Skip to content

ci(opencode): make the reviewer read-only - #4

Merged
JustMarkDev merged 6 commits into
mainfrom
ci/opencode-v2
Oct 5, 2026
Merged

JustMarkDev merged 6 commits into
mainfrom
ci/opencode-v2

Conversation

@JustMarkDev

@JustMarkDev JustMarkDev commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

What

Keep the official v1 anomalyco/opencode/github action (opencode v2 has no github command and no official action) and make the reviewer read-only. Reviews and /oc replies keep posting as the opencode app (opencode-agent).

  • contents: write → contents: read on the job token.
  • /oc chat uses the built-in read-only plan agent (PR reviews keep the review agent and its suggestion blocks), so neither edits code.
  • variant: xhigh on muse-spark-1.3-contributor; actions: read so the reviewer can read CI results.
  • Note: the app token from the OIDC exchange gets its permissions from the opencode GitHub app, not from the workflow, so read-only is enforced by the agents, not by the token.

Test plan

  • This PR's own opencode job posts a review as opencode-agent
  • Inline /oc write request is refused with a suggested diff

🤖 Generated with Claude Code

The anomalyco/opencode/github action installs the latest GitHub release, which
is still v1, and runs `opencode github run`, a command v2 does not have. Install
v2 with the official v2 installer and call `opencode run --standalone --auto`
directly: the review agent for PRs, the default agent for /oc comments, on
muse-spark-1.3-contributor at xhigh. Post the final message as the PR comment,
fail on errors, and grant actions: read.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Comment thread .github/workflows/opencode.yml Outdated
Comment thread .github/workflows/opencode.yml Outdated
@github-actions

This comment has been minimized.

…inline context

Review findings on the v2 workflow: an empty reply left the job green with no
review; an error event aborted the step before the partial reply was posted; and
inline /oc comments lost their file, line and diff hunk.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Comment thread .github/workflows/opencode.yml Outdated
@github-actions

This comment has been minimized.

Capture the exit status instead of letting errexit abort the step, always post
the last reply if there is one, then fail the job on a non-zero exit, an error
event or an empty reply.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

Drop contents: write to contents: read so no run can push code, and run /oc
comments with the built-in read-only plan agent instead of the default build
agent. The reviewer suggests fixes (including suggestion blocks); the user's own
agent applies them.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@github-actions

This comment has been minimized.

opencode v2 has no `github` command and no official action, so the hand-built v2
workflow is replaced by main's v1 action plus the hardening: contents: read,
use_github_token (with checkout credentials kept so the action can fetch the PR
branch) so the app-token exchange cannot bypass it, the read-only plan agent for
/oc chat, variant xhigh and actions: read.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@JustMarkDev JustMarkDev changed the title ci(opencode): run the PR reviewer on opencode v2 ci(opencode): make the reviewer read-only Oct 4, 2026
@github-actions

This comment has been minimized.

use_github_token made comments post as github-actions[bot]. Restore the opencode
app-token exchange (id-token: write, checkout credentials off) so reviews post
as opencode-agent again. Read-only is enforced by the review and plan agents and
contents: read; the app token's own permissions are set by the opencode app.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@opencode-agent

opencode-agent Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review · 54a9f42

✅ No blocking issues

This PR reverts to the official v1 anomalyco/opencode/github action and makes the reviewer read-only (contents: read, plan agent for /oc). The biggest residual risk is the floating @latest/@main pins, which let upstream drift change behavior.

Confidence: 4/5 — All three prior threads stay resolved and the read-only delta is tight, but head CI is still running (latest completed CI on the branch succeeded).

@JustMarkDev
JustMarkDev merged commit f19ca2a into main Oct 5, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant