mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-02 21:03:34 +03:00
Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.20.0 to 2.20.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/step-security/harden-runner/releases">step-security/harden-runner's releases</a>.</em></p> <blockquote> <h2>v2.20.1</h2> <h2>What's Changed</h2> <ul> <li>AWS CodeBuild-hosted runner support</li> <li>Implicitly allow single-labeled (internal) domains in block-mode</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1">https://github.com/step-security/harden-runner/compare/v2.20.0...v2.20.1</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/step-security/harden-runner/commit/b09bb98e06d4d774595224525879c09bc6e98c40"><code>b09bb98</code></a> Merge pull request <a href="https://redirect.github.com/step-security/harden-runner/issues/680">#680</a> from step-security/aws-code-build</li> <li><a href="https://github.com/step-security/harden-runner/commit/35cd77bcf669054f67ffd3d2802ee54a4f13b5b6"><code>35cd77b</code></a> docs: document the Global Block List in the features list</li> <li><a href="https://github.com/step-security/harden-runner/commit/bb6dbef4bf53876cd2710acd1d36413620d20fb3"><code>bb6dbef</code></a> chore: rebuild dist with clean dependency install</li> <li><a href="https://github.com/step-security/harden-runner/commit/98f73c5a0d2b2cc518e6fb8d973a0a4dde00ba13"><code>98f73c5</code></a> chore: update eBPF agent to v1.8.14</li> <li><a href="https://github.com/step-security/harden-runner/commit/54193c17a4fa3883977217b9afe20378ebe60b19"><code>54193c1</code></a> Reapply "feat(runners): detect AWS CodeBuild-hosted runners as third-party pr...</li> <li><a href="https://github.com/step-security/harden-runner/commit/d22dd481cea4e96cedde031cfe600c248b592d54"><code>d22dd48</code></a> Revert "fix(self-hosted): flush agent events at job end when deploy-on-self-h...</li> <li><a href="https://github.com/step-security/harden-runner/commit/0ff09412fb572363b483a3c86ffe52fe61d9fd19"><code>0ff0941</code></a> fix(self-hosted): flush agent events at job end when deploy-on-self-hosted-vm...</li> <li><a href="https://github.com/step-security/harden-runner/commit/a3c333d110c8d95f34488a22e0e56742cfb1b14f"><code>a3c333d</code></a> Revert "feat(runners): detect AWS CodeBuild-hosted runners as third-party pro...</li> <li><a href="https://github.com/step-security/harden-runner/commit/bf94c00d6bba2ae7c4a479b86653039811569968"><code>bf94c00</code></a> feat(runners): detect AWS CodeBuild-hosted runners as third-party provider</li> <li><a href="https://github.com/step-security/harden-runner/commit/514522c5e449f9e28fc901f770e08a573d413e67"><code>514522c</code></a> fix(self-hosted): resolve runner user when USER env var is unset</li> <li>See full diff in <a href="https://github.com/step-security/harden-runner/compare/bf7454d06d71f1098171f2acdf0cd4708d7b5920...b09bb98e06d4d774595224525879c09bc6e98c40">compare view</a></li> </ul> </details> <br /> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
222 lines
8.4 KiB
YAML
222 lines
8.4 KiB
YAML
name: AI - PR Title Review
|
||
|
||
on:
|
||
pull_request:
|
||
types: [opened, edited]
|
||
branches: [main]
|
||
|
||
permissions: # required for secure-repo hardening
|
||
contents: read
|
||
|
||
jobs:
|
||
ai-title-review:
|
||
# GITHUB_TOKEN obeys this block, so it must cover every API call made below.
|
||
permissions:
|
||
contents: read # actions/checkout, git fetch/diff
|
||
issues: write # issues.listComments / createComment / updateComment on the PR
|
||
pull-requests: write # same endpoints when the target is a pull request
|
||
models: read # actions/ai-inference
|
||
|
||
runs-on: ubuntu-latest
|
||
|
||
steps:
|
||
- name: Harden Runner
|
||
uses: step-security/harden-runner@b09bb98e06d4d774595224525879c09bc6e98c40 # v2.20.1
|
||
with:
|
||
egress-policy: audit
|
||
|
||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||
with:
|
||
fetch-depth: 0
|
||
|
||
- name: Configure Git to suppress detached HEAD warning
|
||
run: git config --global advice.detachedHead false
|
||
|
||
- name: Check if actor is repo developer
|
||
id: actor
|
||
run: |
|
||
if [[ "${{ github.actor }}" == *"[bot]" ]]; then
|
||
echo "PR opened by a bot – skipping AI title review."
