ci(ai-review): grant contents: write so the AI review can start - #35
Conversation
The reusable workflow now resolves review threads it has verified as fixed, in a dedicated job holding `contents: write` — the permission GitHub actually gates `resolveReviewThread` on. A called workflow may only narrow the permissions it inherits, so a job asking for more than the caller granted is not a degraded feature: it is a `startup_failure` that stops the whole review from running. That is what has been happening here since fpt/klein-cli#112 merged. Granting the ceiling here fixes it. Nothing writes to this repository — inside the reusable workflow the job that checks out and runs this repo's PR code is narrowed straight back to `contents: read`, and only the mutation-only job, which checks nothing out, keeps the write scope. Upstream: fpt/klein-cli#111 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
🤖 AI Review (klein) — turn 1This change raises the caller workflow's contents permission from read to write so the referenced reusable workflow can perform its review-thread resolution mutation, while retaining pull-requests write. The permission change is consistent with the documented reusable-workflow permission inheritance model and is scoped to the same-repository PR condition already present on the job. I found no verified correctness or security defect in the changed lines; the remaining risk is that the workflow delegates a write-capable token to a mutable external turn 1 (full review of b037171) · comments: total 0, active 0 (+0 new, −0 resolved) · verdict: approve |
The AI review has been failing at startup here since fpt/klein-cli#112 merged —
startup_failure, no jobs, no review.That PR split thread resolution into its own job holding
contents: write, thepermission GitHub actually gates
resolveReviewThreadon. A called workflow mayonly narrow the permissions it inherits, so a job requesting more than the
caller granted isn't a degraded feature — it's a parse-time rejection that stops
the entire workflow. This repo grants
contents: read, so nothing ran.Granting the ceiling here fixes it. Nothing writes to this repository: inside the
reusable workflow the job that checks out and runs this repo's PR code is
narrowed straight back to
contents: read, and only the mutation-only job —no checkout, no build, no model — keeps the write scope.
Upstream: fpt/klein-cli#111
🤖 Generated with Claude Code