diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml index e4fe73f596..202c7b565e 100644 --- a/.github/workflows/claude-code-review.yml +++ b/.github/workflows/claude-code-review.yml @@ -12,6 +12,10 @@ on: jobs: claude-review: + # CLAUDE_CODE_OAUTH_TOKEN is a repository secret, and secrets are withheld on + # pull_request events from forks, so the action started with an empty token + # and failed on every fork PR. Skip fork PRs; same-repo PRs still get reviewed. + if: github.event.pull_request.head.repo.full_name == github.repository # Optional: Filter by PR author # if: | # github.event.pull_request.user.login == 'external-contributor' || diff --git a/.github/workflows/project-auto-add.yml b/.github/workflows/project-auto-add.yml index 4c82f26d9b..debcce4074 100644 --- a/.github/workflows/project-auto-add.yml +++ b/.github/workflows/project-auto-add.yml @@ -13,6 +13,10 @@ on: jobs: add-to-project: + # Pull requests from forks run without repository secrets, so PROJECT_TOKEN is + # empty there and the action fails with "Input required and not supplied: + # github-token". Skip those runs instead of failing them. + if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository runs-on: ubuntu-latest steps: - uses: actions/add-to-project@v1.0.2 diff --git a/.github/workflows/project-auto-status.yml b/.github/workflows/project-auto-status.yml index ea0ab1922e..e9ad8ea75f 100644 --- a/.github/workflows/project-auto-status.yml +++ b/.github/workflows/project-auto-status.yml @@ -70,7 +70,8 @@ jobs: # When a PR is opened → set "In review" pr-opened: - if: github.event_name == 'pull_request' && github.event.action == 'opened' + # Fork PRs have no PROJECT_TOKEN (secrets are withheld on pull_request from forks). + if: github.event_name == 'pull_request' && github.event.action == 'opened' && github.event.pull_request.head.repo.full_name == github.repository runs-on: ubuntu-latest steps: - name: Get project item ID @@ -115,7 +116,7 @@ jobs: # When a PR is merged → set PR + linked issues to "Done" pr-merged: - if: github.event_name == 'pull_request' && github.event.action == 'closed' && github.event.pull_request.merged == true + if: github.event_name == 'pull_request' && github.event.action == 'closed' && github.event.pull_request.merged == true && github.event.pull_request.head.repo.full_name == github.repository runs-on: ubuntu-latest steps: - name: Move PR to Done