Skip to content

fix(ci): auto-fix for PR #77 - #97

Closed
moomooskycow wants to merge 1 commit into
dependabot/npm_and_yarn/eslint-config-prettier-tw-10.1.8from
kaylee/pr-77-fix-1767890162427
Closed

moomooskycow wants to merge 1 commit into
dependabot/npm_and_yarn/eslint-config-prettier-tw-10.1.8from
kaylee/pr-77-fix-1767890162427

Conversation

@moomooskycow

Copy link
Copy Markdown
Owner

Automated CI Fix

Diagnosis

Summary

Changes

See diff for details.


Generated by kaylee

Dependabot PRs cannot access repository secrets due to GitHub's security
restrictions. This causes the claude-code-action to fail with 'Environment
variable validation failed: Either ANTHROPIC_API_KEY or CLAUDE_CODE_OAUTH_TOKEN
is required'.

Add conditional check to skip the Claude Code Review step when the actor is
dependabot[bot], preventing workflow failures while maintaining reviews for
human-created PRs.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jan 8, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Review Updated (UTC)
vanity Error Error Jan 8, 2026 4:40pm

@coderabbitai

coderabbitai Bot commented Jan 8, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@moomooskycow

Copy link
Copy Markdown
Owner Author

🔧 kaylee here!

I took a look at the failing CI, but this one's beyond my wrench:

Why I can't fix it: This is not a code problem - it's a workflow validation security feature.**

What I found

Well, here's the thing - this ain't actually broken, it's working exactly as designed. The Claude Code action has a security check built into it that compares the workflow file in a PR against the version on the repository's default branch. If they don't match, it refuses to run.

This is a smart security measure - it prevents bad actors from sneaking malicious changes into workflow files through PRs (like changing action versions, leaking secrets, or modifying permissions). But it also means you can't fix or modify a workflow file that uses this action through a normal PR process.

What's happening:

  1. PR fix(ci): auto-fix for PR #77 #97 adds an if condition to skip Claude Code Review for Dependabot PRs
  2. This changes .github/workflows/claude-code-review.yml
  3. The claude-code-action sees the workflow file is different from main
  4. It fails with "Workflow validation failed" - exactly as intended

The irony: You're trying to fix the workflow, but the workflow's own security check prevents you from fixing it via PR.

What needs to happen

This likely requires human intervention — maybe setting up secrets, configuring external services, or other non-code changes.


🤖 Generated by kaylee — I tried, Captain!

@moomooskycow

Copy link
Copy Markdown
Owner Author

🔧 kaylee here — attempt #2

Hmm, looked at the failure but couldn't figure out what code to change. Might need a human eye on this one.

What I found

I've got enough info. The error is crystal clear from the logs:

The Error:

Workflow validation failed. The workflow file must exist and have identical content to the version on the repository's default branch.

This is happening during OIDC token exchange for the anthropics/claude-code-action@beta action. The action requires the workflow file to be identical to what's on the default branch (main/master) before it will issue tokens.

The problem is: This PR modifies the workflow file itself (adding the if: ${{ github.actor != 'dependabot[bot]' }} condition), which means the workflow validation will ALWAYS fail because the workflow on the PR branch is different from the default branch.

This is a security feature of the claude-code-action - it prevents PRs from modifying the workflow to gain unauthorized access. It's not fixable with code changes - it's working as intended.

Root Cause

The anthropics/claude-code-action@beta action validates that workflo


🤖 Generated by kaylee — stumped on this one

@moomooskycow
moomooskycow deleted the kaylee/pr-77-fix-1767890162427 branch January 9, 2026 16:06

This branch had an error being deployed

1 failed deployment
Preview — e64e1653 Deployed Jan 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant