Build & push image / build-and-push (pull_request) Successful in 8s
Gadfly's own swarm reviewed PR #26 and reached consensus (3/3 models) on a real bug, plus flagged security/maintainability items. Fixes: - Pass-through auth (BLOCKING, 3/3 agreement): openCodeEnv() stripped every provider key except OLLAMA_API_KEY, so the documented opencode/<provider>/<model> escape hatch (e.g. opencode/anthropic/...) had no way to authenticate — the reusable workflow forwards ANTHROPIC_API_KEY/OPENAI_API_KEY into the container and the allowlist discarded them. Now forward ANTHROPIC_*/OPENAI_*/GOOGLE_*/ GEMINI_* so OpenCode's built-in providers can authenticate, while still withholding gadfly's own secrets (Gitea/findings tokens, claude-code OAuth). - Read-only hardening (security lens): the generated config denied only edit/bash. Using OpenCode's documented permission schema, also deny webfetch/websearch/ external_directory — the network + out-of-sandbox tools — closing the exfiltration surface a prompt-injected review could otherwise reach. Permission is now a map so the deny set is extensible. - Dedup (maintainability lens, 3/3): extract shared filterEnv() and killGroupOnCancel() helpers in engine.go, used by both shell-out engines' runPass/env builders instead of the copy-pasted blocks. - Cosmetic: split the const block so defaultOpenCodeBaseURL's doc comment no longer visually misattaches to the agent-name const. README updated: the read-only note and the reduced-env note now reflect the broader deny set and the forwarded provider keys. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>