise. The mark in front
|
||||||
|
of it is added when posting, so write the words alone; any other first line is
|
||||||
|
posted as a plain comment, which wastes the run. Minor issues alone never block,
|
||||||
|
and neither does a finding the author has answered in the comment history below
|
||||||
|
as intended or a false alarm, once the code or docs make that clear. When the
|
||||||
|
verdict is `Changes requested`, the second line names what must change in one
|
||||||
|
line, addressed to the author; the author's own agent picks the fixes up, so
|
||||||
|
never ask `@bot` to make them. For UI changes, check that the result is aligned,
|
||||||
|
clean, and pixel-perfect, and that included screenshots prove the intended
|
||||||
|
result was achieved.
|
||||||
|
|
||||||
|
The review must read at a glance: everything outside `<details>` blocks totals
|
||||||
|
under 512 bytes. Only core information stays visible: the verdict, the summary
|
||||||
|
line, and the section headings. Anything verbose goes into a `<details>` block
|
||||||
|
whose `<summary>` is a few words, such as the `file:line` and title of an issue
|
||||||
|
with the what, why, and how inside; the same for each strength, each
|
||||||
|
recommendation, the reasoning, and any compliance notes. Details blocks are
|
||||||
|
top-level, never inside a list item, because Gitea breaks them there.
|
||||||
|
|
||||||
For an `issue_comment` or `pull_request_review_comment` event, treat the `body`
|
For an `issue_comment` or `pull_request_review_comment` event, treat the `body`
|
||||||
in the triggering comment payload below as the user's exact instruction.
|
in the triggering comment payload below as the user's exact instruction.
|
||||||
|
|||||||
@@ -20,6 +20,13 @@ const EVENT = env("EVENT_NAME");
|
|||||||
const AUTHOR_TOKEN = env("GITEA_TOKEN");
|
const AUTHOR_TOKEN = env("GITEA_TOKEN");
|
||||||
const REVIEWER_TOKEN = env("REVIEWER_TOKEN");
|
const REVIEWER_TOKEN = env("REVIEWER_TOKEN");
|
||||||
const RULES_PATH = "repos/commons/code-rules/raw/README.md";
|
const RULES_PATH = "repos/commons/code-rules/raw/README.md";
|
||||||
|
// The mid tiers: a run follows a fixed template and the project's checks.
|
||||||
|
const DEFAULT_MODELS: Record<string, string> = {
|
||||||
|
claude: "claude-sonnet-5",
|
||||||
|
codex: "gpt-5.6-terra",
|
||||||
|
};
|
||||||
|
const model = (bot: string): string =>
|
||||||
|
Deno.env.get("MODEL") || DEFAULT_MODELS[bot];
|
||||||
|
|
||||||
// The reviewer token is withheld so the agent cannot approve as the bot.
|
// The reviewer token is withheld so the agent cannot approve as the bot.
|
||||||
const { REVIEWER_TOKEN: _, ...agentEnv } = Deno.env.toObject();
|
const { REVIEWER_TOKEN: _, ...agentEnv } = Deno.env.toObject();
|
||||||
@@ -52,32 +59,56 @@ async function postComment(body: string): Promise<void> {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
// A pull request event is a review request, so the response becomes a review:
|
// A pull request event is a review request, so the review is posted instead
|
||||||
// changes are requested when the agent asked @bot to fix something, a failed
|
// of the response. It comes through a file, because a final chat message picks
|
||||||
// run only comments, and anything else approves.
|
// up narration while a file's first line is written on purpose. That line is
|
||||||
|
// the verdict, matched whole; anything unexpected only comments, never
|
||||||
|
// approves. The mark in front is added here, so it is never part of the match.
