Ovyero
Documentation

Govern pull requests with GitHub Actions

A workflow that sends the files changed in a pull request, or in a push to main / master, to Ovyero and reports a PASS, WARN or GATE verdict for each file. GATE is the blocking verdict.

Set up

  1. Add the workflow file to your repository:
    mkdir -p .github/workflows
    curl -fsSL https://ovyero.visnryentertainment.com/install/ovyero.yml -o .github/workflows/ovyero.yml
  2. In the repository, open Settings → Secrets and variables → Actions → New repository secret. Name it OVYERO_API_KEY and paste your Ovyero API key. A secret named AIOS_API_KEY from an earlier install keeps working.
  3. Pin the runner. Read the runner script, then add a repository Variable (same Settings page, Variables tab) named OVYERO_RUNNER_SHA256 holding its SHA-256:
    curl -fsSL https://ovyero.visnryentertainment.com/gha-runner.js | sha256sum
    The same value is published as script_sha256 at https://ovyero.visnryentertainment.com/gha-runner/version. The workflow checks the downloaded runner against this value before running it, and the job fails until the variable is set.
  4. Commit the file. The job Govern changed files runs on every pull request and on pushes to main and master.

Block merges on a GATE

By default the workflow reports only. To fail the job when a file is gated, add a repository Variable (same Settings page, Variables tab) named OVYERO_FAIL_ON_GATE with the value true. AIOS_FAIL_ON_GATE is honoured too. Then require the job in your branch protection rules.

Settings in the workflow file

LineWhat it does
INPUT_GOVERNANCE-PROFILEproduction (default, strictest), library, mixed, knowledge_base, data_extraction, local_tooling or test_harness. An unknown name falls back to production.
INPUT_COMMENT-MODEcomment posts the verdict table on the pull request; summary writes the job summary only.
INPUT_MAX-FILESMost files reviewed in one run. The served workflow sets 200.

Limits

Something not working? See Troubleshooting.

TroubleshootingContactTrust