Skip to content

hyperdxio/.github

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

8 Commits
 
 
 
 

Repository files navigation

hyperdxio/.github

Org-wide shared GitHub Actions for the hyperdxio organization.

The workflows under .github/workflows/ are reusable workflows (on: workflow_call) — the single source of truth for CI that should behave identically across every repo. Each consuming repo adds a small caller stub that declares the triggers and calls one of these. Editing a workflow here propagates to every repo that references it (see Versioning).

Available workflows

Workflow What it does Required secret
deep-review.yml Multi-agent "Deep Code Review" of a PR (compound-engineering plugin), posted as a sticky <!-- deep-review --> comment. ANTHROPIC_API_KEY
external-contributor-alerts.yml Slack alert + external label when a non-member opens an issue/PR. SLACK_WEBHOOK_OSS_PRS
pr-triage.yml Classifies PR risk tier, applies a review/tier-* label, and posts a <!-- pr-triage --> comment. Logic lives in .github/scripts/. none

Consuming a workflow

Add a caller stub to the consuming repo under .github/workflows/. The stub owns the triggers and permissions (a reusable workflow can't declare its own triggers, and caller permissions are authoritative). Pass only the secrets a workflow declares (below) rather than secrets: inherit, so a compromised reusable workflow can't reach secrets it never needed.

Deep Code Review — .github/workflows/deep-review.yml

name: Deep Code Review
on:
  pull_request_target:
    types: [opened, synchronize, ready_for_review]
  workflow_dispatch:
    inputs:
      pr_number:
        description: Pull request number to review
        required: true
        type: string
jobs:
  deep-review:
    permissions:
      contents: read
      pull-requests: write
      issues: write
      id-token: write
      actions: read
    uses: hyperdxio/.github/.github/workflows/deep-review.yml@main
    with:
      pr_number: ${{ inputs.pr_number }} # empty on PR events; the workflow falls back to the PR event
    secrets:
      ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}

External-contributor alerts — .github/workflows/external-contributor-alerts.yml

name: Alert on external contributions
on:
  issues:
    types: [opened, reopened]
  pull_request_target:
    types: [opened, reopened, ready_for_review]
jobs:
  alert:
    permissions:
      issues: write
      pull-requests: write
    uses: hyperdxio/.github/.github/workflows/external-contributor-alerts.yml@main
    secrets:
      SLACK_WEBHOOK_OSS_PRS: ${{ secrets.SLACK_WEBHOOK_OSS_PRS }}

PR Triage — .github/workflows/pr-triage.yml

name: PR Triage
on:
  pull_request:
    branches: [main]
    types: [opened, synchronize, reopened, ready_for_review]
  workflow_dispatch:
    inputs:
      pr_number:
        description: PR number to classify (leave blank to classify all open PRs)
        required: false
        type: string
jobs:
  triage:
    permissions:
      contents: read
      pull-requests: write
      issues: write
    uses: hyperdxio/.github/.github/workflows/pr-triage.yml@main
    with:
      pr_number: ${{ inputs.pr_number }}

Versioning

Callers pin with @main, so edits here take effect on the next run in every consuming repo. If you'd prefer a release gate (a bad edit to main otherwise breaks all repos at once), tag releases and have callers pin @v1, then move the v1 tag when you cut a new version. If you adopt tags, keep the ref: in pr-triage.yml's checkout steps in lockstep with the tag callers use.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors