Pinned Forgejo Action that publishes OIDC-bound pull request reviews.
This repository has been archived on 2026-09-05. You can view files and clone it, but you cannot make any changes to its state, such as pushing and creating new issues, pull requests or comments.
  • TypeScript 100%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-08-16 17:17:09 +02:00
test fix: bind reviews to the PR merge base (#4) 2026-08-16 07:32:45 +00:00
.gitignore feat: add Forgejo review writer action (#1) 2026-08-02 09:13:22 +00:00
.oxfmtrc.json feat: add Forgejo review writer action (#1) 2026-08-02 09:13:22 +00:00
action.yml feat: bind reviews to stacked PR bases (#3) 2026-08-14 16:21:14 +00:00
forgejo-post-review-capability.ts feat: add Forgejo review writer action (#1) 2026-08-02 09:13:22 +00:00
forgejo-post-review-comments.ts feat: add Forgejo review writer action (#1) 2026-08-02 09:13:22 +00:00
forgejo-post-review-common.ts fix: bind reviews to the PR merge base (#4) 2026-08-16 07:32:45 +00:00
forgejo-post-review-diff.ts feat: add Forgejo review writer action (#1) 2026-08-02 09:13:22 +00:00
forgejo-post-review-envelope.ts fix: bind reviews to the PR merge base (#4) 2026-08-16 07:32:45 +00:00
forgejo-post-review-http.ts feat: add Forgejo review writer action (#1) 2026-08-02 09:13:22 +00:00
forgejo-post-review-input.ts fix: bind reviews to the PR merge base (#4) 2026-08-16 07:32:45 +00:00
forgejo-post-review-pending.ts feat: bind reviews to stacked PR bases (#3) 2026-08-14 16:21:14 +00:00
forgejo-post-review-pr.ts fix: bind reviews to the PR merge base (#4) 2026-08-16 07:32:45 +00:00
forgejo-post-review-receipt.ts fix: bind reviews to the PR merge base (#4) 2026-08-16 07:32:45 +00:00
forgejo-post-review-result.ts feat: bind reviews to stacked PR bases (#3) 2026-08-14 16:21:14 +00:00
knip.json feat: add Forgejo review writer action (#1) 2026-08-02 09:13:22 +00:00
LICENSE Initial commit 2026-08-02 08:57:13 +00:00
oxlint.config.ts feat: add Forgejo review writer action (#1) 2026-08-02 09:13:22 +00:00
package.json chore: bump pnpm to 11.22.0 2026-08-16 17:17:09 +02:00
pnpm-lock.yaml feat: bind reviews to stacked PR bases (#3) 2026-08-14 16:21:14 +00:00
post-review.ts feat: bind reviews to stacked PR bases (#3) 2026-08-14 16:21:14 +00:00
README.md fix: bind reviews to the PR merge base (#4) 2026-08-16 07:32:45 +00:00
tsconfig.json feat: add Forgejo review writer action (#1) 2026-08-02 09:13:22 +00:00

Forgejo review writer

forgejo-review-writer is a dependency-free composite action that posts an OIDC-bound, Axrecipe-finalized pull-request review to Forgejo. It is designed for trusted pull_request_target posting jobs and runs directly with Node 24+ native TypeScript support. It never installs runtime dependencies.

Use a full commit SHA, never a branch or tag:

- uses: https://code.j4k.dev/j4k-oss/forgejo-review-writer@<full-commit-sha>
  with:
    axrecipe-url: https://recipe.axkit.dev
    axrecipe-audience: https://recipe.axkit.dev/forgejo-actions
    forgejo-token: ${{ secrets.FORGEJO_TOKEN }}
    review-slot: forgejo-review-code-smart-1
    review-repository: ${{ github.repository }}
    review-pull-request-binding: ${{ inputs.review-pull-request-binding }}
    source-workflow-run-id: ${{ inputs.source-workflow-run-id }}
    source-generator-attempt: ${{ inputs.source-generator-attempt }}

review-pull-request-binding is one strict JSON object with number, headSha, headRef, headRepository, baseRef, and mergeBaseSha. The calling job must have Node 24+ available and Forgejo must advertise the actions-reviewer-isolation capability. The writer accepts only an open, same-repository PR whose live base ref, merge-base SHA, head SHA, head ref, and head repository exactly match the supplied values. This includes main and same-repository stacked PR bases. It checks that binding before OIDC minting, before cleanup, and immediately before publication.

The action exact-pins its Axrecipe URL and audience, binds the finalized result to the repository ID, PR, base, head, review slot, source workflow run, and generator attempt, and emits an exact publication receipt. It accepts an existing receipt only from Forgejo's isolated Actions actor, so another workflow cannot forge idempotency. It performs bounded HTTP reads, refuses stale result windows, filters inline comments to the current diff, and removes only its own pending reviews after verifying the isolated actor.

The Axrecipe result read and result envelope must also require baseRef and mergeBaseSha; the writer uses receipt schema v2 and does not accept prior receipts.

The action is intentionally scoped to the current Axrecipe Forgejo integration. Other Axrecipe deployments require a separately built and reviewed action so an untrusted caller cannot redirect its OIDC token.

Development

pnpm install --frozen-lockfile
pnpm run format:check
pnpm run typecheck
pnpm run lint
pnpm run fta
pnpm run knip
pnpm test

MIT licensed. See LICENSE.