fix(clerk): reject a secret key containing a return character #27394
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # ReviewHog label trigger. | ||
|
Check warning on line 1 in .github/workflows/review-hog.yml
|
||
| # | ||
| # When the `reviewhog` label is added to a non-fork PR — by a maintainer, or by stamphog[bot] handing | ||
| # off a refused/escalated PR — this makes ONE authenticated call to the PostHog `review_hog` trigger | ||
| # endpoint, which starts the review Temporal workflow server-side and publishes the review back to the | ||
| # PR. One label add = one review: pushes and ready-for-review deliberately do NOT re-trigger — | ||
| # re-reviewing is an explicit gesture (remove and re-add the label), so a labeled PR can keep evolving | ||
| # without burning a review per event. Unlike Stamphog, the agent does NOT run in CI: there is no | ||
| # checkout, no app token, no Anthropic key here — the only secret is the shared trigger token. | ||
| # Publishing happens server-side via the PostHog GitHub App installation token. | ||
| # | ||
| # Safety: `pull_request_target` always runs the base branch's version of this file, so a PR cannot | ||
| # edit its own trigger, and it fires even when the PR has merge conflicts. It does expose secrets to | ||
| # fork PRs, so the `if:` hard-gates forks — safe because this job never checks out or runs PR code. | ||
| name: ReviewHog | ||
| # Sanctioned use — no job checks out or runs PR code; see the Safety note above. | ||
| # nosemgrep: github-actions-pull-request-target | ||
| on: | ||
| pull_request_target: | ||
| types: [labeled] | ||
| # No GitHub permissions by default — the trigger job only makes an outbound authenticated request; | ||
| # the review is fetched and published server-side via the PostHog GitHub App installation token. | ||
| permissions: {} | ||
| concurrency: | ||
| group: reviewhog-${{ github.event.pull_request.number }} | ||
| cancel-in-progress: true | ||
| jobs: | ||
| trigger: | ||
| name: Trigger ReviewHog review | ||
| runs-on: ubuntu-24.04 | ||
| timeout-minutes: 5 | ||
| # Run when the `reviewhog` label lands on a non-fork PR from an allowed labeler: a human, or | ||
| # stamphog[bot] handing off a refused/escalated PR. Other bots are skipped below. Any author | ||
| # (drafts and bots included); the label is the explicit review request. | ||
| if: >- | ||
| github.event.pull_request.head.repo.full_name == github.event.pull_request.base.repo.full_name | ||
| && github.event.label.name == 'reviewhog' | ||
| && (github.event.sender.type != 'Bot' || github.event.sender.login == 'stamphog[bot]') | ||
| steps: | ||
| - name: Trigger ReviewHog review | ||
| env: | ||
| REVIEWHOG_TRIGGER_TOKEN: ${{ secrets.REVIEWHOG_TRIGGER_TOKEN }} | ||
| ENDPOINT: ${{ vars.REVIEWHOG_ENDPOINT_URL || 'https://us.posthog.com/api/review_hog/trigger/' }} | ||
| REPO: ${{ github.repository }} | ||
| PR_NUMBER: ${{ github.event.pull_request.number }} | ||
| run: | | ||
| if [ -z "$REVIEWHOG_TRIGGER_TOKEN" ]; then | ||
| echo "::error::REVIEWHOG_TRIGGER_TOKEN secret is not set." >&2 | ||
| exit 1 | ||
| fi | ||
| payload="$(jq -n --arg repo "$REPO" --argjson pr "$PR_NUMBER" '{repo: $repo, pr_number: $pr}')" | ||
| # Retries are safe: the trigger dedups via Temporal USE_EXISTING, so a | ||
| # double-delivered trigger joins the in-flight review instead of starting another. | ||
| curl --fail-with-body --silent --show-error \ | ||
| --retry 3 --retry-delay 2 --max-time 30 --connect-timeout 10 \ | ||
| -X POST "$ENDPOINT" \ | ||
| -H "Authorization: Bearer $REVIEWHOG_TRIGGER_TOKEN" \ | ||
| -H "Content-Type: application/json" \ | ||
| -d "$payload" | ||
| # The trigger job skips bot-applied labels silently (stamphog[bot] excepted — it hands off | ||
| # refused PRs and is routed above); explain why and strip the label so a human can re-add it. | ||
| bot-labeler-skip: | ||
| name: Explain skipped bot label | ||
| runs-on: ubuntu-24.04 | ||
| timeout-minutes: 5 | ||
| permissions: | ||
| issues: write | ||
| if: >- | ||
| github.event.pull_request.head.repo.full_name == github.event.pull_request.base.repo.full_name | ||
| && github.event.sender.type == 'Bot' | ||
| && github.event.sender.login != 'stamphog[bot]' | ||
| && github.event.label.name == 'reviewhog' | ||
| steps: | ||
| - name: Comment and strip label | ||
| env: | ||
| GH_TOKEN: ${{ github.token }} | ||
| REPO: ${{ github.repository }} | ||
| PR_NUMBER: ${{ github.event.pull_request.number }} | ||
| run: | | ||
| set -euo pipefail | ||
| gh api -X POST "repos/$REPO/issues/$PR_NUMBER/comments" \ | ||
| -f body="ReviewHog reviews start only when a human adds the \`reviewhog\` label, so this bot-applied label was removed. Re-add it yourself to start a review." | ||
| gh api -X DELETE "repos/$REPO/issues/$PR_NUMBER/labels/reviewhog" | ||