Repository navigation
ci: adopt klein-cli AI review workflow - #33
Conversation
Add an AI code-review workflow that delegates to klein-cli's published reusable workflow (fpt/klein-cli/.github/workflows/ai-review-reusable.yml). Runs klein review over each PR diff and posts a sticky summary plus inline comments. Gated to same-repo PRs so fork PRs never see the API-key secret. Requires the OPENAI_API_KEY repo secret. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
🤖 AI Review (klein) — turn 1This adds a pull-request-triggered job that delegates review to an external reusable workflow and correctly limits execution to same-repository heads, while granting the workflow the API key and pull-request write permission it needs. The external workflow is referenced by the mutable turn 1 (full review of 1ce976e) · comments: total 1, active 1 (+1 new, −0 resolved) · verdict: request_changes |
| jobs: | ||
| review: | ||
| if: github.event.pull_request.head.repo.full_name == github.repository | ||
| uses: fpt/klein-cli/.github/workflows/ai-review-reusable.yml@main |
There was a problem hiding this comment.
[major] Pin the reusable workflow to an immutable commit SHA (and update that SHA deliberately, ideally with an automated dependency-update process) instead of @main.
Rationale
Verified this is the only implementation of the new review job, and it receives OPENAI_API_KEY plus pull-requests: write. Because @main is mutable, a change or compromise in the external repository can alter the workflow that runs with this repository's secret and write token, allowing secret exfiltration or unauthorized PR mutations without any change here.
Summary
Adopt klein-cli's AI code-review workflow by delegating to its published reusable workflow (
fpt/klein-cli/.github/workflows/ai-review-reusable.yml@main).On every PR (
opened/synchronize/reopened) it runsklein reviewover the diff and posts a single sticky summary comment plus inline review comments. Reviews are stateful — incremental on later pushes, no-op rebases skipped, verified-fixed threads resolved.openai, language:enhead.repo.full_name == github.repository), so fork PRs are skipped and never see the API-key secret.Setup required
Add the
OPENAI_API_KEYsecret to the repo for the workflow to run:🤖 Generated with Claude Code