|
||||||
|
const REVIEW_PATH = `${await Deno.makeTempDir()}/review.md`;
|
||||||
|
const VERDICTS: Record<string, [event: string, mark: string]> = {
|
||||||
|
Approved: ["APPROVED", "✅"],
|
||||||
|
"Changes requested": ["REQUEST_CHANGES", "🛑"],
|
||||||
|
};
|
||||||
|
|
||||||
async function postResult(body: string): Promise<void> {
|
async function postResult(body: string): Promise<void> {
|
||||||
if (EVENT !== "pull_request") return postComment(body);
|
if (EVENT !== "pull_request") return postComment(body);
|
||||||
const event = body.includes("@bot")
|
const review = await Deno.readTextFile(REVIEW_PATH).catch(() => {
|
||||||
? "REQUEST_CHANGES"
|
throw new Error(`no review was written to ${REVIEW_PATH}`);
|
||||||
: body.startsWith("Bot failed:")
|
});
|
||||||
? "COMMENT"
|
const [verdict, ...rest] = review.split("\n");
|
||||||
: "APPROVED";
|
const [event, mark] = VERDICTS[verdict.trim()] ?? ["COMMENT", "💬"];
|
||||||
await gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
|
await gitea(REVIEWER_TOKEN, `repos/${REPO}/pulls/${INDEX}/reviews`, {
|
||||||
body: stripAnsi(body),
|
body: stripAnsi([`${mark} ${verdict.trim()}`, ...rest].join("\n")),
|
||||||
event,
|
event,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
async function run(command: string, args: string[]): Promise<void> {
|
||||||
|
const { success, code } = await new Deno.Command(command, { args }).output();
|
||||||
|
if (!success) throw new Error(`${command} ${args[0]} exited with ${code}`);
|
||||||
|
}
|
||||||
|
|
||||||
// Commits belong to the same account as the pull request they end up in.
|
// Commits belong to the same account as the pull request they end up in.
|
||||||
async function configureGitAuthor(): Promise<void> {
|
async function configureGitAuthor(): Promise<void> {
|
||||||
const user: GiteaUser = await (await gitea(AUTHOR_TOKEN, "user")).json();
|
const user: GiteaUser = await (await gitea(AUTHOR_TOKEN, "user")).json();
|
||||||
for (const [key, value] of [["name", user.login], ["email", user.email]]) {
|
for (const [key, value] of [["name", user.login], ["email", user.email]]) {
|
||||||
await new Deno.Command("git", {
|
await run("git", ["config", "--global", `user.${key}`, value]);
|
||||||
args: ["config", "--global", `user.${key}`, value],
|
|
||||||
}).output();
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// The superpowers plugin gives the agent its skills, including the code review
|
||||||
|
// one that the prompt asks for. Both installs are idempotent on the persisted
|
||||||
|
// home.
|
||||||
|
async function installSuperpowers(bot: string): Promise<void> {
|
||||||
|
const commands = bot === "claude"
|
||||||
|
? [
|
||||||
|
["plugin", "marketplace", "add", "obra/superpowers-marketplace"],
|
||||||
|
["plugin", "install", "-y", "superpowers@superpowers-marketplace"],
|
||||||
|
]
|
||||||
|
: [["plugin", "add", "superpowers@openai-curated-remote"]];
|
||||||
|
for (const args of commands) await run(bot, args);
|
||||||
|
}
|
||||||
|
|
||||||
async function renderPrompt(): Promise<string> {
|
async function renderPrompt(): Promise<string> {
|
||||||
const comments: GiteaComment[] = await (await gitea(
|
const comments: GiteaComment[] = await (await gitea(
|
||||||
REVIEWER_TOKEN,
|
REVIEWER_TOKEN,
|
||||||
@@ -93,6 +124,7 @@ async function renderPrompt(): Promise<string> {
|
|||||||
GITEA_API_URL: API,
|
GITEA_API_URL: API,
|
||||||
GITEA_REPOSITORY: REPO,
|
GITEA_REPOSITORY: REPO,
|
||||||
ISSUE_INDEX: INDEX,
|
ISSUE_INDEX: INDEX,
|
||||||
|
REVIEW_PATH,
|
||||||
};
|
};
|
||||||
const template = await Deno.readTextFile(
|
const template = await Deno.readTextFile(
|
||||||
new URL("prompt.md", import.meta.url),
|
new URL("prompt.md", import.meta.url),
|
||||||
@@ -106,17 +138,17 @@ async function renderPrompt(): Promise<string> {
|
|||||||
async function runClaude(prompt: string): Promise<string> {
|
async function runClaude(prompt: string): Promise<string> {
|
||||||
const token = Deno.env.get("BOT_TOKEN");
|
const token = Deno.env.get("BOT_TOKEN");
|
||||||
if (!token) {
|
if (!token) {
|
||||||
await postComment(
|
throw new Error(
|
||||||
"Run `claude setup-token` locally and set the `bot-token` action input.",
|
"Run `claude setup-token` locally and set the `bot-token` action input.",
|
||||||
);
|
);
|
||||||
Deno.exit(1);
|
|
||||||
}
|
}
|
||||||
|
await installSuperpowers("claude");
|
||||||
const claude = new Deno.Command("claude", {
|
const claude = new Deno.Command("claude", {
|
||||||
args: [
|
args: [
|
||||||
"--print",
|
"--print",
|
||||||
"--dangerously-skip-permissions",
|
"--dangerously-skip-permissions",
|
||||||
"--model",
|
"--model",
|
||||||
"claude-fable-5",
|
model("claude"),
|
||||||
"--output-format",
|
"--output-format",
|
||||||
"stream-json",
|
"stream-json",
|
||||||
"--verbose",
|
"--verbose",
|
||||||
@@ -127,7 +159,7 @@ async function runClaude(prompt: string): Promise<string> {
|
|||||||
clearEnv: true,
|
clearEnv: true,
|
||||||
stdout: "piped",
|
stdout: "piped",
|
||||||
}).spawn();
|
}).spawn();
|
||||||
let result = "Bot failed: no result";
|
let result: { result?: string; subtype: string } | undefined;
|
||||||
// Print events as they stream so the runner does not kill the job as a zombie.
