Repository navigation
OSAC-2050: fix resolve-pr job permissions for PR comment reactions - #96
Conversation
The resolve-pr job had pull-requests: read, but adding reactions on PR comments requires pull-requests: write since GitHub routes PR comments through the pulls API. This caused the Acknowledge comment step to fail with HTTP 403, skipping the entire review pipeline. Assisted-by: Claude Code <noreply@anthropic.com> Signed-off-by: Eran Cohen <eranco@redhat.com>
|
@eranco74: This pull request references OSAC-2050 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the bug to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: osac-project/coderabbit/.coderabbit.yaml Review profile: ASSERTIVE Plan: Enterprise Run ID: 📒 Files selected for processing (1)
WalkthroughThe ChangesWorkflow Permissions Update
Estimated code review effort: 1 (Trivial) | ~2 minutes Possibly related PRs
Suggested reviewers: Correctness check: a single-line permission bump from read to write on 🚥 Pre-merge checks | ✅ 11✅ Passed checks (11 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: AlonaKaplan, eranco74 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Summary
The
resolve-prjob inep-review.ymlhadpull-requests: readbut needspull-requests: writeto add the 👀 reaction on PR comments. GitHub treats PR comments as part of the pulls API, soissues: writealone is insufficient.The
Acknowledge commentstep was failing with HTTP 403, which killed the entireresolve-prjob and skipped thereviewjob downstream.Root cause: Two issues compounded:
resolve-prjob declaredpull-requests: readinstead ofpull-requests: writeFix
resolve-prpermissions frompull-requests: readtopull-requests: writeTest plan
/review-epon a PR with aprd.mdordesign.mdchange — the 👀 reaction should appear and the review job should proceedAssisted-by: Claude Code noreply@anthropic.com
Summary by CodeRabbit