Repository navigation
fix(ci): let the automatic Claude review post its comments - #516
Merged
Merged
Conversation
The automatic review workflow declared `pull-requests: read` while running `/code-review --comment`, which needs write to post. The manual review workflow, which does the same thing, already grants write. With read the job still succeeds and still spends a Claude run — it just cannot publish what it found, so a review that raised issues is indistinguishable from a clean one. No recent PR (#504, #508, #509, #510, #515) carries a single inline comment from this workflow. Grant `pull-requests: write` and record in docs/dev/ci-cd.md why the scope matters, since the failure mode is silent. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UYWJYDDvbBQUCQvPgwzBaA
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to the review-plumbing question raised while checking #515.
claude-code-review.ymlruns/code-review:code-review --comment ...but declared onlypull-requests: read. Posting inline comments needs write —manual-code-review.yml, which runs the identical prompt, already grants it.Why this was invisible
The job does not fail. On #515 it completed with
"is_error": false,"num_turns": 3,$0.097spent, OIDC token obtained, and then loggedNo buffered inline comments. A review that found nothing and a review that could not publish what it found look exactly the same from the checks list.Supporting evidence: no inline comment or issue comment from this workflow exists on #504, #508, #509, #510 or #515.
Changes
pull-requests: read→write, with a comment saying why.docs/dev/ci-cd.md— the Automatic section now records the permission and names the silent failure mode, matching the note the Manual section already carries.The tool allow-list is deliberately left alone:
--allowedTools "mcp__github_inline_comment__create_inline_comment"is the sandbox that keeps an untrusted diff from getting a shell, andmanual-code-review.ymldocuments that as intentional.This PR cannot test itself
claude-reviewis green here but did not review anything.claude-code-actionrefuses to run when the workflow file differs from the copy on the default branch:That is a deliberate guard against a PR rewriting the reviewer that judges it. So any PR touching
claude-code-review.ymlgets a green, no-op review, and the fix only takes effect once this is merged tomain. Verification has to be the next PR that does not touch this file.Worth recording separately: it also means a green
claude-reviewon a workflow-editing PR is never evidence of a review — a second silent-success mode alongside the one this PR fixes.🤖 Generated with Claude Code
https://claude.ai/code/session_01UYWJYDDvbBQUCQvPgwzBaA