Repository navigation
ci: triage on plain pull_request with explicit github token; skip fork PRs - #316
Conversation
…k prs Fixes the ai-triage Claude step's startup failure (#312): the action's OIDC-to-app-token exchange returns 401 for tokens minted under pull_request_target, so the step died before any session started. Bun-style fix, plus a deliberate scope cut: - Trigger switches pull_request_target -> pull_request, and the job if gains a head-repo guard so fork PRs skip cleanly (auto AND label paths). Fork PRs are no longer triaged at all - same trade-off oven-sh/bun makes, removing the pull_request_target risk class instead of mitigating it. - The Claude step now passes github_token (GITHUB_TOKEN), which short-circuits the OIDC exchange entirely; id-token: write is dropped. Triage comments post as github-actions[bot]. - Everything probing those comments is now author-agnostic (marker + Bot-type author, never a login): the three triage command pre-checks and auto-close-duplicates.mjs findMarkerComment (which previously hard-required claude[bot] and would have matched nothing ever again). - Docs: ai-development guide + root CLAUDE.md note the same-repo-only PR scope and the new comment author. Fixes #312 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Pohc8xLkdx4gwXkW3xd7up
|
Important Review skippedNo new commits to review since the last review. ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
WalkthroughThe PR changes AI triage to use same-repository ChangesTriage workflow and marker handling
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant GitHub
participant TriageWorkflow
participant ClaudeAction
GitHub->>TriageWorkflow: Send pull_request event
TriageWorkflow->>TriageWorkflow: Check head repository matches base repository
TriageWorkflow->>ClaudeAction: Provide explicit github_token
ClaudeAction->>GitHub: Read triage data and post bot-authored markers
Possibly related PRs
Suggested labels: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Preview DeploymentPreview URL: https://cb6825c3.bestax.pages.dev |
There was a problem hiding this comment.
Deep review — 1 finding(s)
| # | Severity | Area | Finding | Location |
|---|---|---|---|---|
| 1 | 🟡 Minor | Correctness | Job-level fork guard skips the always() label-removal step, so ai-triage wedges "on" when a fork PR is labeled |
.github/workflows/ai-triage.yml:115 |
Overall: The change is sound and unusually well-documented. Switching ai-triage.yml from pull_request_target to plain pull_request + an explicit github_token cleanly removes the fork-secrets risk class and sidesteps the #312 OIDC 401, and the findMarkerComment broadening from a hardcoded claude[bot] login to isBot() is correct — it transparently matches both pre-#312 (claude[bot]) and post-#312 (github-actions[bot]) verdict comments, and the marker + Duplicate of #N gate keeps unrelated bot comments out. The riskiest external assumption is that claude-code-action truly short-circuits its OIDC->app-token exchange when github_token is supplied (the entire fix depends on it) — worth a human sanity-check that a real same-repo run posts as github-actions[bot] and the auto-close cron still finds those markers. The only defect is the minor stuck-label UX regression noted inline. Budget probe, single-flight concurrency, and veto logic are all consistent with the new bot identity.
🏄 Clean set on this one, dude — they paddled out of the gnarly
pull_request_targetrip current and rode plainpull_requestall the way in, secrets dry the whole way. Just a little label barnacle that sticks to fork PRs, totally cosmetic. Good to send it. 🌊
The job-level fork guard also skips the always() label-removal step, so labeling a fork PR wedges the ai-triage label. Not fixable under plain pull_request (fork runs cap GITHUB_TOKEN at read-only, so even a standalone unlabel job's DELETE would 403) - accepted and documented: fork PRs are never triaged, the label is inert, manual removal. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Pohc8xLkdx4gwXkW3xd7up
Preview DeploymentPreview URL: https://c8e31de7.bestax.pages.dev |
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
🎉 This PR is included in version 5.6.2 🎉 The release is available on: Your semantic-release bot 📦🚀 |
|
🎉 This PR is included in version 3.3.2 🎉 The release is available on: Your semantic-release bot 📦🚀 |
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
|
🎉 This PR is included in version 1.0.0 🎉 The release is available on: Your semantic-release bot 📦🚀 |
Pull Request
Description
Fixes #312 — the ai-triage Claude step died at startup with
401 Unauthorized - Invalid OIDC token: the claude-code-action's OIDC→app-token exchange rejects tokens minted underpull_request_target(theissuesandpull_requestpaths were never affected — the July 11 triage on #240 and every deep review prove the exchange works there).@allxsmith/bestax-bulma)create-bestax)@allxsmith/bestax-docs) — ai-development guide notes the new scope + comment author.github/workflows/ai-triage.yml,.claude/commands/triage-*.md,scripts/auto-close-duplicates.mjs, rootCLAUDE.mdThe fix (Bun-style), plus a deliberate scope cut:
pull_request_target→ plainpull_request, and the jobifgains a head-repo guard. Fork PRs are no longer triaged at all — auto and label paths alike, exactly the trade-off oven-sh/bun makes. Rationale in the workflow header: rather than mitigating thepull_request_targetrisk class (secrets + write token exposed to fork-triggered runs), we remove it. Fork runs would lack secrets underpull_requestanyway; the guard turns that failure mode into a clean silent skip.github_token: ${{ secrets.GITHUB_TOKEN }}on the Claude step — verified against the pinned action's source: a provided token short-circuits before any OIDC code runs.id-token: writeis dropped from the job. Bonus: GITHUB_TOKEN-authored comments can never re-trigger workflows.github-actions[bot]instead ofclaude[bot]. Everything that probes for them is now author-agnostic (marker + Bot-type author, never a specific login — Bun's convention):.claude/commands/triage-*.mdmarker pre-checks (their--edit-lastrefresh already had the "only if it's your most recent comment" guard, so no clobber risk);scripts/auto-close-duplicates.mjsfindMarkerComment, which hard-requiredclaude[bot]and would have matched nothing ever again after this change. Oldclaude[bot]comments still match (smoke-tested: latest-bot-wins across both identities; human comments containing a spoofed marker are still ignored).Related Issue(s)
Fixes #312
Type of Change
Checklist
node --check+ behavioral smoke offindMarkerComment; prettier +check:conformancegreen)CLAUDE.mdfiles are updated (root CLAUDE.md updated)Note: this PR touches
.github/**, a loop-refused path — it's driven manually, not by the AI loop.🤖 Generated with Claude Code
https://claude.ai/code/session_01Pohc8xLkdx4gwXkW3xd7up
Generated by Claude Code
Summary by CodeRabbit
Bug Fixes
Security & Reliability
Documentation