add output_schema_file option

This commit is contained in:
Michael Bolin
2025-10-02 17:59:03 -07:00
parent 4788b5152f
commit 8b3066088f
5 changed files with 47 additions and 15 deletions
+15 -12
View File
@@ -31,18 +31,21 @@ Provide either `prompt` or `prompt_file`; the other may be left empty. The actio
## Inputs
| Name | Required | Description | Default |
| ------------------------- | ------------- | -------------------------------------------------------------------------------------------------------------- | ---------------- |
| `openai_api_key` | Yes | Secret used to authenticate the helper proxy with OpenAI. Store it in `secrets` and never hardcode it. | — |
| `prompt` | Conditionally | Inline prompt text. Provide this or `prompt_file`. | `""` |
| `prompt_file` | Conditionally | Path (relative to the repository root) of a file that contains the prompt. Provide this or `prompt`. | `""` |
| `working_directory` | No | Directory passed to `codex exec --cd`. Defaults to the repository root. | `""` |
| `codex_version` | No | Version of `@openai/codex` to install. | `0.42.0-alpha.3` |
| `codex_args` | No | Extra arguments forwarded to `codex exec`. Accepts JSON arrays (`["--flag", "value"]`) or shell-style strings. | `""` |
| `output_file` | No | File where the final Codex message is written. Leave empty to skip writing a file. | `""` |
| `codex_home` | No | Directory to use as the Codex CLI home (config/cache). Uses the CLI default when empty. | `""` |
| `safety_strategy` | No | Controls how the action restricts Codex privileges. See [Safety strategy](#safety-strategy). | `drop_sudo` |
| `codex_user` | No | Username to run Codex as when `safety_strategy` is `unprivileged_user`. | `""` |
| Name | Required | Description | Default |
| -------------------- | ------------- | -------------------------------------------------------------------------------------------------------------- | ---------------- |
| `openai_api_key` | Yes | Secret used to authenticate the helper proxy with OpenAI. Store it in `secrets` and never hardcode it. | — |
| `prompt` | Conditionally | Inline prompt text. Provide this or `prompt_file`. | `""` |
| `prompt_file` | Conditionally | Path (relative to the repository root) of a file that contains the prompt. Provide this or `prompt`. | `""` |
| `working_directory` | No | Directory passed to `codex exec --cd`. Defaults to the repository root. | `""` |
| `codex_version` | No | Version of `@openai/codex` to install. | `0.42.0-alpha.3` |
| `codex_args` | No | Extra arguments forwarded to `codex exec`. Accepts JSON arrays (`["--flag", "value"]`) or shell-style strings. | `""` |
| `output_file` | No | File where the final Codex message is written. Leave empty to skip writing a file. | `""` |
| `output_schema_file` | No | Schema file forwarded to `codex exec --output-schema`. Leave empty to skip passing the option. | `""` |
| `codex_home` | No | Directory to use as the Codex CLI home (config/cache). Uses the CLI default when empty. | `""` |
| `safety_strategy` | No | Controls how the action restricts Codex privileges. See [Safety strategy](#safety-strategy). | `drop_sudo` |
| `codex_user` | No | Username to run Codex as when `safety_strategy` is `unprivileged_user`. | `""` |
| `require_repo_write` | No | Whether to require the triggering actor to have write access to the repository before running. | "true" |
| `allow_bots` | No | Allow runs triggered by GitHub Apps/bot accounts to bypass the write-access check. | "false" |
## Safety Strategy
+8 -2
View File
@@ -20,13 +20,17 @@ inputs:
codex_version:
description: "Version of `@openai/codex` to install."
required: false
default: "0.43.0-alpha.3"
default: "0.43.0-alpha.17"
codex_args:
description: "Additional args to pass through to `codex exec`. If this value starts with `[`, it will be parsed as a JSON array; otherwise, it will be parsed as a shell-like string."
required: false
default: ""
output_file:
description: "File path where the Codex output should be written. Ignored if the empty string."
description: "Path to a JSON Schema file describing the model's final response shape."
required: false
default: ""
output_schema_file:
description: "File path to the schema that should be passed to `codex exec --output-schema`."
required: false
default: ""
codex_home:
@@ -174,6 +178,7 @@ runs:
CODEX_WORKING_DIRECTORY: ${{ inputs.working_directory || github.workspace }}
CODEX_ARGS: ${{ inputs.codex_args }}
CODEX_OUTPUT_FILE: ${{ inputs.output_file }}
CODEX_OUTPUT_SCHEMA_FILE: ${{ inputs.output_schema_file }}
CODEX_SAFETY_STRATEGY: ${{ inputs.safety_strategy }}
CODEX_USER: ${{ inputs.codex_user }}
shell: bash
@@ -186,6 +191,7 @@ runs:
--proxy-port "${{ steps.read_server_info.outputs.port }}" \
--extra-args "$CODEX_ARGS" \
--output-file "$CODEX_OUTPUT_FILE" \
--output-schema-file "$CODEX_OUTPUT_SCHEMA_FILE" \
--safety-strategy "$CODEX_SAFETY_STRATEGY" \
--codex-user "$CODEX_USER"
+10 -1
View File
File diff suppressed because one or more lines are too long
+7
View File
@@ -70,6 +70,10 @@ export async function main() {
"--output-file <FILE>",
"Path where the final message from `codex exec` will be written."
)
.requiredOption(
"--output-schema-file <FILE>",
"Path to a schema file to pass to `codex exec --output-schema`."
)
.requiredOption(
"--safety-strategy <strategy>",
"Safety strategy to use. One of 'drop_sudo', 'read_only', 'unprivileged_user', or 'unsafe'."
@@ -87,6 +91,7 @@ export async function main() {
proxyPort: number;
extraArgs: Array<string>;
outputFile: string;
outputSchemaFile: string;
safetyStrategy: string;
codexUser: string;
}) => {
@@ -98,6 +103,7 @@ export async function main() {
proxyPort,
extraArgs,
outputFile,
outputSchemaFile,
safetyStrategy,
codexUser,
} = options;
@@ -124,6 +130,7 @@ export async function main() {
proxyPort,
extraArgs,
explicitOutputFile: emptyAsNull(outputFile),
outputSchemaFile: emptyAsNull(outputSchemaFile),
safetyStrategy: toSafetyStrategy(safetyStrategy),
codexUser: emptyAsNull(codexUser),
});
+7
View File
@@ -26,6 +26,7 @@ export async function runCodexExec({
proxyPort,
extraArgs,
explicitOutputFile,
outputSchemaFile,
safetyStrategy,
codexUser,
}: {
@@ -35,6 +36,7 @@ export async function runCodexExec({
proxyPort: number;
extraArgs: Array<string>;
explicitOutputFile: string | null;
outputSchemaFile: string | null;
safetyStrategy: SafetyStrategy;
codexUser: string | null;
}): Promise<void> {
@@ -84,6 +86,11 @@ export async function runCodexExec({
"--output-last-message",
outputFile.file
);
if (outputSchemaFile != null) {
command.push("--output-schema", outputSchemaFile);
}
command.push(...extraArgs);
// Note that if profiles expand to support their own sandbox policies, a