- pr-queue-worker.py: cron orchestrator (review trigger → AI fix → safety → CI gate → approve/merge) now versioned in-repo - TOOLCHAIN_PINS: close dependabot PRs bumping pinned majors (typescript/eslint/@tsparticles/eslint-config-next/eslint-plugin-react) - STALE_CI_CLOSE_DAYS=2: close dependabot PRs stuck failing CI - Secrets externalized to env (PR_AGENT_*), hydrated from ~/.hermes/.env — file is safe for the public repo; no inline secrets
1.7 KiB
1.7 KiB
PR Queue Worker
pr-queue-worker.py — the orchestration cron that watches open PRs across all
repos where the PR-Agent GitHub App is installed and drives the full lifecycle:
- Open PR found → ensure a PR-Agent review exists (fabricates a webhook to
pr-agent.asepharyana.my.idif not) - Toolchain pin guard → closes dependabot PRs that bump pinned toolchain
majors (see
TOOLCHAIN_PINSmap — typescript/eslint/@tsparticles/…) instead of waiting on them forever - AI auto-fix → runs Claude Code (
-p) on the PR head for up toAI_FIX_MAX_TURNSturns, then pushes the fix - Safety analysis → parses the review body for security/major-issue blockers; score must be ≥ 6/10
- CI gate → waits for the required check to pass (closes stale dependabot
PRs stuck failing CI for >
STALE_CI_CLOSE_DAYS) - Approve + merge
Deployment
- Cron: Hermes cron job
04f13b9fdadc, every 5 minutes - Live path:
~/.hermes/scripts/pr-queue-worker.py(cron reads this file — keep it in sync with this repo copy) - Secrets: NOT in this file. Hydrated at import from
~/.hermes/.env(PR_AGENT_APP_ID,PR_AGENT_KEY_PATH,PR_AGENT_WEBHOOK_SECRET,PR_AGENT_WEBHOOK_URL). The GitHub App private key lives at~/.hermes/keys/pr-agent-key.pem(gitignored, never commit).
Sync note
This repo is the canonical version. The live cron copy under ~/.hermes/scripts/
is what actually runs — after editing here, cp scripts/pr-queue-worker.py ~/.hermes/scripts/pr-queue-worker.py and verify with:
/home/code/hermes-agent/.venv/bin/python3 -m py_compile ~/.hermes/scripts/pr-queue-worker.py
timeout 90 /home/code/hermes-agent/.venv/bin/python3 ~/.hermes/scripts/pr-queue-worker.py