Skip to content

OSAC-2050: fix resolve-pr job permissions for PR comment reactions - #96

Merged
openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
eranco74:fix/OSAC-2050-ep-review-permissions
Jul 5, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
osac-project:mainfrom
eranco74:fix/OSAC-2050-ep-review-permissions

Conversation

@eranco74

@eranco74 eranco74 commented Jul 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The resolve-pr job in ep-review.yml had pull-requests: read but needs pull-requests: write to add the 👀 reaction on PR comments. GitHub treats PR comments as part of the pulls API, so issues: write alone is insufficient.

The Acknowledge comment step was failing with HTTP 403, which killed the entire resolve-pr job and skipped the review job downstream.

Root cause: Two issues compounded:

  1. The org workflow permissions were set to read-only, overriding all job-level permissions (fixed via org settings)
  2. The resolve-pr job declared pull-requests: read instead of pull-requests: write

Fix

  • Change resolve-pr permissions from pull-requests: read to pull-requests: write

Test plan

  • Comment /review-ep on a PR with a prd.md or design.md change — the 👀 reaction should appear and the review job should proceed

Assisted-by: Claude Code noreply@anthropic.com

Summary by CodeRabbit

  • Chores
    • Updated an automated workflow to allow it to make changes to pull request records when resolving PR context.

The resolve-pr job had pull-requests: read, but adding reactions on PR
comments requires pull-requests: write since GitHub routes PR comments
through the pulls API. This caused the Acknowledge comment step to fail
with HTTP 403, skipping the entire review pipeline.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: Eran Cohen <eranco@redhat.com>
@openshift-ci-robot

openshift-ci-robot commented Jul 5, 2026 •

Copy link
Copy Markdown

@eranco74: This pull request references OSAC-2050 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the bug to target the "5.0.0" version, but no target version was set.

Details

In response to this:

Summary

The resolve-pr job in ep-review.yml had pull-requests: read but needs pull-requests: write to add the 👀 reaction on PR comments. GitHub treats PR comments as part of the pulls API, so issues: write alone is insufficient.

The Acknowledge comment step was failing with HTTP 403, which killed the entire resolve-pr job and skipped the review job downstream.

Root cause: Two issues compounded:

  1. The org workflow permissions were set to read-only, overriding all job-level permissions (fixed via org settings)
  2. The resolve-pr job declared pull-requests: read instead of pull-requests: write

Fix

  • Change resolve-pr permissions from pull-requests: read to pull-requests: write

Test plan

  • Comment /review-ep on a PR with a prd.md or design.md change — the 👀 reaction should appear and the review job should proceed

Assisted-by: Claude Code noreply@anthropic.com

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested review from avishayt and chenyosef July 5, 2026 16:17
@openshift-ci openshift-ci Bot added the approved label Jul 5, 2026
@coderabbitai

coderabbitai Bot commented Jul 5, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: osac-project/coderabbit/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Enterprise

Run ID: f43ad6aa-a4c9-4589-b861-8b47f02551af

📥 Commits

Reviewing files that changed from the base of the PR and between 08d6dea and 42668d3.

📒 Files selected for processing (1)
  • .github/workflows/ep-review.yml

Walkthrough

The resolve-pr job permission for pull-requests in the GitHub Actions workflow ep-review.yml is changed from read to write, granting the job write access to pull requests.

Changes

Workflow Permissions Update

Layer / File(s) Summary
resolve-pr permission escalation
.github/workflows/ep-review.yml
Changed pull-requests permission for the resolve-pr job from read to write.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

Suggested reviewers: carbonin, mhrivnak

Correctness check: a single-line permission bump from read to write on pull-requests scope for resolve-pr — verify this write access is actually required by the job's downstream actions (e.g., commenting, labeling, or merging) and isn't over-scoped, since broadened token permissions are a security-relevant change worth confirming against least-privilege practice.

🚥 Pre-merge checks | ✅ 11
✅ Passed checks (11 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: increasing resolve-pr permissions to support PR comment reactions.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
No-Hardcoded-Secrets ✅ Passed The only change is pull-requests permission from read to write; no hardcoded secrets, tokens, passwords, or embedded credentials were added.
No-Weak-Crypto ✅ Passed Only .github/workflows/ep-review.yml changed; it adjusts PR permissions and adds no weak crypto or secret-comparison logic.
No-Injection-Vectors ✅ Passed Diff only changes pull-requests permission from read to write; no SQL, shell, eval, pickle, yaml, or HTML injection vectors were added.
Container-Privileges ✅ Passed PR only changes a GitHub Actions workflow permission; no container/K8s manifest changes or privilege flags were present.
No-Sensitive-Data-In-Logs ✅ Passed Diff only changes pull-requests permission from read to write; no logging changes or sensitive-data exposure found.
Ai-Attribution ✅ Passed Commit 42668d3 includes an Assisted-by trailer for Claude Code; no Co-Authored-By trailer is present.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@openshift-ci

openshift-ci Bot commented Jul 5, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: AlonaKaplan, eranco74

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [AlonaKaplan,eranco74]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot
openshift-merge-bot Bot merged commit c1c9aea into osac-project:main Jul 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants