Have Junie review each pull request

CI says whether the code works. Nothing says whether it reads well, and the
one review this repository has had so far arrived by hand.

Kept as a separate workflow rather than a third job in ci.yml so a review can
never turn the build red — the two answer different questions and should be
able to disagree.

It skips drafts, and skips pull requests from forks: GitHub withholds secrets
from `pull_request` runs on a forked head, so the job would fail on a missing
JUNIE_API_KEY rather than say anything about the code. Each push supersedes
the previous review rather than stacking another comment beside it.

Requires a JUNIE_API_KEY repository secret, generated at
junie.jetbrains.com/cli. Without it the workflow is inert.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WaySiNst4HhDXBHnMy8p5G
This commit is contained in:
Claude
2026-08-07 11:31:53 +00:00
parent b14ce78c5f
commit ddf805e61f
+49
View File
@@ -0,0 +1,49 @@
name: Junie review
# JetBrains' Junie agent reads each pull request and leaves inline review comments. It runs
# alongside CI rather than as part of it: CI answers whether the code works, this answers whether
# it reads well, and a review comment should never be able to turn the build red.
on:
pull_request:
types: [opened, synchronize, ready_for_review]
# A review of the previous push is stale the moment a new one lands, so supersede it rather than
# letting two reviews comment on the same pull request. Keyed by pull request rather than by ref
# so a push to `main` never cancels a review.
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
cancel-in-progress: true
# Read the code, write the review. `issues: write` is what posts the summary comment — GitHub
# treats a pull request's conversation timeline as an issue.
permissions:
contents: read
pull-requests: write
issues: write
jobs:
review:
name: Review the diff
runs-on: ubuntu-latest
# Drafts are work in progress and forks cannot see `JUNIE_API_KEY` — GitHub withholds secrets
# from `pull_request` runs on forked branches, so the job would fail on a missing key rather
# than say anything useful about the code.
if: >-
github.event.pull_request.draft == false &&
github.event.pull_request.head.repo.full_name == github.repository
steps:
- uses: actions/checkout@v5
with:
# Junie reads the diff through the GitHub API, so the full history it would otherwise
# clone is never used.
fetch-depth: 1
- uses: JetBrains/junie-github-action@v1
with:
junie_api_key: ${{ secrets.JUNIE_API_KEY }}
# The action's built-in review prompt. Replace with a prompt block to review against
# criteria of our own.
prompt: code-review
# Rewrite one comment on each push instead of stacking a new one per revision, so the
# conversation shows the current state of the review rather than its history.
use_single_comment: "true"