Repository navigation
ci: fix Devin threads on deepseek-ci (quota guards, ESM solver, gitignore, heredoc) #115
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
|
|
@@ -11,6 +11,9 @@ name: 'DeepSeek CI (peer Omni ↔ OpenRouter HTTPS + opt-in web-wrapper)' | |||||
| # The DeepSeek web-wrapper is intentionally a separate, explicit third-peer path | ||||||
| # (see the deepseek-webwrapper job) and stays disabled until a real, non-simulated | ||||||
| # invocation exists. Never caches/uploads/commits session cookies or tokens. | ||||||
| # | ||||||
| # Review job runs only on non-fork, non-draft PRs and uses a distinct comment | ||||||
| # marker to avoid double-counting free-tier quota against gemini-after-peers. | ||||||
|
|
||||||
| on: | ||||||
| pull_request: | ||||||
|
|
@@ -31,7 +34,10 @@ permissions: {} | |||||
|
|
||||||
| jobs: | ||||||
| review: | ||||||
| if: github.event_name == 'pull_request' | ||||||
| if: | | ||||||
| github.event_name == 'pull_request' && | ||||||
| github.event.pull_request.head.repo.fork == false && | ||||||
| github.event.pull_request.draft == false | ||||||
| runs-on: ubuntu-latest | ||||||
| permissions: | ||||||
| contents: read | ||||||
|
|
@@ -71,16 +77,19 @@ jobs: | |||||
| fi | ||||||
| DIFF=$(gh api "repos/${REPO}/pulls/${TARGET_PR}" -H "Accept: application/vnd.github.v3.diff" 2>/dev/null \ | ||||||
| | head -c 24000 || true) | ||||||
| # Random delimiter prevents PR-diff lines that equal a fixed token from | ||||||
| # terminating the multiline GITHUB_OUTPUT early (step-output injection). | ||||||
| DELIM="DSCR_$(openssl rand -hex 8)" | ||||||
| { | ||||||
| echo "prompt<<EOF" | ||||||
| echo "prompt<<${DELIM}" | ||||||
| cat <<PROMPT | ||||||
| You are the free-tier DeepSeek-CI peer reviewer for termux-monorepo. Concise. ONE response. | ||||||
| Target PR #${TARGET_PR}. | ||||||
| Check: correctness, security (no secrets/PII), AGENTS.md rules, minimal diff. | ||||||
| Diff (truncated): | ||||||
| ${DIFF} | ||||||
| PROMPT | ||||||
| echo "EOF" | ||||||
| echo "${DELIM}" | ||||||
| } >> "$GITHUB_OUTPUT" | ||||||
|
Comment on lines
89
to
93
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Random GITHUB_OUTPUT delimiter fixes only half of the injection path The randomized (Refers to lines 80-93) Was this helpful? React with 👍 or 👎 to provide feedback. |
||||||
|
|
||||||
| - name: OmniRoute review (peer) | ||||||
|
|
@@ -118,6 +127,7 @@ jobs: | |||||
| github.event_name == 'workflow_dispatch' && | ||||||
| (inputs.enable_deepseek_webwrapper == true || vars.DEEPSEEK_WEBWRAPPER_ENABLED == '1') | ||||||
| runs-on: ubuntu-latest | ||||||
| timeout-minutes: 10 | ||||||
| permissions: | ||||||
| contents: read | ||||||
| steps: | ||||||
|
|
@@ -126,12 +136,12 @@ jobs: | |||||
| persist-credentials: false | ||||||
|
|
||||||
| - name: Setup Node.js (PoW WASM solver) | ||||||
| uses: actions/setup-node@v4 | ||||||
| uses: actions/setup-node@39370e3970a6d050c480ffad4ff0ed4d3fdee5af # v4.1.0 | ||||||
| with: | ||||||
| node-version: '20' | ||||||
|
|
||||||
| - name: Setup Python | ||||||
| uses: actions/setup-python@v5 | ||||||
| uses: actions/setup-python@0b93645e9fea7318ecaed2b4117511b8a72f1f5 # v5.3.0 | ||||||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔴 Opt-in DeepSeek smoke-test job always fails because a pinned action reference is malformed The Python setup step points at a commit reference that is one character short of a valid 40-character commit id ( Action reference resolution requires a full 40-hex commit SHA
Suggested change
Was this helpful? React with 👍 or 👎 to provide feedback. |
||||||
| with: | ||||||
| python-version: '3.11' | ||||||
|
|
||||||
|
|
||||||
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
@@ -124,13 +124,13 @@ cli-synthegration/workspace/provenance/ | |||||||||||||||||||||||||||||||||||||||
| cli-synthegration/codex/ | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| # === DeepSeek web-wrapper opt-in CI smoke test (transient; $RUNNER_TEMP only) === | ||||||||||||||||||||||||||||||||||||||||
| # Only ignore runtime session state — never ignore tracked sources such as | ||||||||||||||||||||||||||||||||||||||||
| # deepcli/pow_solver.js (required for PoW). Bare patterns like pow_solver.js | ||||||||||||||||||||||||||||||||||||||||
| # or session.json would hide legitimate tracked files if re-added. | ||||||||||||||||||||||||||||||||||||||||
| deepseek-webwrapper-home/ | ||||||||||||||||||||||||||||||||||||||||
| deepseek_output.json | ||||||||||||||||||||||||||||||||||||||||
| deepcli/session.json | ||||||||||||||||||||||||||||||||||||||||
| deepcli/pow_solver.js | ||||||||||||||||||||||||||||||||||||||||
| session.json | ||||||||||||||||||||||||||||||||||||||||
| cookies_2.json | ||||||||||||||||||||||||||||||||||||||||
| pow_solver.js | ||||||||||||||||||||||||||||||||||||||||
| deepcli/cookies_2.json | ||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+127
to
+133
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🟡 Session-state files outside one folder are no longer excluded from version control The catch-all exclusion for session state files was narrowed to a single folder (removal of the bare Which paths lose protectionAGENTS.md hard rule: "No Class 3/4 artifacts in git (session stores, browser profiles, tokens)". The old bare patterns
Suggested change
Was this helpful? React with 👍 or 👎 to provide feedback.
Comment on lines
+127
to
+133
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🟨 Repo-wide ignore for session state files removed, risking commit of session/token artifacts The bare Was this helpful? React with 👍 or 👎 to provide feedback. |
||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| # === Build artifacts and caches === | ||||||||||||||||||||||||||||||||||||||||
| workspace/maxc/target/ | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,6 @@ | ||
| { | ||
| "name": "deepcli-pow-solver", | ||
| "private": true, | ||
| "type": "module", | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Adding type:module scopes ESM to the whole deepcli directory The new Was this helpful? React with 👍 or 👎 to provide feedback. |
||
| "description": "ESM context so pow_solver.js (import syntax) runs under Node 20 without .mjs rename" | ||
| } | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔍 Header comment claims a distinct comment marker that this PR does not add
The new header text says the review job "uses a distinct comment marker to avoid double-counting free-tier quota against gemini-after-peers", but no marker is set anywhere in this workflow. Markers are derived inside the shared action from provider+role (
<!-- omni-review -->/<!-- openrouter-review -->,.github/actions/http-llm-invoke/action.yml:97-107), so the distinctness is incidental to provider choice, not something added here. If a gemini job also runs with provideromni/openrouterand rolereview, comments would still collide.Was this helpful? React with 👍 or 👎 to provide feedback.