Add GitHub Models tool review workflow - #62
Draft
valentin-vogel wants to merge 3 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Replaces the custom-AI-API approach with a GitHub-native review architecture:
actions/ai-inference@v2with GitHub ModelsGITHUB_TOKEN; noOPENAI_API_KEYis required.prompt.ymlunder.github/prompts/Security
The workflow uses
pull_request_targetso fork PRs can use GitHub Models and write a review comment, but it always checks out the trusted default branch and never executes contributor-controlled PR code.The website fetcher also rejects localhost, private, link-local, multicast/reserved targets and validates redirect destinations before fetching them. Crawling is bounded and restricted to selected pages on the submitted official host. GitHub links found on the official website are recorded as evidence but are not blindly crawled.
Configuration
GitHub Models must be enabled for the repository. The workflow requests
models: readand uses GitHub's automatically provided token; no external AI secret is needed.The prompt currently uses
openai/gpt-4o, which is configured in.github/prompts/tool-review.prompt.ymland can be changed/tested through GitHub Models tooling.Validation
Compared against
main: exactly three new files and no existing repository files modified.Note: because this workflow itself is not yet present on the default branch, its
pull_request_targettrigger cannot fully exercise this new workflow until it is merged.