mirror of
https://github.com/Tencent/teamai-cli.git
synced 2026-10-02 03:14:40 +08:00
The pull_request trigger never receives secrets on fork PRs, so the Codex review silently no-op'd for external contributions (the majority of PRs). Switch to pull_request_target so fork PRs can access the API key, and add the safeguards that trigger requires: - A maintainer gate job: only a user with write/admin/maintain permission can trigger the review; unauthorized assigns skip it. This stops strangers from burning the API budget or exercising the token. - Check out the trusted BASE commit, never the PR head. The PR changes are exposed to Codex only through git diff — read as passive data, never built, installed, or executed (npm install alone would run a fork's pre/postinstall hooks). - Review rules come from the base AGENTS.md, so a PR cannot rewrite its own criteria. - persist-credentials: false keeps the repo token off disk. Codex stays read-only throughout.