Releases: twoimo/codex-meter
Release list
codex-meter v0.1.3
Ships the opt-in label gate and the maintenance work that landed after 0.1.2.
New: requireLabel. When set, only pull requests carrying that label are reviewed; everything else is skipped as label-missing with an actionable reason and no comment. Off by default (requireLabel: null), so existing behaviour is unchanged. The skip label still wins over the opt-in label. Gate order is label-skip then label-missing then fork-pr.
Changed. GitHub Action and CI use actions/checkout@v7 and actions/setup-node@v7. The action-manifest test accepts any actions/setup-node@vN major, so Dependabot bumps no longer fail a hardcoded pin. Dev toolchain is TypeScript 7 and @types/node 26; the committed dist/ was rebuilt to match. Dependabot weekly grouped npm updates and monthly action updates are on, and the release procedure lives in AGENTS.md.
70 tests passing. Use twoimo/codex-meter@v1 to track the major release.
codex-meter v0.1.2
Adds two features and closes the loop on a review of the first of them.
New: bot-author gate. Pull requests authored by automation are skipped before any spend, with skipBotAuthors: false to opt out. Detection is deliberately narrow after review feedback: GitHub's [bot] convention, app/<slug> identities, and a short list of known automation accounts. A generic -bot suffix rule was removed because a human can own a handle like some-bot, and silently skipping a human contribution is worse than reviewing one bot pull request. Gate precedence (draft -> bot-author -> label-skip -> fork-pr) is pinned by a test that stacks every condition on one pull request.
New: custom Codex providers. A provider block points a review at an OpenAI-compatible gateway instead of OpenAI itself:
{
"provider": {
"name": "gateway",
"baseUrl": "https://gateway.example/v1",
"envKey": "GATEWAY_KEY",
"wireApi": "responses",
"model": "my-codex-model"
}
}The OpenAI login is skipped, the provider settings are passed as explicit -c model_providers... overrides, and the provider's environment variable counts as the credential. wireApi defaults to responses because current Codex CLI versions reject wire_api = "chat"; dollar budgets stay disabled without a price entry, leaving token budgets as the control for subscription gateways. The README also records why gateways that route per client (OpenCode Go requires an x-opencode-session header) cannot back a run at all.
68 tests passing. Use twoimo/codex-meter@v1 to track the major release.
codex-meter v0.1.1
Makes the action actually usable. Found by dogfooding: the released v0.1.0 action never loaded.
- Fix: the unquoted colon in the action description made GitHub reject the manifest ("Mapping values are not allowed in this context"), failing the job before any review ran.
- Fix: the action now passes a GitHub token explicitly (
github-tokeninput, defaults to the workflow token), so the review comment is actually posted. Previously the comment was silently skipped. - Fix: the CLI logs the resolved GitHub context and reports
comment: created|updated, or a warning namingpull-requests: writeas the likely cause. A refused comment no longer looks like a review that never ran. - New:
run-tokensinput, so repositories with large diffs can raise the per-review ceiling instead of being skipped by the default. - New: manifest validation in CI (
test/action-manifest.test.ts) covering the action and both workflow files, plus stderr-noise filtering and theorigin/prefix stripped from the displayed base ref.
60 tests passing. Use twoimo/codex-meter@v1 to track the major release.
codex-meter v0.1.0
First release.
- Ordered policy gates that run before any Codex call: drafts, labelled PRs, fork PRs, docs-only diffs, lockfiles and generated files, oversized diffs, already-reviewed commits.
- Monthly token and dollar budgets plus a per-run cap, enforced before the call and recorded in an append-only ledger.
- Real turn.completed usage parsed and priced from a published price table, with the source and retrieval date recorded in src/pricing.ts.
- One upserted pull request comment carrying the findings and the spend that produced them.
- codex-meter explain (decide without spending), review, and report (spend, skips, cache reuse).
- Zero runtime dependencies, 56 tests, and integration tests that replay a recorded Codex session.