Files
cereale/.github/workflows/junie-review.yml
T
Claude fb84d82c84 🤖 ci: add a Junie code review workflow
Runs JetBrains' Junie agent on every PR into main or develop, using the
action's built-in `code-review` prompt rather than a free-form instruction.

Details worth keeping:

- `use_single_comment` plus a `concurrency` group keyed on the PR number, so a
  burst of pushes leaves one review of the final state rather than a queue of
  reviews of intermediate ones.
- Skipped explicitly on fork PRs. `pull_request` does not expose secrets to
  them, so the job would otherwise fail on an empty API key — a skipped job
  reads as "not applicable", a failed one as "broken".
- `contents: read`. This workflow reviews; it does not push.
- Not a required check, on purpose. CI gates merges; a review that can block
  one on a judgement call is a review that gets rubber-stamped.

Needs a JUNIE_API_KEY repository secret before it will do anything but fail.
Pinned to @v1, whose action.yml declares each of the three inputs used here.
actionlint clean across all three workflows.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK
2026-08-07 11:41:16 +00:00

49 lines
2.0 KiB
YAML

name: Junie Review
# Automated PR review by Junie, JetBrains' coding agent. Advisory only: it posts a
# summary and inline comments, and is deliberately not a required check — CI is what
# gates a merge, and a review that can block one on a judgement call is a review that
# gets rubber-stamped.
#
# Requires a JUNIE_API_KEY repository secret (Settings → Secrets and variables →
# Actions). Without it the action fails at the first step rather than skipping, so
# add the secret before merging this file.
on:
pull_request:
types: [ opened, synchronize, reopened ]
branches: [ main, develop ]
# A PR that gets three pushes in a minute should end up with one review of the final
# state, not three reviews of intermediate ones. Combined with use_single_comment
# below, each PR keeps exactly one review comment, rewritten as the diff changes.
concurrency:
group: junie-review-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
review:
name: Junie
runs-on: ubuntu-latest
# Secrets are not exposed to `pull_request` runs originating from a fork, so a
# fork PR would fail on an empty API key rather than review anything. Skip those
# explicitly — a skipped job reads as "not applicable", a failed one as "broken".
if: github.event.pull_request.head.repo.full_name == github.repository
permissions:
contents: read # read the diff; Junie does not push from this workflow
pull-requests: write # post the review summary and inline comments
issues: write # the PR conversation is an issue timeline to the API
steps:
- uses: actions/checkout@v4
- name: Review the pull request
uses: JetBrains/junie-github-action@v1
with:
junie_api_key: ${{ secrets.JUNIE_API_KEY }}
# Built-in structured review prompt, as opposed to a free-form instruction.
prompt: "code-review"
# Update one comment across re-runs instead of appending a new one per push.
use_single_comment: "true"