|
||
echo "is_repo_dev=false" >> $GITHUB_OUTPUT
|
||
exit 0
|
||
fi
|
||
if [ ! -f .github/config/repo_devs.json ]; then
|
||
echo "Error: .github/config/repo_devs.json not found" >&2
|
||
exit 1
|
||
fi
|
||
# Validate JSON and extract repo_devs
|
||
REPO_DEVS=$(jq -r '.repo_devs[]' .github/config/repo_devs.json 2>/dev/null || { echo "Error: Invalid JSON in repo_devs.json" >&2; exit 1; })
|
||
# Convert developer list into Bash array
|
||
mapfile -t DEVS_ARRAY <<< "$REPO_DEVS"
|
||
if [[ " ${DEVS_ARRAY[*]} " == *" ${{ github.actor }} "* ]]; then
|
||
echo "is_repo_dev=true" >> $GITHUB_OUTPUT
|
||
else
|
||
echo "is_repo_dev=false" >> $GITHUB_OUTPUT
|
||
fi
|
||
|
||
- name: Get PR diff
|
||
if: steps.actor.outputs.is_repo_dev == 'true'
|
||
id: get_diff
|
||
run: |
|
||
git fetch origin ${{ github.base_ref }}
|
||
git diff origin/${{ github.base_ref }}...HEAD | head -n 10000 | grep -vP '[\x00-\x08\x0B\x0C\x0E-\x1F\x7F\x{202E}\x{200B}]' > pr.diff
|
||
echo "diff<<EOF" >> $GITHUB_OUTPUT
|
||
cat pr.diff >> $GITHUB_OUTPUT
|
||
echo "EOF" >> $GITHUB_OUTPUT
|
||
|
||
- name: Check and sanitize PR title
|
||
if: steps.actor.outputs.is_repo_dev == 'true'
|
||
id: sanitize_pr_title
|
||
env:
|
||
PR_TITLE_RAW: ${{ github.event.pull_request.title }}
|
||
run: |
|
||
# Sanitize PR title: max 72 characters, only printable characters
|
||
PR_TITLE=$(echo "$PR_TITLE_RAW" | tr -d '\n\r' | head -c 72 | sed 's/[^[:print:]]//g')
|
||
if [[ ${#PR_TITLE} -lt 5 ]]; then
|
||
echo "PR title is too short. Must be at least 5 characters." >&2
|
||
fi
|
||
echo "pr_title=$PR_TITLE" >> $GITHUB_OUTPUT
|
||
|
||
- name: AI PR Title Analysis
|
||
if: steps.actor.outputs.is_repo_dev == 'true'
|
||
id: ai-title-analysis
|
||
uses: actions/ai-inference@a7805884c80886efc241e94a5351df715968a0ad # v2.1.1
|
||
with:
|
||
model: openai/gpt-4o
|
||
system-prompt-file: ".github/config/system-prompt.txt"
|
||
prompt: |
|
||
Based on the following input data:
|
||
|
||
{
|
||
"diff": "${{ steps.get_diff.outputs.diff }}",
|
||
"pr_title": "${{ steps.sanitize_pr_title.outputs.pr_title }}"
|
||
}
|
||
|
||
Respond ONLY with valid JSON in the format:
|
||
{
|
||
"improved_rating": <0-10>,
|
||
"improved_ai_title_rating": <0-10>,
|
||
"improved_title": "<ai generated title>"
|
||
}
|
||
|
||
- name: Validate and set SCRIPT_OUTPUT
|
||
if: steps.actor.outputs.is_repo_dev == 'true'
|
||
run: |
|
||
cat <<EOF > ai_response.json
|
||
${{ steps.ai-title-analysis.outputs.response }}
|
||
EOF
|
||
|
||
# Validate JSON structure
|
||
jq -e '
|
||
(keys | sort) == ["improved_ai_title_rating", "improved_rating", "improved_title"] and
|
||
(.improved_rating | type == "number" and . >= 0 and . <= 10) and
|
||
(.improved_ai_title_rating | type == "number" and . >= 0 and . <= 10) and
|
||
(.improved_title | type == "string")
|
||
' ai_response.json
|
||
if [ $? -ne 0 ]; then
|
||
echo "Invalid AI response format" >&2
|
||
cat ai_response.json >&2
|
||
exit 1
|
||
fi
|
||
# Parse JSON fields
|
||
IMPROVED_RATING=$(jq -r '.improved_rating' ai_response.json)
|
||
IMPROVED_TITLE=$(jq -r '.improved_title' ai_response.json)
|
||
# Limit comment length to 1000 characters
|
||
COMMENT=$(cat <<EOF
|
||
