From c198c4901e9047bc74f78e3d2d6ac38e51d5bade Mon Sep 17 00:00:00 2001 From: Pigbibi <20649888+Pigbibi@users.noreply.github.com> Date: Fri, 10 Jul 2026 20:19:31 +0800 Subject: [PATCH 1/2] chore(ci): harden Codex PR review gate Co-Authored-By: Codex --- .github/workflows/codex_pr_review.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codex_pr_review.yml b/.github/workflows/codex_pr_review.yml index 27351f6a..037717ea 100644 --- a/.github/workflows/codex_pr_review.yml +++ b/.github/workflows/codex_pr_review.yml @@ -1,7 +1,7 @@ name: Codex PR Review on: - pull_request: + pull_request_target: types: [opened, synchronize, reopened] permissions: @@ -19,7 +19,7 @@ jobs: uses: QuantStrategyLab/AIAuditBridge/.github/workflows/codex_pr_review.yml@main with: caller_concurrency_key: pr-${{ github.event.pull_request.number || github.run_id }} - allow_unconfigured_backend: true + allow_unconfigured_backend: false api_fallback_enabled: "false" direct_api_primary_enabled: "false" secrets: inherit From 0bd5cde70361176cb4c9b7885b83e68874b70c8d Mon Sep 17 00:00:00 2001 From: Pigbibi <20649888+Pigbibi@users.noreply.github.com> Date: Fri, 10 Jul 2026 21:04:08 +0800 Subject: [PATCH 2/2] fix(ci): minimize reusable review secrets Co-Authored-By: Codex --- .github/workflows/codex_pr_review.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/codex_pr_review.yml b/.github/workflows/codex_pr_review.yml index 037717ea..1a790a3e 100644 --- a/.github/workflows/codex_pr_review.yml +++ b/.github/workflows/codex_pr_review.yml @@ -22,7 +22,10 @@ jobs: allow_unconfigured_backend: false api_fallback_enabled: "false" direct_api_primary_enabled: "false" - secrets: inherit + # The centralized workflow is fail-closed and only needs the service URL. + # Do not expose unrelated repository or organization secrets to it. + secrets: + CODEX_AUDIT_SERVICE_URL: ${{ secrets.CODEX_AUDIT_SERVICE_URL }} permissions: contents: read id-token: write