Skip to content

ci(ai-review): grant contents: write so the AI review can start - #35

Merged
fpt merged 1 commit into
mainfrom
ci/ai-review-resolve-permission
Aug 11, 2026
Merged

fpt merged 1 commit into
mainfrom
ci/ai-review-resolve-permission

Conversation

@fpt

@fpt fpt commented Aug 11, 2026

Copy link
Copy Markdown
Owner

The AI review has been failing at startup here since fpt/klein-cli#112 merged —
startup_failure, no jobs, no review.

That PR split thread resolution into its own job holding contents: write, the
permission GitHub actually gates resolveReviewThread on. A called workflow may
only narrow the permissions it inherits, so a job requesting more than the
caller granted isn't a degraded feature — it's a parse-time rejection that stops
the entire workflow. This repo grants contents: read, so nothing ran.

Granting the ceiling here fixes it. Nothing writes to this repository: inside the
reusable workflow the job that checks out and runs this repo's PR code is
narrowed straight back to contents: read, and only the mutation-only job —
no checkout, no build, no model — keeps the write scope.

Upstream: fpt/klein-cli#111

🤖 Generated with Claude Code

The reusable workflow now resolves review threads it has verified as
fixed, in a dedicated job holding `contents: write` — the permission
GitHub actually gates `resolveReviewThread` on. A called workflow may only
narrow the permissions it inherits, so a job asking for more than the
caller granted is not a degraded feature: it is a `startup_failure` that
stops the whole review from running. That is what has been happening here
since fpt/klein-cli#112 merged.

Granting the ceiling here fixes it. Nothing writes to this repository —
inside the reusable workflow the job that checks out and runs this repo's
PR code is narrowed straight back to `contents: read`, and only the
mutation-only job, which checks nothing out, keeps the write scope.

Upstream: fpt/klein-cli#111

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

🤖 AI Review (klein) — turn 1

This change raises the caller workflow's contents permission from read to write so the referenced reusable workflow can perform its review-thread resolution mutation, while retaining pull-requests write. The permission change is consistent with the documented reusable-workflow permission inheritance model and is scoped to the same-repository PR condition already present on the job. I found no verified correctness or security defect in the changed lines; the remaining risk is that the workflow delegates a write-capable token to a mutable external @main reusable workflow, but that behavior is intentional here and cannot be evaluated further from this repository's diff alone.


turn 1 (full review of b037171) · comments: total 0, active 0 (+0 new, −0 resolved) · verdict: approve

@fpt
fpt merged commit 9ed9cf3 into main Aug 11, 2026
3 checks passed
@fpt
fpt deleted the ci/ai-review-resolve-permission branch August 11, 2026 03:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant