mirror of
https://github.com/Sea-Haven-Industries/shoc-pr-review-runner.git
synced 2026-09-30 07:13:14 +00:00
Manually-dispatched GitHub Actions workflow that reviews SHOC pull requests in a clean environment: exact-head checkout of shoc-frontend-new and shoc-backend, clean build/test gates, a truthful evidence report, a single-shot Fireworks review, deterministic output validation, and published artifacts. The runner never writes to the product repositories or their pull requests. The review checklists move here from the reviewers' local Cursor commands so the instructions live outside both product repos. Phase 1 does not provision a database, start either application, or run live browser flows; the evidence report records those as NOT_RUN so a review cannot claim them. Security architecture: building a PR executes its author's code, so the workflow is split. The gates job runs that code holding no Fireworks key and revokes its App token first; the review job holds the key, executes no product code, and re-checks out this repo fresh. Product checkouts live outside the workspace, the App token is downscoped at mint time, gate results fail closed on any duplicate key, changed files are read from git objects rather than the filesystem, and the validator re-checks every claim against the gate table.
57 lines
2.8 KiB
YAML
57 lines
2.8 KiB
YAML
# SHOC PR Review Runner configuration record (spec §23).
|
|
#
|
|
# This file is the human-readable source of truth for the values the workflow
|
|
# and scripts use. The workflow's env block mirrors these values; if you change
|
|
# one here, change it there in the same PR (CI cross-checks the pair).
|
|
# Values were verified against the real repositories on 2026-07-29.
|
|
|
|
repositories:
|
|
frontend:
|
|
name: Sea-Haven-Industries/shoc-frontend-new
|
|
path: workspace/frontend
|
|
default_branch: dev # dev is the live integration branch
|
|
node_version: "24" # repo has no .nvmrc; engines >=22.22.1, CI uses 24
|
|
install_command: npm ci # HUSKY=0 (prepare: husky runs on install)
|
|
lint_command: npm run lint
|
|
build_command: npm run build # tsc -b && vite build (no separate typecheck script)
|
|
test_command: npm test # vitest run
|
|
e2e_mocked_command: npm run test:e2e # Playwright, fully page.route-mocked
|
|
build_env:
|
|
VITE_API_URL: /api # must end in /api (build-time contract guard);
|
|
# committed .env.production would otherwise bake
|
|
# the deployed dev API URL into the bundle
|
|
port: 3000 # dev server; Playwright drives its own on 4173
|
|
|
|
backend:
|
|
name: Sea-Haven-Industries/shoc-backend
|
|
path: workspace/backend
|
|
default_branch: dev
|
|
dotnet_version: 8.0.x # no global.json; matches repo CI
|
|
solution: SeaHavenIndustries.sln
|
|
startup_project: Api.SeaHavenIndustries/Api.SeaHavenIndustries.csproj # Phase 2
|
|
restore_command: dotnet restore SeaHavenIndustries.sln
|
|
build_command: dotnet build SeaHavenIndustries.sln --configuration Release --no-restore
|
|
test_command: dotnet test SeaHavenIndustries.sln --configuration Release --no-build
|
|
port: 5141 # Phase 2: launchSettings http profile
|
|
health_path: /swagger/v1/swagger.json # Phase 2: no anonymous /health exists;
|
|
# requires ASPNETCORE_ENVIRONMENT=Development
|
|
|
|
database: # Phase 2 (not provisioned by Phase 1)
|
|
engine: sqlserver # spec draft said postgres; the backend is EF Core
|
|
image: mcr.microsoft.com/mssql/server:2022-latest # + SqlServer — corrected
|
|
port: 1433
|
|
|
|
agent:
|
|
provider: fireworks
|
|
base_url: https://api.fireworks.ai/inference/v1
|
|
default_model: deepseek-v4-pro
|
|
allowed_models: [deepseek-v4-pro, kimi-k2p6] # enforced by the workflow choice input
|
|
diff_max_bytes: 200000
|
|
files_max_bytes: 120000
|
|
file_max_bytes: 65536
|
|
|
|
review:
|
|
artifact_retention_days: 30
|
|
companion_branch: dev # single-repo reviews check out the companion here
|
|
require_live_browser_for_frontend_approval: false # Phase 3 flips this
|
|
allow_mocked_suite_as_live_evidence: false
|