Skip to content

fix(ci): let the automatic Claude review post its comments - #516

Merged
elgorro merged 1 commit into
mainfrom
fix/claude-review-comment-permission
Sep 12, 2026
Merged

elgorro merged 1 commit into
mainfrom
fix/claude-review-comment-permission

Conversation

@elgorro

@elgorro elgorro commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

Follow-up to the review-plumbing question raised while checking #515.

claude-code-review.yml runs /code-review:code-review --comment ... but declared only pull-requests: read. Posting inline comments needs write — manual-code-review.yml, which runs the identical prompt, already grants it.

Why this was invisible

The job does not fail. On #515 it completed with "is_error": false, "num_turns": 3, $0.097 spent, OIDC token obtained, and then logged No buffered inline comments. A review that found nothing and a review that could not publish what it found look exactly the same from the checks list.

Supporting evidence: no inline comment or issue comment from this workflow exists on #504, #508, #509, #510 or #515.

Changes

  • pull-requests: read → write, with a comment saying why.
  • docs/dev/ci-cd.md — the Automatic section now records the permission and names the silent failure mode, matching the note the Manual section already carries.

The tool allow-list is deliberately left alone: --allowedTools "mcp__github_inline_comment__create_inline_comment" is the sandbox that keeps an untrusted diff from getting a shell, and manual-code-review.yml documents that as intentional.

This PR cannot test itself

claude-review is green here but did not review anything. claude-code-action refuses to run when the workflow file differs from the copy on the default branch:

Workflow validation failed. The workflow file must exist and have identical content to the version on the repository's default branch.

That is a deliberate guard against a PR rewriting the reviewer that judges it. So any PR touching claude-code-review.yml gets a green, no-op review, and the fix only takes effect once this is merged to main. Verification has to be the next PR that does not touch this file.

Worth recording separately: it also means a green claude-review on a workflow-editing PR is never evidence of a review — a second silent-success mode alongside the one this PR fixes.

🤖 Generated with Claude Code

https://claude.ai/code/session_01UYWJYDDvbBQUCQvPgwzBaA

The automatic review workflow declared `pull-requests: read` while running
`/code-review --comment`, which needs write to post. The manual review
workflow, which does the same thing, already grants write.

With read the job still succeeds and still spends a Claude run — it just
cannot publish what it found, so a review that raised issues is
indistinguishable from a clean one. No recent PR (#504, #508, #509, #510,
#515) carries a single inline comment from this workflow.

Grant `pull-requests: write` and record in docs/dev/ci-cd.md why the scope
matters, since the failure mode is silent.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UYWJYDDvbBQUCQvPgwzBaA
@elgorro
elgorro merged commit 7c92d3f into main Sep 12, 2026
6 checks passed
@elgorro
elgorro deleted the fix/claude-review-comment-permission branch September 12, 2026 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant