From ddf805e61f87ca71d728b1ca8b672a5bd74785c3 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 7 Aug 2026 11:31:53 +0000 Subject: [PATCH] Have Junie review each pull request MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CI says whether the code works. Nothing says whether it reads well, and the one review this repository has had so far arrived by hand. Kept as a separate workflow rather than a third job in ci.yml so a review can never turn the build red — the two answer different questions and should be able to disagree. It skips drafts, and skips pull requests from forks: GitHub withholds secrets from `pull_request` runs on a forked head, so the job would fail on a missing JUNIE_API_KEY rather than say anything about the code. Each push supersedes the previous review rather than stacking another comment beside it. Requires a JUNIE_API_KEY repository secret, generated at junie.jetbrains.com/cli. Without it the workflow is inert. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01WaySiNst4HhDXBHnMy8p5G --- .github/workflows/junie-review.yml | 49 ++++++++++++++++++++++++++++++ 1 file changed, 49 insertions(+) create mode 100644 .github/workflows/junie-review.yml diff --git a/.github/workflows/junie-review.yml b/.github/workflows/junie-review.yml new file mode 100644 index 0000000..7a659cb --- /dev/null +++ b/.github/workflows/junie-review.yml @@ -0,0 +1,49 @@ +name: Junie review + +# JetBrains' Junie agent reads each pull request and leaves inline review comments. It runs +# alongside CI rather than as part of it: CI answers whether the code works, this answers whether +# it reads well, and a review comment should never be able to turn the build red. +on: + pull_request: + types: [opened, synchronize, ready_for_review] + +# A review of the previous push is stale the moment a new one lands, so supersede it rather than +# letting two reviews comment on the same pull request. Keyed by pull request rather than by ref +# so a push to `main` never cancels a review. +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number }} + cancel-in-progress: true + +# Read the code, write the review. `issues: write` is what posts the summary comment — GitHub +# treats a pull request's conversation timeline as an issue. +permissions: + contents: read + pull-requests: write + issues: write + +jobs: + review: + name: Review the diff + runs-on: ubuntu-latest + # Drafts are work in progress and forks cannot see `JUNIE_API_KEY` — GitHub withholds secrets + # from `pull_request` runs on forked branches, so the job would fail on a missing key rather + # than say anything useful about the code. + if: >- + github.event.pull_request.draft == false && + github.event.pull_request.head.repo.full_name == github.repository + steps: + - uses: actions/checkout@v5 + with: + # Junie reads the diff through the GitHub API, so the full history it would otherwise + # clone is never used. + fetch-depth: 1 + + - uses: JetBrains/junie-github-action@v1 + with: + junie_api_key: ${{ secrets.JUNIE_API_KEY }} + # The action's built-in review prompt. Replace with a prompt block to review against + # criteria of our own. + prompt: code-review + # Rewrite one comment on each push instead of stacking a new one per revision, so the + # conversation shows the current state of the review rather than its history. + use_single_comment: "true"