Documentation
Govern pull requests with GitHub Actions
A workflow that sends the files changed in a pull request, or in a push to main / master, to Ovyero and reports a PASS, WARN or GATE verdict for each file. GATE is the blocking verdict.
Set up
- Add the workflow file to your repository:
mkdir -p .github/workflows curl -fsSL https://ovyero.visnryentertainment.com/install/ovyero.yml -o .github/workflows/ovyero.yml
- In the repository, open Settings → Secrets and variables → Actions → New repository secret. Name it
OVYERO_API_KEYand paste your Ovyero API key. A secret namedAIOS_API_KEYfrom an earlier install keeps working. - Pin the runner. Read the runner script, then add a repository Variable (same Settings page, Variables tab) named
OVYERO_RUNNER_SHA256holding its SHA-256:curl -fsSL https://ovyero.visnryentertainment.com/gha-runner.js | sha256sum
The same value is published asscript_sha256athttps://ovyero.visnryentertainment.com/gha-runner/version. The workflow checks the downloaded runner against this value before running it, and the job fails until the variable is set. - Commit the file. The job Govern changed files runs on every pull request and on pushes to
mainandmaster.
Block merges on a GATE
By default the workflow reports only. To fail the job when a file is gated, add a repository Variable (same Settings page, Variables tab) named OVYERO_FAIL_ON_GATE with the value true. AIOS_FAIL_ON_GATE is honoured too. Then require the job in your branch protection rules.
Settings in the workflow file
| Line | What it does |
|---|---|
INPUT_GOVERNANCE-PROFILE | production (default, strictest), library, mixed, knowledge_base, data_extraction, local_tooling or test_harness. An unknown name falls back to production. |
INPUT_COMMENT-MODE | comment posts the verdict table on the pull request; summary writes the job summary only. |
INPUT_MAX-FILES | Most files reviewed in one run. The served workflow sets 200. |
Limits
- When the runner is updated its SHA-256 changes, so the pinned job fails at the digest check until you review the new runner and update
OVYERO_RUNNER_SHA256. - If some changed files could not be reviewed, the job fails rather than report a clean pass (runner input
fail-on-unverified, defaulttrue). - The workflow needs
contents: readandpull-requests: write(already set in the file) to post the comment. - File contents are sent for analysis and are not stored; see Privacy.
Something not working? See Troubleshooting.