Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 11 additions & 11 deletions .github/workflows/dotbot-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,9 @@ jobs:
with:
fetch-depth: 0
# NOTE: ovh-k8s-cluster uses secrets.DOTBOT_GITHUB_USER_PAT (a machine-user
# PAT) for these statuses; this repo has no such secret, so the workflow
# token (statuses: write) is used instead.
# PAT) for these statuses; this repo now has that secret too, but the
# workflow token still posts the statuses (statuses: write below), which
# keeps them independent of the approval PAT.
# "Being reviewed by dotBot" is a commit status on the head SHA, not a
# PR comment: statuses never send notification emails, and the PR's
# checks area shows the in-progress state live. (A run cancelled by
Expand Down Expand Up @@ -99,15 +100,14 @@ jobs:
mode: review
openrouter_api_key: ${{ secrets.OPENROUTER_API_KEY }}
model: deepseek/deepseek-v4-pro-0813
# Auto-approval when every reviewer reports "patch is correct". This
# repo has no DOTBOT_GITHUB_USER_PAT machine-user PAT (see the note
# above), so the workflow token is used: the approval lands as
# github-actions[bot], which the repo permits
# (Settings → Actions → "Allow GitHub Actions to create and approve
# pull requests"). A PAT is still the better choice where one exists
# — it attributes the approval to a named user, and a bot cannot
# approve a PR the bot itself authored.
github_approval_token: ${{ github.token }}
# Auto-approval when every reviewer reports "patch is correct".
# DOTBOT_GITHUB_USER_PAT (the machine user, dotCMS-Machine-User) is
# preferred: the approval is a named-user approval, and the token's
# user must differ from the PR author or GitHub rejects it. Falls back
# to the workflow token so a repo without the secret still approves —
# that lands as github-actions[bot] (allowed here: Settings → Actions →
# "Allow GitHub Actions to create and approve pull requests").
github_approval_token: ${{ secrets.DOTBOT_GITHUB_USER_PAT || github.token }}
reasoning_effort: medium
web_search_mode: cached
debug_level: 1
Expand Down
6 changes: 5 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,11 @@ submission failures are logged as warnings and never fail the review run.
> The PAT needs `pull-requests: write` scope, and its user must differ from
> the PR author (GitHub rejects approvals from the PR author).
>
> Where no machine-user PAT is available, `github_approval_token: ${{ github.token }}`
> The self-hosted review workflow wires both:
> `github_approval_token: ${{ secrets.DOTBOT_GITHUB_USER_PAT || github.token }}`
> — the machine-user PAT when the secret exists, the workflow token otherwise,
> so a consumer repo with no PAT still approves. Where no machine-user PAT is
> available, `github_approval_token: ${{ github.token }}`
> works too, provided the repo allows it (Settings → Actions → "Allow GitHub
> Actions to create and approve pull requests"). Installation tokens cannot read
> `GET /user`, so the action does not try to resolve an identity for them: the
Expand Down
9 changes: 6 additions & 3 deletions tests/test_module_coverage.py
Original file line number Diff line number Diff line change
Expand Up @@ -800,9 +800,12 @@ def test_review_action_and_workflow_use_expected_resume_guard_and_model() -> Non
if "dotCMS/openrouter-code-review-action@" in line
}
assert pins == {expected_action_pin}, f"unexpected action pins: {sorted(pins)}"
# Auto-approval when every reviewer agrees: this repo has no machine-user
# PAT, so the workflow token is passed explicitly.
assert "github_approval_token: ${{ github.token }}" in review_workflow
# Auto-approval when every reviewer agrees: prefer the machine-user PAT,
# fall back to the workflow token so a repo without the secret still approves.
assert (
"github_approval_token: ${{ secrets.DOTBOT_GITHUB_USER_PAT || github.token }}"
in review_workflow
)


def test_self_hosted_workflows_drive_models_from_org_repo_variables() -> None:
Expand Down
Loading