Skip to content

fix(clerk): reject a secret key containing a return character #27394

fix(clerk): reject a secret key containing a return character

fix(clerk): reject a secret key containing a return character #27394

Workflow file for this run

# ReviewHog label trigger.

Check warning on line 1 in .github/workflows/review-hog.yml

View workflow run for this annotation

GitHub Actions / ReviewHog

Workflow execution policy warning (evaluate mode)

On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
#
# When the `reviewhog` label is added to a non-fork PR — by a maintainer, or by stamphog[bot] handing
# off a refused/escalated PR — this makes ONE authenticated call to the PostHog `review_hog` trigger
# endpoint, which starts the review Temporal workflow server-side and publishes the review back to the
# PR. One label add = one review: pushes and ready-for-review deliberately do NOT re-trigger —
# re-reviewing is an explicit gesture (remove and re-add the label), so a labeled PR can keep evolving
# without burning a review per event. Unlike Stamphog, the agent does NOT run in CI: there is no
# checkout, no app token, no Anthropic key here — the only secret is the shared trigger token.
# Publishing happens server-side via the PostHog GitHub App installation token.
#
# Safety: `pull_request_target` always runs the base branch's version of this file, so a PR cannot
# edit its own trigger, and it fires even when the PR has merge conflicts. It does expose secrets to
# fork PRs, so the `if:` hard-gates forks — safe because this job never checks out or runs PR code.
name: ReviewHog
# Sanctioned use — no job checks out or runs PR code; see the Safety note above.
# nosemgrep: github-actions-pull-request-target
on:
pull_request_target:
types: [labeled]
# No GitHub permissions by default — the trigger job only makes an outbound authenticated request;
# the review is fetched and published server-side via the PostHog GitHub App installation token.
permissions: {}
concurrency:
group: reviewhog-${{ github.event.pull_request.number }}
cancel-in-progress: true
jobs:
trigger:
name: Trigger ReviewHog review
runs-on: ubuntu-24.04
timeout-minutes: 5
# Run when the `reviewhog` label lands on a non-fork PR from an allowed labeler: a human, or
# stamphog[bot] handing off a refused/escalated PR. Other bots are skipped below. Any author
# (drafts and bots included); the label is the explicit review request.
if: >-
github.event.pull_request.head.repo.full_name == github.event.pull_request.base.repo.full_name
&& github.event.label.name == 'reviewhog'
&& (github.event.sender.type != 'Bot' || github.event.sender.login == 'stamphog[bot]')
steps:
- name: Trigger ReviewHog review
env:
REVIEWHOG_TRIGGER_TOKEN: ${{ secrets.REVIEWHOG_TRIGGER_TOKEN }}
ENDPOINT: ${{ vars.REVIEWHOG_ENDPOINT_URL || 'https://us.posthog.com/api/review_hog/trigger/' }}
REPO: ${{ github.repository }}
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
if [ -z "$REVIEWHOG_TRIGGER_TOKEN" ]; then
echo "::error::REVIEWHOG_TRIGGER_TOKEN secret is not set." >&2
exit 1
fi
payload="$(jq -n --arg repo "$REPO" --argjson pr "$PR_NUMBER" '{repo: $repo, pr_number: $pr}')"
# Retries are safe: the trigger dedups via Temporal USE_EXISTING, so a
# double-delivered trigger joins the in-flight review instead of starting another.
curl --fail-with-body --silent --show-error \
--retry 3 --retry-delay 2 --max-time 30 --connect-timeout 10 \
-X POST "$ENDPOINT" \
-H "Authorization: Bearer $REVIEWHOG_TRIGGER_TOKEN" \
-H "Content-Type: application/json" \
-d "$payload"
# The trigger job skips bot-applied labels silently (stamphog[bot] excepted — it hands off
# refused PRs and is routed above); explain why and strip the label so a human can re-add it.
bot-labeler-skip:
name: Explain skipped bot label
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
issues: write
if: >-
github.event.pull_request.head.repo.full_name == github.event.pull_request.base.repo.full_name
&& github.event.sender.type == 'Bot'
&& github.event.sender.login != 'stamphog[bot]'
&& github.event.label.name == 'reviewhog'
steps:
- name: Comment and strip label
env:
GH_TOKEN: ${{ github.token }}
REPO: ${{ github.repository }}
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
set -euo pipefail
gh api -X POST "repos/$REPO/issues/$PR_NUMBER/comments" \
-f body="ReviewHog reviews start only when a human adds the \`reviewhog\` label, so this bot-applied label was removed. Re-add it yourself to start a review."
gh api -X DELETE "repos/$REPO/issues/$PR_NUMBER/labels/reviewhog"