Skip to content

Publish the ReviewBench image to GHCR and rename to review - #2

Merged
joahg merged 4 commits into
mainfrom
publish-ghcr-image
Oct 9, 2026
Merged

joahg merged 4 commits into
mainfrom
publish-ghcr-image

Conversation

@joahg

@joahg joahg commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Publishes the ReviewBench image to ghcr.io/block/review, renames the project from review-panel to review to match the repository, and adds CI.

  • .github/workflows/publish-image.yml builds linux/amd64 from the Dockerfile on v* tag pushes or a manual run. It pushes ghcr.io/block/review:<tag> and :sha-<commit> with the built-in GITHUB_TOKEN (packages: write) and writes the immutable ghcr.io/block/review@sha256:… reference to the job summary, since ReviewBench registers images by digest. Actions are pinned to commit SHAs, and context values reach the shell through env.
  • Rename: the module is github.com/block/review, the command is cmd/review, the binary and the default ReviewBench agent name are review, and environment overrides use the REVIEW_ prefix (for example REVIEW_BUDGET, REVIEW_GOOSE_BIN).
  • .github/workflows/ci.yml checks formatting, vets, tests, and builds the image on every pull request and push to main.

joahg added 2 commits October 9, 2026 17:16
Build the linux/amd64 image on tag pushes or manual runs, push it to
ghcr.io/block/review, and print the immutable digest in the job
summary for registering with ReviewBench.
The repository was renamed, so go install and imports must use the new path.
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread .github/workflows/publish-image.yml Fixed
joahg added 2 commits October 9, 2026 17:21
Match the repository name: the command is now cmd/review, the binary and
default ReviewBench agent name are review, and environment overrides use
the REVIEW_ prefix. Add CI that checks formatting, vets, tests, and builds
the image on every pull request.
Interpolating context values into run scripts is a shell injection risk.
@joahg
joahg marked this pull request as ready for review October 9, 2026 22:26
@joahg joahg changed the title Publish the ReviewBench image to GHCR Publish the ReviewBench image to GHCR and rename to review Oct 9, 2026
@joahg
joahg merged commit 6cddea4 into main Oct 9, 2026
5 checks passed
@joahg
joahg deleted the publish-ghcr-image branch October 9, 2026 22:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants