shoc-pr-review-runner/.github/workflows/ci.yaml
Adam Moussa c3cd8f7765
feat: SHOC PR review runner, phase 1
Manually-dispatched GitHub Actions workflow that reviews SHOC pull requests in
a clean environment: exact-head checkout of shoc-frontend-new and shoc-backend,
clean build/test gates, a truthful evidence report, a single-shot Fireworks
review, deterministic output validation, and published artifacts. The runner
never writes to the product repositories or their pull requests.

The review checklists move here from the reviewers' local Cursor commands so
the instructions live outside both product repos.

Phase 1 does not provision a database, start either application, or run live
browser flows; the evidence report records those as NOT_RUN so a review cannot
claim them.

Security architecture: building a PR executes its author's code, so the
workflow is split. The gates job runs that code holding no Fireworks key and
revokes its App token first; the review job holds the key, executes no product
code, and re-checks out this repo fresh. Product checkouts live outside the
workspace, the App token is downscoped at mint time, gate results fail closed
on any duplicate key, changed files are read from git objects rather than the
filesystem, and the validator re-checks every claim against the gate table.
2026-07-29 12:05:38 -04:00

60 lines
2.2 KiB
YAML

name: ci
# Repo-local CI for the runner itself. No org reusable fits a bash/workflow
# tooling repo, so this thin workflow lints every script and workflow, validates
# the input schema, and runs the bash test suite. The job is named `ci` so the
# required status context is `ci / ci`, matching the org ruleset convention.
on:
pull_request:
branches: [main]
permissions:
contents: read
jobs:
ci:
runs-on: ubuntu-latest
timeout-minutes: 15
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: shellcheck all scripts
run: |
shopt -s nullglob
files=(scripts/*.sh tests/*.sh)
echo "checking: ${files[*]}"
shellcheck --external-sources --source-path=scripts "${files[@]}"
- name: actionlint all workflows
run: |
curl -sSfL -o actionlint.tar.gz \
https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz
echo "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 actionlint.tar.gz" | sha256sum -c -
tar -xzf actionlint.tar.gz actionlint
./actionlint -color
- name: validate input schema + fixtures
run: |
# Pinned: the same integrity bar the actionlint download above meets.
python3 -m pip install --quiet 'check-jsonschema==0.37.4'
check-jsonschema --check-metaschema review/schemas/review-input.schema.json
for f in tests/fixtures/inputs/valid-*.json; do
check-jsonschema --schemafile review/schemas/review-input.schema.json "$f"
done
for f in tests/fixtures/inputs/invalid-*.json; do
if check-jsonschema --schemafile review/schemas/review-input.schema.json "$f" 2>/dev/null; then
echo "expected $f to FAIL schema validation" >&2; exit 1
fi
done
- name: bash tests
run: |
./tests/test-input-validation.sh
./tests/test-output-validation.sh
./tests/test-gate-integrity.sh