Skip to content

ci: skip secret-bound bot workflows on fork pull requests - #1035

Open
dmitrii-f-t27 wants to merge 1 commit into
gHashTag:mainfrom
dmitrii-f-t27:ci/fork-pr-hygiene
Open

dmitrii-f-t27 wants to merge 1 commit into
gHashTag:mainfrom
dmitrii-f-t27:ci/fork-pr-hygiene

Conversation

@dmitrii-f-t27

@dmitrii-f-t27 dmitrii-f-t27 commented Sep 16, 2026 •

Copy link
Copy Markdown
Collaborator

What

project-auto-add.yml, the pr-opened and pr-merged jobs of project-auto-status.yml, and claude-code-review.yml read PROJECT_TOKEN or CLAUDE_CODE_OAUTH_TOKEN. GitHub withholds repository secrets on pull_request events from forks, so on #1032, #1033 and #1034 they failed with Input required and not supplied: github-token, gh: To use GitHub CLI in a GitHub Actions workflow, set the GH_TOKEN environment variable and an empty claude_code_oauth_token. Each of those jobs now carries if: github.event.pull_request.head.repo.full_name == github.repository (the add-to-project job keeps running for issues events). Same-repo PRs behave exactly as before.

Rebased 2026-09-20, one change dropped

This branch also archived .github/workflows/dev-enforcement.yml, which had not parsed since #357 and produced a 0-second startup failure on every push. #1054 rewrote that workflow on main: it parses, its pr-status job carries continue-on-error precisely because a fork pull request gets a read-only token, and the file no longer belongs in the archive. The branch is rebased on main d15d6d8 and now contains only the three guards.

Not touched

  • The S³AI Brain CI gate fails on every run with brain health was NOT MEASURED (no Score: line from tri stress --health); that is independent of forks.
  • PR work report and blog runs on pull_request_target and needs no guard; this PR carries its work report below.
  • Whether fork PRs should reach project deps: Bump @anthropic-ai/sdk from 0.40.1 to 0.72.1 in /vibee-electron #6 through pull_request_target is the owner's call; this PR only stops the failing runs.

Checks

Work report

{
  "version": 1,
  "head_sha": "533f7af822249760d77ddcd6cd6116e923e8d941",
  "summary": "Fork pull requests stop collecting red checks that can never pass: the three bot workflows that need repository secrets now skip when the pull request head repository is not this repository, while same-repo pull requests and issue events keep their current behaviour.",
  "changes": [
    ".github/workflows/project-auto-add.yml: a job-level condition skips pull_request events whose head repository is a fork; issue events are unchanged.",
    ".github/workflows/project-auto-status.yml: the pr-opened and pr-merged jobs gain the same fork guard, because PROJECT_TOKEN is withheld on pull_request events from forks.",
    ".github/workflows/claude-code-review.yml: the claude-review job skips fork PRs, where CLAUDE_CODE_OAUTH_TOKEN arrives empty and the action fails before reviewing anything.",
    "Rebased on main d15d6d86d on 2026-09-20 and the dev-enforcement archive move was dropped, because #1054 rewrote that workflow on main and it parses again."
  ],
  "tests": [
    {
      "command": "python3 -c 'import yaml,sys; [yaml.safe_load(open(f)) for f in sys.argv[1:]]' .github/workflows/project-auto-add.yml .github/workflows/project-auto-status.yml .github/workflows/claude-code-review.yml",
      "result": "All three edited workflows parse and each guarded job carries an if condition",
      "status": "passed",
      "evidence": "Local run 2026-09-20 on commit 533f7af82224 over origin/main d15d6d86d"
    },
    {
      "command": "python3 -c 'import yaml; yaml.safe_load(open(\".github/workflows/dev-enforcement.yml\"))'",
      "result": "The workflow parses on this branch with jobs title-check and pr-status, the rewrite that landed in #1054, so archiving it is no longer warranted and that part of this branch is gone",
      "status": "passed",
      "evidence": "Local run 2026-09-20; the file on this branch is byte identical to the copy on main d15d6d86d"
    },
    {
      "command": "git diff origin/main HEAD --stat",
      "result": "Three workflow files changed, eleven insertions and two deletions, no other path touched",
      "status": "passed",
      "evidence": "Local run 2026-09-20 in the rebased worktree; the earlier rename of dev-enforcement.yml no longer appears"
    },
    {
      "command": "GitHub Actions run of the guarded jobs on this pull request from the dmitrii-f-t27 fork",
      "result": "add-to-project, pr-opened and claude-review all report skipping instead of failing",
      "status": "passed",
      "evidence": "Checks on this PR from 2026-09-16 (run 35071039921 and siblings) show the three jobs as skipping, because pull_request workflows run from the PR merge ref and the PR exercises its own guards"
    }
  ],
  "limitations": [
    "Fork PRs will no longer be auto-added to project #6 or receive a Claude review; switching the two project workflows to pull_request_target would restore board updates with secrets available, but that is a policy choice for the repository owner.",
    "The Brain CI gate (brain health NOT MEASURED, no Score line from tri stress --health) fails on every run, fork or not, and is out of scope here.",
    "Whether the rewritten dev-enforcement workflow behaves correctly on fork pull requests is not measured here; its pr-status job carries continue-on-error, which is why this branch stopped touching it."
  ],
  "tags": [
    "ci",
    "workflows",
    "fork_prs",
    "hygiene"
  ],
  "blog": {
    "title": "Fork pull requests stop failing checks they could never pass",
    "summary": "Why three bot workflows went red on every pull request from a fork, what GitHub withholds from such runs on purpose, and the three one-line guards that turn those failures into skips.",
    "outline": [
      "Every pull request opened from a fork in this repository carried red checks that had nothing to do with the change: three jobs asked for repository secrets that GitHub deliberately withholds on pull_request events from forks, and failed before doing any work.",
      "The change adds one job-level condition to each secret-bound job, so a pull request whose head repository is not this repository skips those jobs instead of failing them, while same-repo pull requests and the issue-driven project automation behave exactly as before.",
      "A fourth failure from the same family, the dev-enforcement workflow that had not parsed since March, was going to be archived by this branch; #1054 rewrote the file on main instead, so the branch was rebased and that part dropped rather than carried further."
    ]
  }
}

Do not merge without the owner's approval.

🤖 Generated with Claude Code

Three workflows depend on repository secrets (PROJECT_TOKEN, CLAUDE_CODE_OAUTH_TOKEN)
that GitHub withholds on pull_request events from forks, so every fork PR has been
collecting red checks that can never pass: add-to-project ("Input required and not
supplied: github-token"), pr-opened ("set the GH_TOKEN environment variable") and
claude-review (empty claude_code_oauth_token). Each job now skips when the PR head
repository is not this repository; same-repo PRs and issue events are unchanged.

The branch also archived .github/workflows/dev-enforcement.yml, which had not
parsed since gHashTag#357. That part is dropped: gHashTag#1054 rewrote the file on main, it parses,
and its pr-status job already carries continue-on-error for fork pull requests.
Only the three guards remain.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@dmitrii-f-t27 dmitrii-f-t27 changed the title ci: skip secret-bound bot workflows on fork PRs; archive the unparseable dev-enforcement workflow ci: skip secret-bound bot workflows on fork pull requests Sep 21, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant