You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 2b35d8e
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: README.md
+50-4Lines changed: 50 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,8 +1,20 @@
1
1
# SimplyCubed Code
2
2
3
+
[](https://simplycubed.com/code?utm_source=github&utm_medium=readme&utm_campaign=code)
4
+
3
5
An autonomous coding agent that lives inside your own GitHub. You file an issue, it opens a pull request, and a human decides whether to merge.
4
6
5
-
> Status: beta. `v0.1.6` is the latest release; expect rough edges. Product overview: [simplycubed.com/code](https://simplycubed.com/code?utm_source=github&utm_medium=readme&utm_campaign=code). See [Status](#status).
7
+
> Beta, at `v0.1.6`. Product overview: [simplycubed.com/code](https://simplycubed.com/code?utm_source=github&utm_medium=readme&utm_campaign=code). See [Status](#status).
8
+
9
+
### Try it without letting it write anything
10
+
11
+
```sh
12
+
simplycubed run owner/repo#12 --dry-run
13
+
```
14
+
15
+
That runs the whole loop, including the model and your own gate. It makes no GitHub writes and never pushes; it prints what it would have done instead.
16
+
17
+
`simplycubed init --workflow` also writes a self-test into your repository. Dispatch it once and it checks, in your own runner, that the App token resolves to a bot, that it can read what it needs, and that it is denied Actions administration. The install fails if that denial does not hold. Delete the workflow once it passes.
6
18
7
19
## What it is
8
20
@@ -22,7 +34,7 @@ The loop is issue to pull request, driven entirely through GitHub.
22
34
4. A human reviews. If they request changes, a fixer role reads the feedback, makes the changes, re-runs the gate, and pushes back to the same pull request for another look. Only feedback left against the current head is addressed, so the loop never re-litigates a comment it already handled.
23
35
5. A human merges. The agent does not.
24
36
25
-
A separate read-only reviewer role is defined in the code but is not yet wired into the loop, so today the review in step 4 is the human's. The roadmap below tracks it.
37
+
An automated reviewer runs before step 4 if you turn it on (`review: true`, off by default). It comments; it never approves and never merges. Step 5 is a human either way.
26
38
27
39
### Label lifecycle
28
40
@@ -45,10 +57,44 @@ You can also drive it by comment, addressed to the bot at the start of a line:
45
57
46
58
Only comments from people with write access are acted on, and only a comment that begins with the mention counts, so quoting an earlier comment never re-triggers a run. Note that a plain pull-request comment is not a review: to run the fixer from a review, submit it through **Files changed → Review changes**.
47
59
60
+
### What triggers a run
61
+
62
+
```mermaid
63
+
flowchart LR
64
+
L["issue labelled sc:go"] --> R["run job"]
65
+
V["review submitted<br/>OWNER, MEMBER or COLLABORATOR"] --> A["address job"]
RC --> PR["pull request opens<br/>a human merges it"]
76
+
AC --> PR
77
+
```
78
+
79
+
A plain comment in the conversation box is not a review. To run the fixer from a review, submit it through **Files changed → Review changes**. Every path checks that the person has write access before anything else happens.
80
+
48
81
## Running in your own GitHub
49
82
50
83
The whole thing runs on GitHub Actions, event-driven, with no server and no VM for SimplyCubed to operate. When you install the app and file issues, the work executes on your runners inside your organization.
51
84
85
+
### What it can do to your repo, and what stops it
86
+
87
+
It can open a pull request against a branch. That is the strongest action available to it.
88
+
89
+
What stops it, roughly in order of how much you should trust each one:
90
+
91
+
1.**It cannot merge, by construction.** The GitHub interface it is built against has no merge method: see [`internal/forge/forge.go`](internal/forge/forge.go). The model is not being asked to follow a rule here. The capability is absent from the code.
92
+
2. The App holds three permissions: contents, pull requests, issues. Not workflows, administration, environments, or secrets. Each job mints its own token, scoped to one repository.
93
+
3. That scope is proved on every run rather than claimed. The workflow calls an Actions-administration endpoint and expects the denial, so your run log carries the evidence.
94
+
4.**The model's shell never holds a GitHub token.**`GH_TOKEN` and `GITHUB_TOKEN` are stripped from the engine's environment before it starts.
95
+
5. Neither engine's "dangerous" bypass flag is set. When a change cannot be made under those constraints, the run stops and a human finishes it. [Why](docs/faq.md).
96
+
6. No deploy credentials, and no path to production. Your branch protection rules decide what happens once the pull request exists.
97
+
52
98
What this buys you:
53
99
54
100
- Your code stays in your repos. SimplyCubed never receives it.
@@ -160,7 +206,7 @@ gate: make check
160
206
engine: claude
161
207
```
162
208
163
-
The first engine adapter targets the Codex CLI running against Azure OpenAI. Today the shipped setup needs an Azure endpoint, an API key, and optionally a deployment name override if you are not using the default `gpt-5.4`. A Claude Code adapter is planned. The `Runner` interface is the seam where other engines plug in.
209
+
The first engine adapter targets the Codex CLI running against Azure OpenAI. Today the shipped setup needs an Azure endpoint, an API key, and optionally a deployment name override if you are not using the default `gpt-5.4`. A Claude Code adapter ships too, behind `engine: claude`. The `Runner` interface is the seam where other engines plug in.
164
210
165
211
## Status
166
212
@@ -173,7 +219,7 @@ Roadmap, roughly in order:
173
219
- Wiring the read-only reviewer role into the loop so a diff is reviewed before it reaches a human.
174
220
- The self-onboarding flow via `init` and `init --workflow`. **Done.**
175
221
- The Codex on Azure OpenAI engine adapter. **Done.**
176
-
- The Claude Code engine adapter.
222
+
- Self-hosted models on Hugging Face.
177
223
178
224
If you are evaluating it now, read that as beta software rather than a polished product. The core loops work; reviewer wiring is still in progress, and self-onboarding shipped as `init` and `init --workflow`.
Copy file name to clipboardExpand all lines: STATUS.md
+13-15Lines changed: 13 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -27,9 +27,8 @@ The Actions runtime authenticates as the `simplycubed-code[bot]` GitHub App.
27
27
Each job mints its own installation token scoped to one repository with
28
28
`contents`, `issues`, and `pull-requests` permissions only.
29
29
30
-
`v0.1.5` is the current release. `go install
31
-
github.com/simplycubed/code/cmd/simplycubed@v0.1.5` works today. `v0.1.2` and
32
-
`v0.1.4` are retracted in `go.mod` because those tags pointed at the wrong
30
+
`v0.1.6` is the current release. `go install
31
+
github.com/simplycubed/code/cmd/simplycubed@v0.1.6` works today. `v0.1.2` and `v0.1.4` are retracted in `go.mod` because those tags pointed at the wrong
33
32
commits.
34
33
35
34
Both loops were dogfooded: the issue-to-PR loop produced the merged
@@ -40,15 +39,19 @@ dependency-upgrade PR on `charlesgreen/gsm`.
0 commit comments