## 🤖 AI PR Title Suggestion
|
||
|
||
**PR-Title Rating**: $IMPROVED_RATING/10
|
||
|
||
### ⬇️ Suggested Title (copy & paste):
|
||
|
||
\`\`\`
|
||
$IMPROVED_TITLE
|
||
\`\`\`
|
||
|
||
---
|
||
*Generated by GitHub Models AI*
|
||
EOF
|
||
)
|
||
echo "$COMMENT" > /tmp/ai-title-comment.md
|
||
# Log input and output to the GitHub Step Summary
|
||
echo "### 🤖 AI PR Title Analysis" >> $GITHUB_STEP_SUMMARY
|
||
echo "### Input PR Title" >> $GITHUB_STEP_SUMMARY
|
||
echo '```bash' >> $GITHUB_STEP_SUMMARY
|
||
echo "${{ steps.sanitize_pr_title.outputs.pr_title }}" >> $GITHUB_STEP_SUMMARY
|
||
echo '```' >> $GITHUB_STEP_SUMMARY
|
||
echo '### AI Response (raw JSON)' >> $GITHUB_STEP_SUMMARY
|
||
echo '```json' >> $GITHUB_STEP_SUMMARY
|
||
cat ai_response.json >> $GITHUB_STEP_SUMMARY
|
||
echo '```' >> $GITHUB_STEP_SUMMARY
|
||
|
||
- name: Post comment on PR if needed
|
||
if: steps.actor.outputs.is_repo_dev == 'true'
|
||
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
||
continue-on-error: true
|
||
with:
|
||
github-token: ${{ github.token }}
|
||
script: |
|
||
const fs = require('fs');
|
||
const body = fs.readFileSync('/tmp/ai-title-comment.md', 'utf8');
|
||
const { GITHUB_REPOSITORY } = process.env;
|
||
const [owner, repo] = GITHUB_REPOSITORY.split('/');
|
||
const issue_number = context.issue.number;
|
||
|
||
const ratingMatch = body.match(/\*\*PR-Title Rating\*\*: (\d+)\/10/);
|
||
const rating = ratingMatch ? parseInt(ratingMatch[1], 10) : null;
|
||
|
||
const expectedActor = "github-actions[bot]";
|
||
const comments = await github.rest.issues.listComments({ owner, repo, issue_number });
|
||
|
||
const existing = comments.data.find(c =>
|
||
c.user?.login === expectedActor &&
|
||
c.body.includes("## 🤖 AI PR Title Suggestion")
|
||
);
|
||
|
||
if (rating === null) {
|
||
console.log("No rating found in AI response – skipping.");
|
||
return;
|
||
}
|
||
|
||
if (rating <= 5) {
|
||
if (existing) {
|
||
await github.rest.issues.updateComment({
|
||
owner, repo,
|
||
comment_id: existing.id,
|
||
body
|
||
});
|
||
console.log("Updated existing suggestion comment.");
|
||
} else {
|
||
await github.rest.issues.createComment({
|
||
owner, repo, issue_number,
|
||
body
|
||
});
|
||
console.log("Created new suggestion comment.");
|
||
}
|
||
} else {
|
||
const praise = `## 🤖 AI PR Title Suggestion\n\nGreat job! The current PR title is clear and well-structured.\n\n✅ No suggestions needed.\n\n---\n*Generated by GitHub Models AI*`;
|
||
|
||
if (existing) {
|
||
await github.rest.issues.updateComment({
|
||
owner, repo,
|
||
comment_id: existing.id,
|
||
body: praise
|
||
});
|
||
console.log("Replaced suggestion with praise.");
|
||
} else {
|
||
console.log("Rating > 5 and no existing comment – skipping comment.");
|
||
}
|
||
}
|
||
|
||
- name: is not repo dev
|
||
if: steps.actor.outputs.is_repo_dev != 'true'
|
||
run: |
|
||
exit 0 # Skip the AI title review for non-repo developers
|
||
|
||
- name: Clean up
|
||
if: always()
|
||
run: |
|
||
rm -f pr.diff ai_response.json /tmp/ai-title-comment.md
|
||
echo "Cleaned up temporary files."
|
||
continue-on-error: true # Ensure cleanup runs even if previous steps fail
|