ci: skip secret-bound bot workflows on fork pull requests - #1035
Open
dmitrii-f-t27 wants to merge 1 commit into
Open
dmitrii-f-t27 wants to merge 1 commit into
dmitrii-f-t27 wants to merge 1 commit into
Conversation
dmitrii-f-t27
force-pushed
the
ci/fork-pr-hygiene
branch
from
September 21, 2026 00:50
64b72cd to
bc9a803
Compare
Three workflows depend on repository secrets (PROJECT_TOKEN, CLAUDE_CODE_OAUTH_TOKEN)
that GitHub withholds on pull_request events from forks, so every fork PR has been
collecting red checks that can never pass: add-to-project ("Input required and not
supplied: github-token"), pr-opened ("set the GH_TOKEN environment variable") and
claude-review (empty claude_code_oauth_token). Each job now skips when the PR head
repository is not this repository; same-repo PRs and issue events are unchanged.
The branch also archived .github/workflows/dev-enforcement.yml, which had not
parsed since gHashTag#357. That part is dropped: gHashTag#1054 rewrote the file on main, it parses,
and its pr-status job already carries continue-on-error for fork pull requests.
Only the three guards remain.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
dmitrii-f-t27
force-pushed
the
ci/fork-pr-hygiene
branch
from
September 21, 2026 00:51
bc9a803 to
533f7af
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
project-auto-add.yml, thepr-openedandpr-mergedjobs ofproject-auto-status.yml, andclaude-code-review.ymlreadPROJECT_TOKENorCLAUDE_CODE_OAUTH_TOKEN. GitHub withholds repository secrets onpull_requestevents from forks, so on #1032, #1033 and #1034 they failed withInput required and not supplied: github-token,gh: To use GitHub CLI in a GitHub Actions workflow, set the GH_TOKEN environment variableand an emptyclaude_code_oauth_token. Each of those jobs now carriesif: github.event.pull_request.head.repo.full_name == github.repository(the add-to-project job keeps running forissuesevents). Same-repo PRs behave exactly as before.Rebased 2026-09-20, one change dropped
This branch also archived
.github/workflows/dev-enforcement.yml, which had not parsed since #357 and produced a 0-second startup failure on every push. #1054 rewrote that workflow onmain: it parses, itspr-statusjob carriescontinue-on-errorprecisely because a fork pull request gets a read-only token, and the file no longer belongs in the archive. The branch is rebased onmaind15d6d8 and now contains only the three guards.Not touched
brain health was NOT MEASURED(noScore:line fromtri stress --health); that is independent of forks.PR work report and blogruns onpull_request_targetand needs no guard; this PR carries its work report below.pull_request_targetis the owner's call; this PR only stops the failing runs.Checks
if.git diff origin/main HEAD --statis three workflow files, +11 / −2, and nothing else.pull_requestworkflows run from the PR merge ref, soadd-to-project,pr-openedandclaude-reviewalready show as skipped here, while the merged fix(website): the Queen's phone chrome keeps every icon in view #1032, docs(website): vendor the viewport spec that notes the two-row phone rail #1033 and fix(website): one scroller on the phone spec page, the pane itself #1034 still show them failing.Work report
{ "version": 1, "head_sha": "533f7af822249760d77ddcd6cd6116e923e8d941", "summary": "Fork pull requests stop collecting red checks that can never pass: the three bot workflows that need repository secrets now skip when the pull request head repository is not this repository, while same-repo pull requests and issue events keep their current behaviour.", "changes": [ ".github/workflows/project-auto-add.yml: a job-level condition skips pull_request events whose head repository is a fork; issue events are unchanged.", ".github/workflows/project-auto-status.yml: the pr-opened and pr-merged jobs gain the same fork guard, because PROJECT_TOKEN is withheld on pull_request events from forks.", ".github/workflows/claude-code-review.yml: the claude-review job skips fork PRs, where CLAUDE_CODE_OAUTH_TOKEN arrives empty and the action fails before reviewing anything.", "Rebased on main d15d6d86d on 2026-09-20 and the dev-enforcement archive move was dropped, because #1054 rewrote that workflow on main and it parses again." ], "tests": [ { "command": "python3 -c 'import yaml,sys; [yaml.safe_load(open(f)) for f in sys.argv[1:]]' .github/workflows/project-auto-add.yml .github/workflows/project-auto-status.yml .github/workflows/claude-code-review.yml", "result": "All three edited workflows parse and each guarded job carries an if condition", "status": "passed", "evidence": "Local run 2026-09-20 on commit 533f7af82224 over origin/main d15d6d86d" }, { "command": "python3 -c 'import yaml; yaml.safe_load(open(\".github/workflows/dev-enforcement.yml\"))'", "result": "The workflow parses on this branch with jobs title-check and pr-status, the rewrite that landed in #1054, so archiving it is no longer warranted and that part of this branch is gone", "status": "passed", "evidence": "Local run 2026-09-20; the file on this branch is byte identical to the copy on main d15d6d86d" }, { "command": "git diff origin/main HEAD --stat", "result": "Three workflow files changed, eleven insertions and two deletions, no other path touched", "status": "passed", "evidence": "Local run 2026-09-20 in the rebased worktree; the earlier rename of dev-enforcement.yml no longer appears" }, { "command": "GitHub Actions run of the guarded jobs on this pull request from the dmitrii-f-t27 fork", "result": "add-to-project, pr-opened and claude-review all report skipping instead of failing", "status": "passed", "evidence": "Checks on this PR from 2026-09-16 (run 35071039921 and siblings) show the three jobs as skipping, because pull_request workflows run from the PR merge ref and the PR exercises its own guards" } ], "limitations": [ "Fork PRs will no longer be auto-added to project #6 or receive a Claude review; switching the two project workflows to pull_request_target would restore board updates with secrets available, but that is a policy choice for the repository owner.", "The Brain CI gate (brain health NOT MEASURED, no Score line from tri stress --health) fails on every run, fork or not, and is out of scope here.", "Whether the rewritten dev-enforcement workflow behaves correctly on fork pull requests is not measured here; its pr-status job carries continue-on-error, which is why this branch stopped touching it." ], "tags": [ "ci", "workflows", "fork_prs", "hygiene" ], "blog": { "title": "Fork pull requests stop failing checks they could never pass", "summary": "Why three bot workflows went red on every pull request from a fork, what GitHub withholds from such runs on purpose, and the three one-line guards that turn those failures into skips.", "outline": [ "Every pull request opened from a fork in this repository carried red checks that had nothing to do with the change: three jobs asked for repository secrets that GitHub deliberately withholds on pull_request events from forks, and failed before doing any work.", "The change adds one job-level condition to each secret-bound job, so a pull request whose head repository is not this repository skips those jobs instead of failing them, while same-repo pull requests and the issue-driven project automation behave exactly as before.", "A fourth failure from the same family, the dev-enforcement workflow that had not parsed since March, was going to be archived by this branch; #1054 rewrote the file on main instead, so the branch was rebased and that part dropped rather than carried further." ] } }Do not merge without the owner's approval.
🤖 Generated with Claude Code