Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 27 additions & 0 deletions .github/workflows/ai-code-review.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
# Caller template: AI Code Review (one-shot, inline) — calls the ai-review reusable.
# Distributed by scripts/distribute-workflow.sh as
# .github/workflows/ai-code-review.yml in each target repository.
# The ref / model / language tokens below are substituted at distribution time.
name: AI Code Review

on:
pull_request:
types: [opened, reopened, ready_for_review] # no synchronize: avoid re-reviewing every push

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ [MEDIUM] [MEDIUM] synchronize イベントが意図的に除外されていますが、これによりPRに追加のコミットがプッシュされた際にレビューが再実行されません。コメントには「every push を避けるため」と記載されていますが、差分のみを対象とした再レビューが必要なユースケースでは問題になる可能性があります。運用方針として意図的であれば問題ありませんが、ドキュメントやREADMEに明記しておくことを推奨します。


concurrency:
group: ai-code-review-${{ github.event.pull_request.number }}
cancel-in-progress: true

jobs:
review:
uses: smkwlab/.github/.github/workflows/ai-review.yml@v1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚨 [HIGH] [HIGH] 呼び出し先のreusable workflowのrefが @v1 と固定されています。v1 タグが強制的に更新(force push)された場合、予期しない破壊的変更が取り込まれるリスクがあります。セキュリティおよび再現性の観点から、@v1 の代わりに特定のコミットSHA(例: @abc1234)を使用することを検討してください。

permissions:
contents: read
pull-requests: write
secrets:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
gemini_api_key: ${{ secrets.GEMINI_API_KEY }}
with:
model_code: claude-sonnet-4-6

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ℹ️ [LOW] [LOW] model_code: claude-sonnet-4-6 というモデル名が直接ハードコードされています。PRの説明では「配布時にトークンが置換される」と記載されていますが、このファイルが配布後のものであれば、モデルのバージョンが変わった際に各リポジトリのファイルを個別に更新する必要が生じます。モデル名をorg/repoレベルの変数(vars.AI_REVIEW_MODEL)として外部化することで、一元管理が容易になります。

review_mode: CODE
language: Japanese
Loading