Skip to content

Commit 84c2517

Browse files
author
SIN-Agent
committed
ci: ceo-audit.yml v3 — App commenter + SIN_GITHUB_FALLBACK_TOKEN
1 parent a7b8e7c commit 84c2517

1 file changed

Lines changed: 40 additions & 5 deletions

File tree

‎.github/workflows/ceo-audit.yml‎

Lines changed: 40 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -11,10 +11,12 @@
1111
name: ceo-audit
1212

1313
on:
14+
# NUR main/master (Branches sind verboten — siehe globale AGENTS.md).
15+
# PRs sind weiterhin willkommen (last line of defense wenn doch einer entsteht).
1416
push:
15-
branches: [main, master, develop]
17+
branches: [main, master]
1618
pull_request:
17-
branches: [main, master, develop]
19+
branches: [main, master]
1820
workflow_dispatch:
1921
inputs:
2022
profile:
@@ -69,10 +71,10 @@ jobs:
6971
run: |
7072
# sin-code-bundle does not yet ship the skill scripts.
7173
# Clone the SSOT (Infra-SIN-OpenCode-Stack) to get audit.sh + axis scripts.
72-
git clone --depth 1 --branch main https://github.com/OpenSIN-Code/Infra-SIN-OpenCode-Stack.git /tmp/infra
74+
git clone --depth 1 --branch main https://github.com/OpenSIN-Code/Infra-SIN-OpenCode-Stack.git ${{ github.workspace }}/infra
7375
mkdir -p ~/.config/opencode/skills/ceo-audit
74-
cp -r /tmp/infra/skills/ceo-audit/scripts ~/.config/opencode/skills/ceo-audit/
75-
cp -r /tmp/infra/skills/ceo-audit/lib ~/.config/opencode/skills/ceo-audit/
76+
cp -r ${{ github.workspace }}/infra/skills/ceo-audit/scripts ~/.config/opencode/skills/ceo-audit/
77+
cp -r ${{ github.workspace }}/infra/skills/ceo-audit/lib ~/.config/opencode/skills/ceo-audit/
7678
chmod +x ~/.config/opencode/skills/ceo-audit/scripts/audit.sh
7779
ls ~/.config/opencode/skills/ceo-audit/scripts/audit.sh
7880
@@ -163,6 +165,39 @@ jobs:
163165
164166
> Run `${{ env.AUDIT_PROFILE == 'FULL' && '~/.config/opencode/skills/ceo-audit/scripts/audit.sh . --profile=FULL' || '~/.config/opencode/skills/ceo-audit/scripts/audit.sh . --profile=QUICK' }}` locally to reproduce.
165167
168+
- name: Post official audit comment (SIN-GitHub-Issues App)
169+
if: github.event_name == 'pull_request' && always()
170+
# Token resolution chain (highest priority first):
171+
# 1. SIN_GITHUB_INSTALLATION_TOKEN (org secret, App identity, public repos only)
172+
# 2. SIN_GITHUB_FALLBACK_TOKEN (repo secret, PAT — works on ALL repos incl. private)
173+
# 3. GITHUB_TOKEN (built-in, Action identity, always present)
174+
# Resolution happens inside post_audit_pr.py via github_app.get_token().
175+
# If ALL tokens are missing, the step fails but continue-on-error prevents
176+
# the workflow from blocking on App issues.
177+
continue-on-error: true
178+
env:
179+
PYTHONPATH: ${{ github.workspace }}/infra/skills/ceo-audit/lib
180+
SIN_GITHUB_APP_CLIENT_ID: Iv23livllaHIBTdQdyhY
181+
# Chain of GitHub tokens (post_audit_pr.py picks the first available).
182+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
183+
SIN_GITHUB_FALLBACK_TOKEN: ${{ secrets.SIN_GITHUB_FALLBACK_TOKEN }}
184+
run: |
185+
# post_audit_pr.py lives in the cloned Infra repo (see 'Install ceo-audit skill' step)
186+
# score.json is written by audit.sh to ~/ceo-audits/<repo>-ceo-audit-<runid>/score.json
187+
# We search both ceo-audit-output/ and ~/ceo-audits/ to be robust.
188+
SCORE_FILE=$(find $HOME/ceo-audits ceo-audit-output -name 'score.json' 2>/dev/null | head -1)
189+
if [ -z "$SCORE_FILE" ]; then
190+
echo "::warning::No score.json found — skipping App commenter (Action comment above still posts)"
191+
exit 0
192+
fi
193+
echo "Using score.json: $SCORE_FILE"
194+
python3 ${{ github.workspace }}/infra/skills/ceo-audit/scripts/post_audit_pr.py \
195+
--repo ${{ github.repository }} \
196+
--pr ${{ github.event.pull_request.number }} \
197+
--score-json "$SCORE_FILE" \
198+
--artifact-url ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} \
199+
--run-id ${{ github.run_id }}
200+
166201
- name: Fail if grade below gate
167202
if: github.event_name == 'pull_request'
168203
run: |

0 commit comments

Comments
 (0)