Repository navigation
What's Changed
Security fix: long GitHub App tokens are fully redacted
ghs_installation tokens in GitHub's new long format are now fully redacted in action output (#160)- The old pattern only matched 36-character alphanumeric tokens. A ~520-character token was left unredacted, or only its first 40 characters were masked if it contained
.or- - Redaction now uses GitHub's recommended pattern,
ghs_[A-Za-z0-9._-]{36,}. Other token types are unchanged
- The old pattern only matched 36-character alphanumeric tokens. A ~520-character token was left unredacted, or only its first 40 characters were masked if it contained
Deep preset runs at medium reasoning effort
review_depth: deepnow usesmediumreasoning effort instead ofhigh(#149)- The model is unchanged (
openai-latest-balanced).mediumis the model's default effort and uses fewer output tokens per review - This applies to every workflow that doesn't set
reasoning_effort: code review candidates, the validator, dedicated security reviews, and GitLab reviews. Subagents spawned during a review inherit it - To keep the previous behavior, set
reasoning_effort: high
- The model is unchanged (
Review session tag records security review
- The
code-reviewsession tag now carriessecurityReview: "true" | "false"on both passes of a code review, on GitHub and GitLab (#149)- This lets analytics split code review and security review spend without parsing prompt text. Dedicated security reviews (
reviewType: "security") omit it
- This lets analytics split code review and security review spend without parsing prompt text. Dedicated security reviews (
Docs
- The GitHub auto-review example sets
allowed_bots: factory-droid, so runs triggered by Factory Droid are allowed. The action-wide default is unchanged (#152) - The README now explains that security review reads
.factory/skills/security-review-guidelines/SKILL.md, notreview-guidelines(#159)
Full Changelog: v9...v10