|
// Print events as they stream so the runner does not kill the job as a zombie.
|
||||||
const lines = claude.stdout
|
const lines = claude.stdout
|
||||||
.pipeThrough(new TextDecoderStream())
|
.pipeThrough(new TextDecoderStream())
|
||||||
@@ -139,12 +171,13 @@ async function runClaude(prompt: string): Promise<string> {
|
|||||||
const text = part.thinking ?? part.text ?? part.name;
|
const text = part.thinking ?? part.text ?? part.name;
|
||||||
if (text) console.log(text);
|
if (text) console.log(text);
|
||||||
}
|
}
|
||||||
if (event.type === "result") {
|
if (event.type === "result") result = event;
|
||||||
result = event.result ?? `Bot failed: ${event.subtype}`;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
await claude.status;
|
await claude.status;
|
||||||
return result;
|
if (result?.result === undefined) {
|
||||||
|
throw new Error(`claude ended with ${result?.subtype ?? "no result"}`);
|
||||||
|
}
|
||||||
|
return result.result;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Posts the device code so a human can finish the login on the persisted home.
|
// Posts the device code so a human can finish the login on the persisted home.
|
||||||
@@ -174,12 +207,13 @@ async function runCodex(prompt: string): Promise<string> {
|
|||||||
})
|
})
|
||||||
.output();
|
.output();
|
||||||
if (!loggedIn.success) await codexDeviceLogin();
|
if (!loggedIn.success) await codexDeviceLogin();
|
||||||
|
await installSuperpowers("codex");
|
||||||
const file = await Deno.makeTempFile();
|
const file = await Deno.makeTempFile();
|
||||||
const status = await new Deno.Command("codex", {
|
const status = await new Deno.Command("codex", {
|
||||||
args: [
|
args: [
|
||||||
"exec",
|
"exec",
|
||||||
"--model",
|
"--model",
|
||||||
"gpt-5.5",
|
model("codex"),
|
||||||
"--dangerously-bypass-approvals-and-sandbox",
|
"--dangerously-bypass-approvals-and-sandbox",
|
||||||
"--output-last-message",
|
"--output-last-message",
|
||||||
file,
|
file,
|
||||||
@@ -194,9 +228,14 @@ async function runCodex(prompt: string): Promise<string> {
|
|||||||
return await Deno.readTextFile(file);
|
return await Deno.readTextFile(file);
|
||||||
}
|
}
|
||||||
|
|
||||||
await configureGitAuthor();
|
try {
|
||||||
const prompt = await renderPrompt();
|
await configureGitAuthor();
|
||||||
const result = env("BOT_TYPE") === "claude"
|
const prompt = await renderPrompt();
|
||||||
? await runClaude(prompt)
|
const result = env("BOT_TYPE") === "claude"
|
||||||
: await runCodex(prompt);
|
? await runClaude(prompt)
|
||||||
await postResult(result);
|
: await runCodex(prompt);
|
||||||
|
await postResult(result);
|
||||||
|
} catch (error) {
|
||||||
|
await postComment(`Bot failed: ${error}`);
|
||||||
|
throw error;
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user