Files
opencode-mobile/.github/workflows/triage-reviews.yml
Den 142518866b fix(metrics): repair review triage — correct secret wiring, privacy-safe aggregated issues. Closes #61. Refs #60. (#78)
* fix(metrics): repair review triage — correct secret wiring, privacy-safe aggregated issues

- triage-reviews.yml read secrets.GOOGLE_SERVICE_ACCOUNT_JSON, which doesn't
  exist; map the real PLAY_STORE_SERVICE_ACCOUNT_JSON secret onto the env var
  the script expects.
- triage-reviews.py rewritten to maintain a single sanitized, deduped
  "Play Store Review Triage" issue instead of one public issue per review.
  The old version leaked reviewer full names and verbatim review text into
  public GitHub issues and spammed the tracker. The new version aggregates
  actionable (<=3 star) reviews into one issue with rating counts, a
  word-frequency theme summary (no quoted sentences), and opaque review_id
  references for Play Console lookup. An embedded HTML comment marker
  (matching the product-intelligence.mjs pattern) holds the current
  actionable review_id set so runs update in place and skip entirely when
  nothing changed.
- product-intelligence.yml referenced the nonexistent
  SENTRY_PRODUCT_INTELLIGENCE_TOKEN secret, causing the daily cron to fail
  silently (#60). Fall back to SENTRY_AUTH_TOKEN when the dedicated
  read-only token isn't configured.
- docs/playstore.md: document that Play Console is still the only trusted
  source for acquisition/uninstall metrics (product-intelligence.mjs defers
  this), and that review-based signals are sourced via the Android
  Publisher API through PLAY_STORE_SERVICE_ACCOUNT_JSON.

Closes #61. Refs #60.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NJKAQ6HAikWGQK7PGZ5Y4E

* fix(triage): fail visibly when GOOGLE_SERVICE_ACCOUNT_JSON is missing

Review finding on PR #78: env_client() exited 0 on missing credentials,
so the scheduled workflow would report success while silently doing
nothing — contradicting issue #61's 'missing credentials fail visibly'
done-criteria.

---------

Co-authored-by: engineer <engineer@gray-knight-m1.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 18:00:41 -07:00

38 lines
1.0 KiB
YAML

name: Play Store Review Triage
on:
workflow_dispatch:
schedule:
# 07:00 UTC daily (staggered after Daily Product Intelligence at 06:00 UTC)
- cron: "0 7 * * *"
permissions:
contents: read
issues: write
concurrency:
group: triage-reviews-${{ github.ref }}
cancel-in-progress: false
jobs:
triage:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v6
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Install dependencies
run: pip install google-auth google-auth-httplib2 google-api-python-client
- name: Triage Play Store reviews
env:
# Repo secret is named PLAY_STORE_SERVICE_ACCOUNT_JSON (see docs/playstore.md);
# mapped here to the env var name the script expects.
GOOGLE_SERVICE_ACCOUNT_JSON: ${{ secrets.PLAY_STORE_SERVICE_ACCOUNT_JSON }}
GH_TOKEN: ${{ secrets.GH_TOKEN || secrets.GITHUB_TOKEN }}
run: python scripts/triage-reviews.py