Skip to content

[Docs] Explain tool policy changes for running tasks #209

[Docs] Explain tool policy changes for running tasks

[Docs] Explain tool policy changes for running tasks #209

Workflow file for this run

name: Judgement

Check warning on line 1 in .github/workflows/judgement.yml

View workflow run for this annotation

GitHub Actions / Judgement

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
on:
pull_request_target:
branches: [main, develop]
types: [opened, synchronize, reopened, ready_for_review, edited]
permissions: {}
concurrency:
group: judgement-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
pending:
name: Mark Judgement pending
runs-on: ubuntu-24.04
permissions:
statuses: write
steps:
- name: Mark the PR check pending
env:
GH_TOKEN: ${{ github.token }}
PR_HEAD: ${{ github.event.pull_request.head.sha }}
run: |
gh api --silent "repos/$GITHUB_REPOSITORY/statuses/$PR_HEAD" \
-f state=pending -f context=Judgement \
-f description='Checking repository rules' \
-f target_url="$GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID"
collect:
name: Collect Git evidence
needs: pending
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: read
outputs:
base: ${{ steps.export.outputs.base }}
env:
PR_HEAD: ${{ github.event.pull_request.head.sha }}
PR_BASE: ${{ github.event.pull_request.base.sha }}
steps:
# This job has no inference secret or repository write permission.
- name: Checkout trusted base
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
with:
ref: ${{ github.event.pull_request.base.sha }}
fetch-depth: 0
persist-credentials: false
- name: Export snapshot objects
id: export
run: |
set -euo pipefail
[[ "$PR_HEAD" =~ ^[0-9a-f]{40}$ && "$PR_BASE" =~ ^[0-9a-f]{40}$ ]]
git fetch --no-tags origin "$PR_HEAD"
base="$(git merge-base "$PR_BASE" "$PR_HEAD")"
git cat-file -e "$base:.judgement/rules.json"
mkdir -p "$RUNNER_TEMP/judgement-evidence"
# Transfer objects only: no worktree, Git config, hooks, or full history.
{
printf '%s\n' "$base" "$PR_HEAD"
git rev-list --objects --no-object-names "$base^{tree}" "$PR_HEAD^{tree}"
} | sort -u | git pack-objects --stdout > "$RUNNER_TEMP/judgement-evidence/objects.pack"
echo "base=$base" >> "$GITHUB_OUTPUT"
- name: Upload snapshot objects
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: judgement-evidence
path: ${{ runner.temp }}/judgement-evidence/objects.pack
if-no-files-found: error
retention-days: 1
compression-level: 0
judgement:
name: Judge Git evidence
needs: collect
outputs:
coverage: ${{ steps.check.outputs.coverage }}
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions: {}
env:
PR_HEAD: ${{ github.event.pull_request.head.sha }}
JUDGEMENT_BASE: ${{ needs.collect.outputs.base }}
steps:
# No repository checkout in this job. The checker is installed separately.
- name: Set up Node
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
with:
node-version: '24.13.1'
- name: Install trusted checker
run: |
mkdir -p "$RUNNER_TEMP/judgement-tool"
cd "$RUNNER_TEMP/judgement-tool"
npm install --ignore-scripts --no-audit --no-fund \
'@roo-code/judgement@0.4.1'
- name: Download snapshot objects
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
name: judgement-evidence
path: ${{ runner.temp }}/judgement-evidence
- name: Import snapshot objects without checkout
id: import
run: |
set -euo pipefail
[[ "$PR_HEAD" =~ ^[0-9a-f]{40}$ && "$JUDGEMENT_BASE" =~ ^[0-9a-f]{40}$ ]]
git init --quiet --template= "$RUNNER_TEMP/judgement-input"
cd "$RUNNER_TEMP/judgement-input"
git index-pack --stdin < "$RUNNER_TEMP/judgement-evidence/objects.pack"
git cat-file -e "$JUDGEMENT_BASE^{commit}"
git cat-file -e "$PR_HEAD^{commit}"
git cat-file -e "$JUDGEMENT_BASE:.judgement/rules.json"
git update-ref refs/heads/evidence "$JUDGEMENT_BASE"
git symbolic-ref HEAD refs/heads/evidence
- name: Check repository rules
id: check
env:
TYPESAFE_API_KEY: ${{ secrets.TYPESAFE_API_KEY }}
JUDGEMENT_MODEL: ${{ vars.JUDGEMENT_MODEL || 'jev-1.13.0' }}
run: |
set -euo pipefail
if [ -z "$TYPESAFE_API_KEY" ]; then
echo 'Configure the TYPESAFE_API_KEY repository secret for Judgement.' >&2
exit 2
fi
result=0
node "$RUNNER_TEMP/judgement-tool/node_modules/@roo-code/judgement/src/cli.js" \
check --cwd "$RUNNER_TEMP/judgement-input" \
--base "$JUDGEMENT_BASE" --head "$PR_HEAD" \
--model "$JUDGEMENT_MODEL" --timeout-ms 120000 --no-cache || result=$?
case "$result" in
0) echo 'coverage=complete' >> "$GITHUB_OUTPUT" ;;
3)
# All incomplete results are non-blocking, including evidence or
# inference failures caught by the checker. Confirmed violations
# take precedence and exit 1, even with partial coverage.
echo 'coverage=incomplete' >> "$GITHUB_OUTPUT"
echo '::warning::Judgement found no violations, but coverage is incomplete. See the check log.'
echo 'Judgement found no violations, but coverage is incomplete. See the check log for unresolved rules.' >> "$GITHUB_STEP_SUMMARY"
;;
*) exit "$result" ;;
esac
report:
name: Publish Judgement result
needs: [pending, collect, judgement]
if: ${{ always() && !cancelled() && needs.pending.result == 'success' }}
runs-on: ubuntu-24.04
permissions:
statuses: write
steps:
# This job receives only the conclusion and coverage flag, never repository contents or secrets.
- name: Publish result
env:
GH_TOKEN: ${{ github.token }}
PR_HEAD: ${{ github.event.pull_request.head.sha }}
CHECK_OUTCOME: ${{ needs.judgement.result }}
CHECK_COVERAGE: ${{ needs.judgement.outputs.coverage }}
run: |
state=failure
description='Judgement failed or did not complete; inspect the run'
if [ "$CHECK_OUTCOME" = success ]; then
state=success
description='Repository rule check completed without findings'
if [ "$CHECK_COVERAGE" = incomplete ]; then
description='No rule violations found; coverage incomplete (see run)'
fi
fi
gh api --silent "repos/$GITHUB_REPOSITORY/statuses/$PR_HEAD" \
-f state="$state" -f context=Judgement -f description="$description" \
-f target_url="$GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID"