Skip to content

chore: add Pullfrog workflow file - #442

Closed
pullfrog[bot] wants to merge 1 commit into
mainfrom
pullfrog/add-workflow-1790864383057
Closed

pullfrog[bot] wants to merge 1 commit into
mainfrom
pullfrog/add-workflow-1790864383057

Conversation

@pullfrog

@pullfrog pullfrog Bot commented Oct 1, 2026

Copy link
Copy Markdown

This PR adds the .github/workflows/pullfrog.yml workflow file to enable Pullfrog agent runs in this repository.

Once merged, return to the Pullfrog console and click Verify workflow to finish setup.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: fabiodalez-dev/Pinakes/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 29da2969-5450-42a2-b4c2-1e288c5b13af

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@fabiodalez-dev

Copy link
Copy Markdown
Owner

Closing in favour of #443, which adds the same workflow file hardened.

#443 keeps everything this PR sets up and changes four things I am not willing to ship without:

  • pullfrog/pullfrog@v0 is a tag that moves — it has already advanced through ninety v0.1.x releases. This is the one action in the repository that runs an agent with access to the code, so it is pinned to a commit SHA. Nothing is lost: the action fetches its steps from npm either way, so the agent still tracks patch releases without this file changing.
  • push defaults to enabled, which lets the agent push branches and open pull requests. Every commit here is authored by me, so the agent is review-only: push: disabled.
  • actions/checkout defaults to persist-credentials: true, which leaves the job GITHUB_TOKEN in .git/config — a working push credential inside the very checkout the agent operates on, which contradicts push: disabled. This repository own CI policy check refuses it, and it was right to.
  • shell: restricted is set explicitly so that making this repository private some day cannot silently widen it, since private repos default to enabled.

It also passes the Workflow, YAML and shell security gate, which this file as generated does not: zizmor at the pedantic persona wants the id-token: write permission documented and a concurrency group, the job needs a name, and two lines carry trailing whitespace that yamllint rejects.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant