Let the review run after a push from claude.yml - #1728
Merged
Merged
Conversation
Every Review run triggered by a push from claude.yml has failed since 2026-09-19: six of six, on #1707, #1708 and #1723. Two causes, in sequence. actions/checkout@v6 persists the workflow token through an includeIf entry in git config. claude-code-action only clears include.path entries, logs "No existing authentication headers to remove", and the leftover header wins over the App token in the remote URL. The push goes out as github-actions[bot], and the runs it triggers are held as action_required. Once approved, the action in review.yml refuses any bot actor not listed in allowed_bots. Drop the persisted credential so the push is the Claude app's, and allow that app as an actor in review.yml. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every Review run triggered by a push from
claude.ymlhas failed since 19 Sept: six of six, on #1707, #1708 and #1723. Two causes, in sequence:actions/checkout@v6persists the workflow token through anincludeIfentry in git config.claude-code-actiononly clearsinclude.pathentries (its log says "No existing authentication headers to remove"), so the leftover header wins over the App token in the remote URL. The push goes out asgithub-actions[bot], and the runs it triggers are held asaction_required.review.ymlrefuses any bot actor not listed inallowed_bots: "Workflow initiated by non-human actor: github-actions".This drops the persisted credential in
claude.yml, so the push is the Claude app's, and allows that app as an actor inreview.yml.For the reviewer
claude.ymlruns frommainon comment events. After merging, the next@claude addresspush should showclaude[bot]as its actor in the branch activity, and its Review run should start without approval and succeed.spec.ymlhas the same checkout default. Left alone: spec PRs are drafts, which the review skips.🤖 Generated with Claude Code