Skip to content

fix(ai-pr-review/anthropic): let Forge PRs past claude-code-action's bot gate - #139

Merged
sparsh-deriv merged 2 commits into
masterfrom
fix/ai-pr-review-anthropic-forge-bot
Sep 24, 2026
Merged

sparsh-deriv merged 2 commits into
masterfrom
fix/ai-pr-review-anthropic-forge-bot

Conversation

@sparsh-deriv

Copy link
Copy Markdown
Collaborator

Summary

  • The job-level Forge allowlist is engine-neutral. Kimi (and Grok) already review same-repo gh-app-write[bot] PRs because they do not use claude-code-action. GLM and DeepSeek share engine: anthropic, so they start, then die in ~5s: Workflow initiated by non-human actor: gh-app-write. Add bot to allowed_bots list or use '*' to allow all bots. Evidence: deriv-com/deriv-api-v2#955.
  • Pass allowed_bots: gh-app-write on the Anthropic engine (and the deprecated claude-pr-review.yml caller of the same SHA). The action strips [bot] when matching. Do not use *.
  • Unchanged: Dependabot / other bots still skip at the job if:; fork skip (HackerOne #4037167); Kimi/Grok have no second gate.

Test plan

  • bash tests/ai-pr-review-contract.sh — pins allowed_bots: gh-app-write and fails a wildcard
  • After merge, re-run GLM + DeepSeek on a Forge PR (e.g. deriv-api-v2#955 synchronize) and confirm they get past Checking permissions for actor: gh-app-write[bot]
  • Confirm a Dependabot PR still skips at the job if:

Made with Cursor

…bot gate

The job-level allowlist starts GLM and DeepSeek, then the action exits
in seconds with "non-human actor: gh-app-write". Pass allowed_bots for
that app only — not *.

Co-authored-by: Cursor <cursoragent@cursor.com>
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails

Scanned Manifest Files

…orkflow

allowed_bots is SHA-parity with the Anthropic engine; this workflow's access gate still rejects gh-app-write[bot].

Co-authored-by: Cursor <cursoragent@cursor.com>
@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Model: kimi-k3

🤖 Kimi PR Review Complete

🔄 Follow-up Review

Summary

1 of 1 issues from the previous review have been resolved. The single Low finding — the misleading "Same Forge exception as ai_review_engine_anthropic" comment above allowed_bots in the deprecated claude-pr-review.yml — has been replaced with a comment that accurately states the line is inert there (the workflow's access gate has no gh-app-write[bot] exception, so Forge PRs fail at the gate first) and points consumers to ai-pr-review.yml for Forge. The incremental diff touches only that comment; the allowed_bots: gh-app-write value itself is unchanged, no executable code was modified, and the contract-test pinning (an optional part of the alternative fix path, not the preferred one) was deliberately skipped. No regressions introduced.

Recommendation: APPROVE


🔴 Critical Issues (BLOCK MERGE)

None.

🟠 High Priority Issues

None.

🟡 Medium Priority Issues

None.

🟢 Low Priority Issues

None.


Summary Table

Priority Count Categories
🔴 Critical 0 —
🟠 High 0 —
🟡 Medium 0 —
🟢 Low 0 —

Total: 0 remaining issues (1 previous Low issue fixed).


Recommendations

  1. Merge is appropriate — the one outstanding Low item is resolved, and the corrected comment now matches the workflow's actual behavior.
  2. Before considering the fix verified end-to-end, complete the remaining post-merge test plan items from the PR description: re-run GLM + DeepSeek on a Forge PR (e.g. deriv-api-v2#955) and confirm they get past Checking permissions for actor: gh-app-write[bot], and confirm a Dependabot PR still skips at the job if:.

Auto Fix Claude Reviews

Action Open Dashboard

@sparsh-deriv
sparsh-deriv merged commit 5263f67 into master Sep 24, 2026
7 checks passed
@sparsh-deriv
sparsh-deriv deleted the fix/ai-pr-review-anthropic-forge-bot branch September 24, 2026 05:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants