Skip to content

Let the review run after a push from claude.yml - #1728

Merged
riccardoferretti merged 1 commit into
mainfrom
fix/review-after-claude-push
Sep 30, 2026
Merged

riccardoferretti merged 1 commit into
mainfrom
fix/review-after-claude-push

Conversation

@riccardoferretti

Copy link
Copy Markdown
Collaborator

Every Review run triggered by a push from claude.yml has failed since 19 Sept: six of six, on #1707, #1708 and #1723. Two causes, in sequence:

  • actions/checkout@v6 persists the workflow token through an includeIf entry in git config. claude-code-action only clears include.path entries (its log says "No existing authentication headers to remove"), so the leftover header wins over the App token in the remote URL. The push goes out as github-actions[bot], and the runs it triggers are held as action_required.
  • Once approved, the action in review.yml refuses any bot actor not listed in allowed_bots: "Workflow initiated by non-human actor: github-actions".

This drops the persisted credential in claude.yml, so the push is the Claude app's, and allows that app as an actor in review.yml.

For the reviewer

  • Not verifiable before merge: claude.yml runs from main on comment events. After merging, the next @claude address push should show claude[bot] as its actor in the branch activity, and its Review run should start without approval and succeed.
  • The Review run on this PR may be skipped: the action validates the workflow file against the default branch, and this PR changes it.
  • spec.yml has the same checkout default. Left alone: spec PRs are drafts, which the review skips.

🤖 Generated with Claude Code

Every Review run triggered by a push from claude.yml has failed since
2026-09-19: six of six, on #1707, #1708 and #1723. Two causes, in sequence.

actions/checkout@v6 persists the workflow token through an includeIf entry
in git config. claude-code-action only clears include.path entries, logs
"No existing authentication headers to remove", and the leftover header
wins over the App token in the remote URL. The push goes out as
github-actions[bot], and the runs it triggers are held as action_required.

Once approved, the action in review.yml refuses any bot actor not listed in
allowed_bots.

Drop the persisted credential so the push is the Claude app's, and allow
that app as an actor in review.yml.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@riccardoferretti
riccardoferretti merged commit 248b210 into main Sep 30, 2026
8 checks passed
@riccardoferretti
riccardoferretti deleted the fix/review-after-claude-push branch September 30, 2026 09:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant