From fb84d82c8467553198b72869624b8b91fe97d358 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 7 Aug 2026 11:41:16 +0000 Subject: [PATCH] =?UTF-8?q?=F0=9F=A4=96=20ci:=20add=20a=20Junie=20code=20r?= =?UTF-8?q?eview=20workflow?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Runs JetBrains' Junie agent on every PR into main or develop, using the action's built-in `code-review` prompt rather than a free-form instruction. Details worth keeping: - `use_single_comment` plus a `concurrency` group keyed on the PR number, so a burst of pushes leaves one review of the final state rather than a queue of reviews of intermediate ones. - Skipped explicitly on fork PRs. `pull_request` does not expose secrets to them, so the job would otherwise fail on an empty API key — a skipped job reads as "not applicable", a failed one as "broken". - `contents: read`. This workflow reviews; it does not push. - Not a required check, on purpose. CI gates merges; a review that can block one on a judgement call is a review that gets rubber-stamped. Needs a JUNIE_API_KEY repository secret before it will do anything but fail. Pinned to @v1, whose action.yml declares each of the three inputs used here. actionlint clean across all three workflows. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK --- .github/workflows/junie-review.yml | 48 ++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 .github/workflows/junie-review.yml diff --git a/.github/workflows/junie-review.yml b/.github/workflows/junie-review.yml new file mode 100644 index 0000000..382fbcc --- /dev/null +++ b/.github/workflows/junie-review.yml @@ -0,0 +1,48 @@ +name: Junie Review + +# Automated PR review by Junie, JetBrains' coding agent. Advisory only: it posts a +# summary and inline comments, and is deliberately not a required check — CI is what +# gates a merge, and a review that can block one on a judgement call is a review that +# gets rubber-stamped. +# +# Requires a JUNIE_API_KEY repository secret (Settings → Secrets and variables → +# Actions). Without it the action fails at the first step rather than skipping, so +# add the secret before merging this file. + +on: + pull_request: + types: [ opened, synchronize, reopened ] + branches: [ main, develop ] + +# A PR that gets three pushes in a minute should end up with one review of the final +# state, not three reviews of intermediate ones. Combined with use_single_comment +# below, each PR keeps exactly one review comment, rewritten as the diff changes. +concurrency: + group: junie-review-${{ github.event.pull_request.number }} + cancel-in-progress: true + +jobs: + review: + name: Junie + runs-on: ubuntu-latest + + # Secrets are not exposed to `pull_request` runs originating from a fork, so a + # fork PR would fail on an empty API key rather than review anything. Skip those + # explicitly — a skipped job reads as "not applicable", a failed one as "broken". + if: github.event.pull_request.head.repo.full_name == github.repository + + permissions: + contents: read # read the diff; Junie does not push from this workflow + pull-requests: write # post the review summary and inline comments + issues: write # the PR conversation is an issue timeline to the API + + steps: + - uses: actions/checkout@v4 + - name: Review the pull request + uses: JetBrains/junie-github-action@v1 + with: + junie_api_key: ${{ secrets.JUNIE_API_KEY }} + # Built-in structured review prompt, as opposed to a free-form instruction. + prompt: "code-review" + # Update one comment across re-runs instead of appending a new one per push. + use_single_comment: "true"