Repository navigation
ci(opencode): make the reviewer read-only - #4
Merged
Merged
Conversation
The anomalyco/opencode/github action installs the latest GitHub release, which is still v1, and runs `opencode github run`, a command v2 does not have. Install v2 with the official v2 installer and call `opencode run --standalone --auto` directly: the review agent for PRs, the default agent for /oc comments, on muse-spark-1.3-contributor at xhigh. Post the final message as the PR comment, fail on errors, and grant actions: read. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This comment has been minimized.
This comment has been minimized.
…inline context Review findings on the v2 workflow: an empty reply left the job green with no review; an error event aborted the step before the partial reply was posted; and inline /oc comments lost their file, line and diff hunk. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This comment has been minimized.
This comment has been minimized.
Capture the exit status instead of letting errexit abort the step, always post the last reply if there is one, then fail the job on a non-zero exit, an error event or an empty reply. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This comment has been minimized.
This comment has been minimized.
Drop contents: write to contents: read so no run can push code, and run /oc comments with the built-in read-only plan agent instead of the default build agent. The reviewer suggests fixes (including suggestion blocks); the user's own agent applies them. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This comment has been minimized.
This comment has been minimized.
opencode v2 has no `github` command and no official action, so the hand-built v2 workflow is replaced by main's v1 action plus the hardening: contents: read, use_github_token (with checkout credentials kept so the action can fetch the PR branch) so the app-token exchange cannot bypass it, the read-only plan agent for /oc chat, variant xhigh and actions: read. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This comment has been minimized.
This comment has been minimized.
use_github_token made comments post as github-actions[bot]. Restore the opencode app-token exchange (id-token: write, checkout credentials off) so reviews post as opencode-agent again. Read-only is enforced by the review and plan agents and contents: read; the app token's own permissions are set by the opencode app. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Review · 54a9f42✅ No blocking issues This PR reverts to the official v1 Confidence: 4/5 — All three prior threads stay resolved and the read-only delta is tight, but head CI is still running (latest completed CI on the branch succeeded). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Keep the official v1
anomalyco/opencode/githubaction (opencode v2 has nogithubcommand and no official action) and make the reviewer read-only. Reviews and/ocreplies keep posting as the opencode app (opencode-agent).contents: write→contents: readon the job token./occhat uses the built-in read-onlyplanagent (PR reviews keep thereviewagent and its suggestion blocks), so neither edits code.variant: xhighonmuse-spark-1.3-contributor;actions: readso the reviewer can read CI results.Test plan
opencodejob posts a review asopencode-agent/ocwrite request is refused with a suggested diff🤖 Generated with Claude Code