|
11 | 11 | name: ceo-audit |
12 | 12 |
|
13 | 13 | on: |
| 14 | + # NUR main/master (Branches sind verboten — siehe globale AGENTS.md). |
| 15 | + # PRs sind weiterhin willkommen (last line of defense wenn doch einer entsteht). |
14 | 16 | push: |
15 | | - branches: [main, master, develop] |
| 17 | + branches: [main, master] |
16 | 18 | pull_request: |
17 | | - branches: [main, master, develop] |
| 19 | + branches: [main, master] |
18 | 20 | workflow_dispatch: |
19 | 21 | inputs: |
20 | 22 | profile: |
@@ -69,10 +71,10 @@ jobs: |
69 | 71 | run: | |
70 | 72 | # sin-code-bundle does not yet ship the skill scripts. |
71 | 73 | # Clone the SSOT (Infra-SIN-OpenCode-Stack) to get audit.sh + axis scripts. |
72 | | - git clone --depth 1 --branch main https://github.com/OpenSIN-Code/Infra-SIN-OpenCode-Stack.git /tmp/infra |
| 74 | + git clone --depth 1 --branch main https://github.com/OpenSIN-Code/Infra-SIN-OpenCode-Stack.git ${{ github.workspace }}/infra |
73 | 75 | mkdir -p ~/.config/opencode/skills/ceo-audit |
74 | | - cp -r /tmp/infra/skills/ceo-audit/scripts ~/.config/opencode/skills/ceo-audit/ |
75 | | - cp -r /tmp/infra/skills/ceo-audit/lib ~/.config/opencode/skills/ceo-audit/ |
| 76 | + cp -r ${{ github.workspace }}/infra/skills/ceo-audit/scripts ~/.config/opencode/skills/ceo-audit/ |
| 77 | + cp -r ${{ github.workspace }}/infra/skills/ceo-audit/lib ~/.config/opencode/skills/ceo-audit/ |
76 | 78 | chmod +x ~/.config/opencode/skills/ceo-audit/scripts/audit.sh |
77 | 79 | ls ~/.config/opencode/skills/ceo-audit/scripts/audit.sh |
78 | 80 |
|
@@ -163,6 +165,39 @@ jobs: |
163 | 165 |
|
164 | 166 | > Run `${{ env.AUDIT_PROFILE == 'FULL' && '~/.config/opencode/skills/ceo-audit/scripts/audit.sh . --profile=FULL' || '~/.config/opencode/skills/ceo-audit/scripts/audit.sh . --profile=QUICK' }}` locally to reproduce. |
165 | 167 |
|
| 168 | + - name: Post official audit comment (SIN-GitHub-Issues App) |
| 169 | + if: github.event_name == 'pull_request' && always() |
| 170 | + # Token resolution chain (highest priority first): |
| 171 | + # 1. SIN_GITHUB_INSTALLATION_TOKEN (org secret, App identity, public repos only) |
| 172 | + # 2. SIN_GITHUB_FALLBACK_TOKEN (repo secret, PAT — works on ALL repos incl. private) |
| 173 | + # 3. GITHUB_TOKEN (built-in, Action identity, always present) |
| 174 | + # Resolution happens inside post_audit_pr.py via github_app.get_token(). |
| 175 | + # If ALL tokens are missing, the step fails but continue-on-error prevents |
| 176 | + # the workflow from blocking on App issues. |
| 177 | + continue-on-error: true |
| 178 | + env: |
| 179 | + PYTHONPATH: ${{ github.workspace }}/infra/skills/ceo-audit/lib |
| 180 | + SIN_GITHUB_APP_CLIENT_ID: Iv23livllaHIBTdQdyhY |
| 181 | + # Chain of GitHub tokens (post_audit_pr.py picks the first available). |
| 182 | + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |
| 183 | + SIN_GITHUB_FALLBACK_TOKEN: ${{ secrets.SIN_GITHUB_FALLBACK_TOKEN }} |
| 184 | + run: | |
| 185 | + # post_audit_pr.py lives in the cloned Infra repo (see 'Install ceo-audit skill' step) |
| 186 | + # score.json is written by audit.sh to ~/ceo-audits/<repo>-ceo-audit-<runid>/score.json |
| 187 | + # We search both ceo-audit-output/ and ~/ceo-audits/ to be robust. |
| 188 | + SCORE_FILE=$(find $HOME/ceo-audits ceo-audit-output -name 'score.json' 2>/dev/null | head -1) |
| 189 | + if [ -z "$SCORE_FILE" ]; then |
| 190 | + echo "::warning::No score.json found — skipping App commenter (Action comment above still posts)" |
| 191 | + exit 0 |
| 192 | + fi |
| 193 | + echo "Using score.json: $SCORE_FILE" |
| 194 | + python3 ${{ github.workspace }}/infra/skills/ceo-audit/scripts/post_audit_pr.py \ |
| 195 | + --repo ${{ github.repository }} \ |
| 196 | + --pr ${{ github.event.pull_request.number }} \ |
| 197 | + --score-json "$SCORE_FILE" \ |
| 198 | + --artifact-url ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} \ |
| 199 | + --run-id ${{ github.run_id }} |
| 200 | +
|
166 | 201 | - name: Fail if grade below gate |
167 | 202 | if: github.event_name == 'pull_request' |
168 | 203 | run: | |
|
0 commit comments