shoc-pr-review-runner/review/runner-config.yml
Adam Moussa c3cd8f7765
feat: SHOC PR review runner, phase 1
Manually-dispatched GitHub Actions workflow that reviews SHOC pull requests in
a clean environment: exact-head checkout of shoc-frontend-new and shoc-backend,
clean build/test gates, a truthful evidence report, a single-shot Fireworks
review, deterministic output validation, and published artifacts. The runner
never writes to the product repositories or their pull requests.

The review checklists move here from the reviewers' local Cursor commands so
the instructions live outside both product repos.

Phase 1 does not provision a database, start either application, or run live
browser flows; the evidence report records those as NOT_RUN so a review cannot
claim them.

Security architecture: building a PR executes its author's code, so the
workflow is split. The gates job runs that code holding no Fireworks key and
revokes its App token first; the review job holds the key, executes no product
code, and re-checks out this repo fresh. Product checkouts live outside the
workspace, the App token is downscoped at mint time, gate results fail closed
on any duplicate key, changed files are read from git objects rather than the
filesystem, and the validator re-checks every claim against the gate table.
2026-07-29 12:05:38 -04:00

57 lines
2.8 KiB
YAML

# SHOC PR Review Runner configuration record (spec §23).
#
# This file is the human-readable source of truth for the values the workflow
# and scripts use. The workflow's env block mirrors these values; if you change
# one here, change it there in the same PR (CI cross-checks the pair).
# Values were verified against the real repositories on 2026-07-29.
repositories:
frontend:
name: Sea-Haven-Industries/shoc-frontend-new
path: workspace/frontend
default_branch: dev # dev is the live integration branch
node_version: "24" # repo has no .nvmrc; engines >=22.22.1, CI uses 24
install_command: npm ci # HUSKY=0 (prepare: husky runs on install)
lint_command: npm run lint
build_command: npm run build # tsc -b && vite build (no separate typecheck script)
test_command: npm test # vitest run
e2e_mocked_command: npm run test:e2e # Playwright, fully page.route-mocked
build_env:
VITE_API_URL: /api # must end in /api (build-time contract guard);
# committed .env.production would otherwise bake
# the deployed dev API URL into the bundle
port: 3000 # dev server; Playwright drives its own on 4173
backend:
name: Sea-Haven-Industries/shoc-backend
path: workspace/backend
default_branch: dev
dotnet_version: 8.0.x # no global.json; matches repo CI
solution: SeaHavenIndustries.sln
startup_project: Api.SeaHavenIndustries/Api.SeaHavenIndustries.csproj # Phase 2
restore_command: dotnet restore SeaHavenIndustries.sln
build_command: dotnet build SeaHavenIndustries.sln --configuration Release --no-restore
test_command: dotnet test SeaHavenIndustries.sln --configuration Release --no-build
port: 5141 # Phase 2: launchSettings http profile
health_path: /swagger/v1/swagger.json # Phase 2: no anonymous /health exists;
# requires ASPNETCORE_ENVIRONMENT=Development
database: # Phase 2 (not provisioned by Phase 1)
engine: sqlserver # spec draft said postgres; the backend is EF Core
image: mcr.microsoft.com/mssql/server:2022-latest # + SqlServer — corrected
port: 1433
agent:
provider: fireworks
base_url: https://api.fireworks.ai/inference/v1
default_model: deepseek-v4-pro
allowed_models: [deepseek-v4-pro, kimi-k2p6] # enforced by the workflow choice input
diff_max_bytes: 200000
files_max_bytes: 120000
file_max_bytes: 65536
review:
artifact_retention_days: 30
companion_branch: dev # single-repo reviews check out the companion here
require_live_browser_for_frontend_approval: false # Phase 3 flips this
allow_mocked_suite_as_live_evidence: false