🤖 ci: add a Junie code review workflow
Runs JetBrains' Junie agent on every PR into main or develop, using the action's built-in `code-review` prompt rather than a free-form instruction. Details worth keeping: - `use_single_comment` plus a `concurrency` group keyed on the PR number, so a burst of pushes leaves one review of the final state rather than a queue of reviews of intermediate ones. - Skipped explicitly on fork PRs. `pull_request` does not expose secrets to them, so the job would otherwise fail on an empty API key — a skipped job reads as "not applicable", a failed one as "broken". - `contents: read`. This workflow reviews; it does not push. - Not a required check, on purpose. CI gates merges; a review that can block one on a judgement call is a review that gets rubber-stamped. Needs a JUNIE_API_KEY repository secret before it will do anything but fail. Pinned to @v1, whose action.yml declares each of the three inputs used here. actionlint clean across all three workflows. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK
This commit is contained in:
@@ -0,0 +1,48 @@
|
||||
name: Junie Review
|
||||
|
||||
# Automated PR review by Junie, JetBrains' coding agent. Advisory only: it posts a
|
||||
# summary and inline comments, and is deliberately not a required check — CI is what
|
||||
# gates a merge, and a review that can block one on a judgement call is a review that
|
||||
# gets rubber-stamped.
|
||||
#
|
||||
# Requires a JUNIE_API_KEY repository secret (Settings → Secrets and variables →
|
||||
# Actions). Without it the action fails at the first step rather than skipping, so
|
||||
# add the secret before merging this file.
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [ opened, synchronize, reopened ]
|
||||
branches: [ main, develop ]
|
||||
|
||||
# A PR that gets three pushes in a minute should end up with one review of the final
|
||||
# state, not three reviews of intermediate ones. Combined with use_single_comment
|
||||
# below, each PR keeps exactly one review comment, rewritten as the diff changes.
|
||||
concurrency:
|
||||
group: junie-review-${{ github.event.pull_request.number }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
review:
|
||||
name: Junie
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
# Secrets are not exposed to `pull_request` runs originating from a fork, so a
|
||||
# fork PR would fail on an empty API key rather than review anything. Skip those
|
||||
# explicitly — a skipped job reads as "not applicable", a failed one as "broken".
|
||||
if: github.event.pull_request.head.repo.full_name == github.repository
|
||||
|
||||
permissions:
|
||||
contents: read # read the diff; Junie does not push from this workflow
|
||||
pull-requests: write # post the review summary and inline comments
|
||||
issues: write # the PR conversation is an issue timeline to the API
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- name: Review the pull request
|
||||
uses: JetBrains/junie-github-action@v1
|
||||
with:
|
||||
junie_api_key: ${{ secrets.JUNIE_API_KEY }}
|
||||
# Built-in structured review prompt, as opposed to a free-form instruction.
|
||||
prompt: "code-review"
|
||||
# Update one comment across re-runs instead of appending a new one per push.
|
||||
use_single_comment: "true"
|
||||
Reference in New Issue
Block a user