mirror of
https://github.com/Sea-Haven-Industries/shoc-pr-review-runner.git
synced 2026-10-04 11:22:12 +00:00
Manually-dispatched GitHub Actions workflow that reviews SHOC pull requests in a clean environment: exact-head checkout of shoc-frontend-new and shoc-backend, clean build/test gates, a truthful evidence report, a single-shot Fireworks review, deterministic output validation, and published artifacts. The runner never writes to the product repositories or their pull requests. The review checklists move here from the reviewers' local Cursor commands so the instructions live outside both product repos. Phase 1 does not provision a database, start either application, or run live browser flows; the evidence report records those as NOT_RUN so a review cannot claim them. Security architecture: building a PR executes its author's code, so the workflow is split. The gates job runs that code holding no Fireworks key and revokes its App token first; the review job holds the key, executes no product code, and re-checks out this repo fresh. Product checkouts live outside the workspace, the App token is downscoped at mint time, gate results fail closed on any duplicate key, changed files are read from git objects rather than the filesystem, and the validator re-checks every claim against the gate table.
1.2 KiB
1.2 KiB
Review Evidence
Review Request
- Review type:
- Frontend PR:
- Backend PR:
- Ticket:
- Reviewer notes:
- Workflow run:
Exact Heads
- Frontend SHA:
- Backend SHA:
- Frontend base:
- Backend base:
Governance Signals
- Frontend PR CI status: green | red | pending | missing
- Backend PR CI status: green | red | pending | missing
- Frontend PR mergeable:
- Backend PR mergeable:
Stack Status
- Frontend parent:
- Backend parent:
- Base integrity:
Backend Gates
- Restore:
- Release build:
- Tests:
- Migration list:
- Migration script:
- Migration apply:
- Startup:
- Health endpoint:
- API runtime scenarios:
Frontend Gates
- Clean install:
- Lint:
- TypeScript + production build:
- Unit/component tests:
- Development startup:
- Production preview:
Browser Validation
- Mocked Playwright:
- Live Playwright:
- Affected routes:
- Console errors:
- Failed requests:
Runtime Limitations
- Disabled integrations:
- Mocked external systems:
- Unexecuted checks: