github Factory-AI/droid-action v10

3 hours ago

What's Changed

Security fix: long GitHub App tokens are fully redacted

  • ghs_ installation tokens in GitHub's new long format are now fully redacted in action output (#160)
    • The old pattern only matched 36-character alphanumeric tokens. A ~520-character token was left unredacted, or only its first 40 characters were masked if it contained . or -
    • Redaction now uses GitHub's recommended pattern, ghs_[A-Za-z0-9._-]{36,}. Other token types are unchanged

Deep preset runs at medium reasoning effort

  • review_depth: deep now uses medium reasoning effort instead of high (#149)
    • The model is unchanged (openai-latest-balanced). medium is the model's default effort and uses fewer output tokens per review
    • This applies to every workflow that doesn't set reasoning_effort: code review candidates, the validator, dedicated security reviews, and GitLab reviews. Subagents spawned during a review inherit it
    • To keep the previous behavior, set reasoning_effort: high

Review session tag records security review

  • The code-review session tag now carries securityReview: "true" | "false" on both passes of a code review, on GitHub and GitLab (#149)
    • This lets analytics split code review and security review spend without parsing prompt text. Dedicated security reviews (reviewType: "security") omit it

Docs

  • The GitHub auto-review example sets allowed_bots: factory-droid, so runs triggered by Factory Droid are allowed. The action-wide default is unchanged (#152)
  • The README now explains that security review reads .factory/skills/security-review-guidelines/SKILL.md, not review-guidelines (#159)

Full Changelog: v9...v10

Don't miss a new droid-action release

NewReleases is sending notifications on new releases.