fix(ai-pr-review/anthropic): let Forge PRs past claude-code-action's bot gate - #139
Conversation
…bot gate The job-level allowlist starts GLM and DeepSeek, then the action exits in seconds with "non-human actor: gh-app-write". Pass allowed_bots for that app only — not *. Co-authored-by: Cursor <cursoragent@cursor.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Manifest Files |
…orkflow allowed_bots is SHA-parity with the Anthropic engine; this workflow's access gate still rejects gh-app-write[bot]. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Model: 🤖 Kimi PR Review Complete🔄 Follow-up Review Summary1 of 1 issues from the previous review have been resolved. The single Low finding — the misleading "Same Forge exception as ai_review_engine_anthropic" comment above Recommendation: APPROVE 🔴 Critical Issues (BLOCK MERGE)None. 🟠 High Priority IssuesNone. 🟡 Medium Priority IssuesNone. 🟢 Low Priority IssuesNone. Summary Table
Total: 0 remaining issues (1 previous Low issue fixed). Recommendations
Auto Fix Claude Reviews
|
Summary
gh-app-write[bot]PRs because they do not useclaude-code-action. GLM and DeepSeek shareengine: anthropic, so they start, then die in ~5s:Workflow initiated by non-human actor: gh-app-write. Add bot to allowed_bots list or use '*' to allow all bots.Evidence: deriv-com/deriv-api-v2#955.allowed_bots: gh-app-writeon the Anthropic engine (and the deprecatedclaude-pr-review.ymlcaller of the same SHA). The action strips[bot]when matching. Do not use*.if:; fork skip (HackerOne #4037167); Kimi/Grok have no second gate.Test plan
bash tests/ai-pr-review-contract.sh— pinsallowed_bots: gh-app-writeand fails a wildcardChecking permissions for actor: gh-app-write[bot]if:Made with Cursor