File
Blob: .github/workflows/new-pr-review.yml
| 1 | name: New PR Review |
| 2 | |
| 3 | on: |
| 4 | pull_request: |
| 5 | types: [opened] |
| 6 | |
| 7 | jobs: |
| 8 | review: |
| 9 | if: github.event.pull_request.head.repo.full_name == github.event.pull_request.base.repo.full_name |
| 10 | runs-on: ubuntu-latest |
| 11 | timeout-minutes: 30 |
| 12 | concurrency: |
| 13 | group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} |
| 14 | cancel-in-progress: false |
| 15 | permissions: |
| 16 | id-token: write |
| 17 | contents: read |
| 18 | issues: write |
| 19 | pull-requests: write |
| 20 | steps: |
| 21 | - name: Checkout repository |
| 22 | uses: actions/checkout@v6 |
| 23 | with: |
| 24 | fetch-depth: 30 # Fetch some history; not all of it |
| 25 | |
| 26 | - name: Load review prompt |
| 27 | id: prompt |
| 28 | run: | |
| 29 | { |
| 30 | echo 'value<<EOF' |
| 31 | echo "You are reviewing PR #${{ github.event.pull_request.number }} on ${{ github.repository }}." |
| 32 | echo "" |
| 33 | cat .github/bonk_reviewer.md |
| 34 | echo EOF |
| 35 | } >> "$GITHUB_OUTPUT" |
| 36 | |
| 37 | - name: Run Bonk |
| 38 | uses: ask-bonk/ask-bonk/github@main |
| 39 | env: |
| 40 | CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CF_AI_GATEWAY_ACCOUNT_ID }} |
| 41 | CLOUDFLARE_GATEWAY_ID: ${{ secrets.CF_AI_GATEWAY_NAME }} |
| 42 | CLOUDFLARE_API_TOKEN: ${{ secrets.CF_AI_GATEWAY_TOKEN }} |
| 43 | with: |
| 44 | model: 'cloudflare-ai-gateway/anthropic/claude-opus-4-6' |
| 45 | forks: 'false' |
| 46 | permissions: write |
| 47 | opencode_version: "1.14.33" |
| 48 | # The auto-reviewer must never push to PR branches. Its prompt |
| 49 | # (bonk_reviewer.md) already forbids git write ops, but NO_PUSH |
| 50 | # enforces that at the token level so it holds even if the model |
| 51 | # ignores the instruction. |
| 52 | token_permissions: 'NO_PUSH' |
| 53 | prompt: ${{ steps.prompt.outputs.value }} |