Repository navigation
Conversation
GitHub App installation tokens cannot call GET /user (returns 403 "Resource not accessible by integration"). The health_check_tool was hardcoded to "get_me" for both PAT and GitHub App auth, causing the github toolset to be permanently marked as failed when using App auth. New behaviour: - GitHub App auth: health_check_tool defaults to "" (check skipped) - PAT auth: health_check_tool defaults to "get_me" (unchanged) - Both: mcpAddons.github.healthCheckTool overrides the default Closes #<TBD>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
WalkthroughThe Helm chart template for the GitHub MCP server now computes ChangesGitHub MCP health_check_tool per-auth-type configuration
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related PRs
Suggested reviewers
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
✅ Deploy Preview for holmes-docs ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@helm/holmes/templates/toolset-config.yaml`:
- Around line 110-119: The `health_check_tool` field in the githubConfig dict is
being set to an empty string as a default to disable health checks, but
downstream logic treats empty strings as falsey and falls back to
auto-detection, defeating the purpose and allowing the system to pick `get_me`
which causes 403 errors. Instead of using an empty string as a sentinel value,
implement an explicit disable mechanism such as a dedicated config flag (for
example `"health_check_enabled" false` or `"health_check_tool" "disabled"`) that
the downstream MCP prerequisite logic can check for to truly disable health
checks instead of auto-detecting when the value is absent or empty.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 7c3d8a02-83fd-4b6f-844b-edca75976b64
📒 Files selected for processing (2)
helm/holmes/templates/toolset-config.yamlhelm/holmes/values.yaml
…o-detect Previously, `health_check_tool or auto_detect()` meant that both None and "" triggered auto-detection. An empty string set in the Helm chart (the intended "skip" sentinel for GitHub App auth) would still cause auto-detection to pick up get_me — and the resulting GET /user call returns 403 for App installation tokens, keeping the toolset unhealthy. Now the logic is: - None → not configured → auto-detect (unchanged default behaviour) - "" → explicitly disabled → skip the health check entirely - name → call that specific tool (unchanged) This makes the empty-string sentinel in the Helm chart's GitHub App branch actually work as intended.
Fixes #2205
Changes
health_check_tooldefaults to""(health check skipped — App tokens cannot callGET /user)health_check_tooldefaults to"get_me"(no change in behaviour)mcpAddons.github.healthCheckToolvalues field to override the defaultWhy
get_mecallsGET /user, which requires a user-level OAuth token. GitHub App installation tokens always return403 Resource not accessible by integrationfor this endpoint. This causes thegithubtoolset to be permanently marked as failed and all GitHub tools become unavailable to users.Summary by CodeRabbit
nullnow triggers auto-detection, while an empty value cleanly disables the health/auth check; non-empty values directly select the tool.