fix(ci): run hourly review autofix through NVIDIA NIM - #752
Merged
seonghobae merged 30 commits intoAug 4, 2026
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
seonghobae
marked this pull request as ready for review
August 4, 2026 23:12
seonghobae
merged commit Aug 4, 2026
32ac926
into
fix/strix-python-security-cves
26 of 28 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Migrate the write-capable scheduled OpenCode PR review-autofix worker from GitHub Models to the organization secret
NVIDIA_NIM_API_KEY, while preserving the existing read-only review agent's independent workflow, credential, and model-pool contract.This PR is intentionally stacked on #731 because #731 establishes the hourly scheduler cadence, one-hour same-head retry, immutable scheduler-source binding, dependency snapshots, and central security baseline.
Changes
nvidia-nimthrough OpenCode's OpenAI-compatible provider adapter;mistralai/mistral-nemotronas the primary repair model andnvidia/nemotron-3-nano-30b-a3bas the bounded helper model;NVIDIA_API_KEYfromsecrets.NVIDIA_NIM_API_KEYonly in the two OpenCode execution steps;USE_GITHUB_TOKENmodel-auth fallback from the scheduled autofix path;GITHUB_TOKENfrom the ordinary model step and launch both OpenCode child processes withGITHUB_TOKEN,GH_TOKEN,ACTIONS_ID_TOKEN_REQUEST_TOKEN, andACTIONS_ID_TOKEN_REQUEST_URLexplicitly unset;.github/workflows/opencode-review-dispatch.ymlbyte-for-byte so the existing independent reviewer-agent key system is not changed;TDD evidence
The test-only phase failed against the inherited GitHub Models configuration. The production phase then satisfied focused contracts for:
NVIDIA_NIM_API_KEYbindings;A deterministic GitHub-hosted one-shot verification executed the focused contracts and
git diff --checkbefore publishing the workflow update. The one-shot workflow removed itself, so the final PR contains exactly three reviewed files.Security and operational boundaries
Standards traceability
docs/doctoring/hourly-nvidia-nim-autofix.mdrecords the design and APA 7th references to GitHub's event/secret guidance, NVIDIA NIM API/model documentation, and OpenCode provider/permission documentation. The implementation applies those boundaries without claiming formal certification.Required before merge
main;mainwithout helper-workflow residue;