Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .github/project.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,3 +29,8 @@ pages:
deploy-at-release: true
github-automation:
auto-merge-build-versions: true

cuioss-review-bot:
enabled: true
packs: [java]
additional_rules: []
58 changes: 58 additions & 0 deletions .github/workflows/cuioss-review-bot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
# Example: cuioss-review-bot review workflow (third automated reviewer — PR-Agent on Google Gemini)
# Copy this file to .github/workflows/cuioss-review-bot.yml in your repository.
#
# Adoption is opt-in: a repository is reviewed only once this workflow exists in it.
# All tuning is central — cuioss/cuioss-review-bot (.pr_agent.toml). Nothing is copied here.
# Pin the reusable workflow at the release that first contains it (or later).
#
# The review charter is a second, separate opt-in, declared in .github/project.yml on the
# default branch — never in this file:
#
# cuioss-review-bot:
# enabled: true # absent or false keeps the central charter
# packs: [java] # domain packs appended after the spine (not selectable)
# additional_rules: [] # repository rules appended after every pack
#
# Without `enabled: true` the review keeps the central charter. See docs/project-yml-schema.adoc.
#
# Prerequisites (organization-wide, already in place):
# - cuioss-review-bot GitHub App installed org-wide
# - org secrets REVIEW_APP_ID, REVIEW_APP_PRIVATE_KEY
# - org variables GCP_WIF_PROVIDER, GCP_REVIEW_SERVICE_ACCOUNT, GCP_PROJECT_ID
# (Vertex AI is reached keylessly, so these are variables, not secrets)
# - the skip-bot-review label present in the repository (gh label create skip-bot-review)

name: cuioss-review-bot Review

on:
pull_request:
types: [opened, reopened, ready_for_review]
# Enables the on-demand slash commands (/review, /ask, /improve, /help) as PR comments.
# This is also how a re-review is requested after pushing fixes — there is deliberately no
# automatic re-review on every push.
issue_comment:
types: [created]

permissions:
contents: read
pull-requests: write
issues: write
# Required: mints the OIDC token Workload Identity Federation exchanges for the short-lived
# GCP credentials the reviewer uses to reach Gemini on Vertex AI.
id-token: write

jobs:
review:
uses: cuioss/cuioss-organization/.github/workflows/reusable-cuioss-review-bot.yml@b2de4107d3d53a41a7edab7e2513887c309b8237 # v0.36.0
# Map only what the reviewer needs. `secrets: inherit` would hand it every caller secret
# (GPG keys, Sonatype credentials, SONAR_TOKEN, …) for no reason; these two are the whole
# requirement, because Vertex AI is reached keylessly.
secrets:
REVIEW_APP_ID: ${{ secrets.REVIEW_APP_ID }}
REVIEW_APP_PRIVATE_KEY: ${{ secrets.REVIEW_APP_PRIVATE_KEY }}
# Optional inputs (all have sensible defaults):
# with:
# auto-review: true # run /review on a new pull request
# auto-describe: false # rewrites the PR description — leave off
# auto-improve: false # duplicates CodeRabbit's suggestions — opt in per repo only
# timeout-minutes: 15
Loading