ci: pilot AI first-pass PR review via open-code-review - #232
Open
asachs01 wants to merge 1 commit into
Open
Conversation
Automated first-pass review, not a merge gate — a human approval is still required separately via branch protection (to follow once this pilot is validated). Fork PRs are deliberately excluded for now (uses pull_request, not pull_request_target) until the action's internal steps get reviewed for safe fork-secret handling. Pinned to alibaba/open-code-review@v1.11.1 by commit SHA rather than @main, with a dependabot.yml entry to track future pin updates.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Pilot for the SOC2 change-management control — automated first-pass review on every same-repo PR via alibaba/open-code-review, pinned to v1.11.1 by SHA.
This is a review assist, not the merge gate. Branch protection requiring a human approval is the actual control (matches what Vanta's "Application Changes Reviewed" test checks for) — to follow once this pilot proves out.
Fork PRs are excluded for now (
pull_request, notpull_request_target) pending a security review of the action's internal steps.This PR itself is the live test — the workflow should trigger on this PR and post a review.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.