Public repository for reusable GitHub workflows and actions built around agent tools.
This repository is intentionally tool-generic. Codex is the first workflow family, but the repository is structured so future workflow sets can target other agent tools without changing the repository identity.
/.github/workflows/codex-pr-review.ymlReusable workflow for pull-request Codex review with inline PR comments and a sticky summary./.github/workflows/codex-review-override.ymlReusable workflow for the/codex-overrideissue-comment flow./.github/codex-review/Internal helper scripts that build the review prompt, run Codex in structured mode, normalize findings, and publish managed GitHub review comments.
The shared review workflow restores a Codex CLI auth bundle from
codex_auth_json.
The helper scripts restore the secret into an isolated ~/.codex/auth.json,
validate the restored bundle shape, and run the review without relying on
runner-local Codex state. This keeps the workflow aligned with the current
Orbio CI contract: restored Codex session credentials in a temporary isolated
home, not API-key login during the job.
OpenAI documents persisted auth.json as an advanced pattern for trusted
private runners:
- https://developers.openai.com/codex/auth/ci-cd-auth/
- https://developers.openai.com/codex/cli/reference/#codex-login
Each consumer repository keeps a thin caller workflow with repo-local triggers, permissions, and concurrency. The caller delegates the implementation to this repository by semver tag or immutable ref.
Because this workflow restores a Codex CLI auth bundle, callers should run it on trusted private runners, not on public shared runner fleets.
Example PR review caller:
name: codex-pr-review
on:
pull_request:
types:
- opened
- synchronize
- reopened
- ready_for_review
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
actions: read
contents: read
issues: write
pull-requests: write
jobs:
review:
uses: Gabrielgvl/agent-workflows/.github/workflows/codex-pr-review.yml@v1
with:
runs_on_json: '["self-hosted"]'
install_codex_cli: true
codex_version: "latest"
review_model: "gpt-5.4"
review_reasoning_effort: medium
max_inline_comments: "10"
secrets:
codex_auth_json: ${{ secrets.CODEX_AUTH_JSON }}Example override caller:
name: codex-review-override
on:
issue_comment:
types:
- created
- edited
permissions:
actions: write
contents: read
issues: write
pull-requests: write
jobs:
override:
uses: Gabrielgvl/agent-workflows/.github/workflows/codex-review-override.yml@v1- Draft pull requests are skipped.
- Fork pull requests are skipped.
- Blocking findings are published as native inline PR review comments.
- The workflow always maintains one sticky PR summary comment with the current verdict, counts, override state, and workflow links.
- The review prompt performs an exhaustive blocker-first sweep of every changed file and diff hunk before returning, so the first run is biased toward surfacing all P0 and P1 findings instead of only the first couple discovered.
- The review helper emits timestamped progress logs while Codex is running so long inference steps do not look frozen in Actions.
- The review helper pins the runner's existing
codexexecutable behind a wrapper before isolatingHOME, so common self-hosted installs such as Volta-managed shims keep working during review execution. - The review prompt treats same-owner reusable workflows and actions as
first-party infrastructure, so it does not raise supply-chain findings solely
because those refs use a major tag such as
@v1. - Unresolved managed findings from the previous bot run are fed back into the next Codex prompt so reruns revalidate prior issues.
- The workflow auto-selects a review mode to prevent rerun churn:
discovery: first completed run for a PR performs the full exhaustive sweep overorigin/<base>...HEAD.gate: later runs review only incremental changes from the most recent completed review SHA toHEAD, while revalidating prior open findings.same_sha: if no code changed since the latest completed review, the workflow skips Codex execution and reuses prior open findings state.- Rebase/force-push safety: when a gate run detects that the prior review SHA
is no longer an ancestor of
HEAD, it automatically degrades to discovery scope for that run.
- Publication freshness guard: before posting inline comments or updating the
sticky summary, the workflow re-checks the PR's current
head.shaand skips publication if the run is stale. - Managed inline comments are now incrementally reconciled: newly discovered blockers are posted, reopened blockers are re-posted, and findings that no longer appear can be pruned without deleting every managed comment on each run.
- The caller workflow must grant
actions: readso the reusable workflow can resolve its own pinned source from the current run metadata. - The review helper runs Codex with
--sandbox danger-full-access. This is intentional for trusted CI runners where the Linux sandbox backend can fail during setup, includingbwraploopback bridge initialization. - P0 always blocks.
- P1 blocks unless an admin override is active.
- P2 and P3 are visible in the summary and artifacts, but do not block.
Primary review inputs:
review_modelDefault:gpt-5.4Usegpt-5.2-codexif you want the current OpenAI code-review cookbook's review-specialized recommendation.review_reasoning_effortAllowed:minimal,low,medium,high,xhighDefault:mediumreview_reasoning_summaryAllowed:auto,concise,detailed,noneDefault: unsetreview_verbosityAllowed:low,medium,highDefault: unsetmax_inline_commentsAllowed:1through20Default:10
Runner and installation inputs:
runs_on_jsonJSON array passed directly toruns-onworking_directoryCheckout path for the caller repositoryinstall_codex_cliWhether the workflow should install Codex itselfnode_versionNode version used when installing Codexcodex_version@openai/codexversion used wheninstall_codex_cliis true Default:latestreview_timeout_secondsInner Codex execution timeout Default:900override_labelLabel used by the override workflow to mark an approved P1 exception
Secrets:
codex_auth_jsonRequired. The raw Codex CLIauth.jsondocument restored into an isolated temporary home for the review run.
- Use
@v1for a stable moving major tag. - Use an immutable SHA when you need strict pinning.
- Roll forward or back by changing the caller ref in consumer repositories.