supernovae-st/nika-action
turns every PR that touches a .nika into a reviewed plan: a sticky
comment with the nika check verdict, the cost floor (never a fake zero),
the models and secrets the change needs, its egress statics, and the DAG —
rendered natively by GitHub as mermaid.
nika compile hello hello.nika writes the offline
lesson. For chain, preview with nika compile chain --json and answer
its questions before naming a destination —
authoring in 10 minutes.
Already have CI? One line
The starter repo publishes a reusable workflow that wraps the action with the same fork-safe posture — adopting the check in an existing repo is a singleuses: block:
nika-actions-starter
is a template repo — Use this template, and the verdict lands on your
first PR with zero further wiring. Its own pull requests run the check
live, so you can read a real sticky comment before adopting anything.
What lands on the PR
Every pull request gets a verdict. The first push refers to a task that does not exist, and the comment names the finding (NIKA-DAG-002, did you mean assess?). The second push fixes that line, and the same comment turns clean and draws the graph. Both comments are the action’s own renderer run on nika check --json and nika inspect; the pull request page is an illustration.
✅ nika check — clean ·One comment per workflow file, upserted in place on every push — never thread spam.flows/report.nika· 3 task(s) · 3 wave(s) 💰 **cost floor ≥ 0 🔐 requires — models:ollama/qwen3.5:4b·openai/gpt-5.2· secrets:OPENAI_API_KEY🌊 schedule — 3 wave(s), max width 1 🗺 DAG (collapsible mermaid)
The lanes — and the missing one
Security posture
- The engine download is verified against the release’s
SHA256SUMSbefore extraction. - Fork PRs carry a read-only token: the comment degrades to the step
summary automatically. Never wire any of this via
pull_request_targetwith a checkout of the PR head. - Pin the action itself by commit SHA — the marketplace norm.
Honesty semantics
The comment’s cost figure is a floor (spend ≥ floor); unpriced tasks
render as unpriced with their reason verbatim, never $0. When the DAG
has parallel waves the comment states the budget bound explicitly: a
mid-run --max-cost-usd stops new admissions, so the worst-case
overshoot is one full wave (spend ≤ floor + W · c_max). The full
semantics: cost honesty.