Skip to content

ci: fix fallback reviewer token permissions (checks/statuses read, GITHUB_TOKEN read-only) - #115

Merged
DevVig merged 1 commit into
mainfrom
cursor/fix-fallback-reviewer-token-permissions-394b
Oct 6, 2026
Merged

DevVig merged 1 commit into
mainfrom
cursor/fix-fallback-reviewer-token-permissions-394b

Conversation

@DevVig

@DevVig DevVig commented Oct 6, 2026

Copy link
Copy Markdown
Owner

What

Give the fallback reviewer GITHUB_TOKEN checks: read and statuses: read, drop unused write scopes, and omit CODEX_GITHUB_TOKEN from pull_request runs.

Why

Unlisted workflow permission scopes are none. loadPrEvidence reads CodeRabbit check-runs and commit statuses; those 403s were swallowed into empty lists, so in-progress and rate-limit evidence never appeared. Writes already go through CODEX_GITHUB_TOKEN. Same-repo pull_request jobs check out PR code, so they must not receive the PAT.

Follow-up to #114 (Jon approved the fallback-only rollout on Oct 5, 2026).

How was this tested?

  • Inspected .github/workflows/coderabbit-fallback-review.yml permissions and step env against GitHub’s unlisted-scope-is-none rule
  • Policy sentence added in docs/ops/pr-review-policy.md under Automatic Codex fallback
  • Script, cron, and CodeRabbit settings unchanged

Checklist

  • Protocol unchanged
  • Not an adapter PR
  • Nothing added to the daemon's idle footprint
Open in Web Open in Cursor 

Unlisted workflow scopes are none, so loadPrEvidence could not see
CodeRabbit check-runs or commit statuses. Keep GITHUB_TOKEN read-only
and omit CODEX_GITHUB_TOKEN from pull_request runs.

Co-authored-by: Jonathan Borgwing <DevVig@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 03:23
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

Next included review available in 15 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 69 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Essentials
  • Run ID: 55f157bf-01ac-4c48-b6f6-f15b7021e491
📥 Commits

Reviewing files that changed from the base of the PR and between 76ae9ed and be43bcd.

📒 Files selected for processing (2)
  • .github/workflows/coderabbit-fallback-review.yml
  • docs/ops/pr-review-policy.md
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It changes CI workflow token permissions and PAT exposure boundaries, a security-sensitive area that warrants final human sign-off.

Review effort: Balanced
Findings: None

What changed in this PR

This PR hardens the token handling for the CodeRabbit→Codex fallback reviewer workflow. It corrects the GITHUB_TOKEN scopes so the read-only evidence collection (CodeRabbit check-runs and commit statuses) actually works, while keeping all writes on the CODEX_GITHUB_TOKEN PAT and preventing that PAT from being exposed to PR-checked-out code on pull_request runs. It is a follow-up to #114, which introduced the fallback reviewer.

Changes:

  • Downgrade GITHUB_TOKEN pull-requests/issues from write to read and add checks: read and statuses: read so loadPrEvidence no longer silently gets empty check-run/status lists.
  • Omit CODEX_GITHUB_TOKEN from pull_request runs (which are always dry-run) so the PAT is not available when PR code is checked out.
  • Document the read-only token posture in docs/ops/pr-review-policy.md.
File Description
.github/​workflows/​coderabbit-fallback-review.yml Adjusts GITHUB_TOKEN permissions (read-only + checks/statuses read) and gates the PAT env out of pull_request runs.
docs/​ops/​pr-review-policy.md Adds a sentence noting the workflow token is read-only plus checks/statuses read, with writes via CODEX_GITHUB_TOKEN.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@DevVig
DevVig merged commit 2b1e295 into main Oct 6, 2026
9 checks passed
@DevVig
DevVig deleted the cursor/fix-fallback-reviewer-token-permissions-394b branch October 6, 2026 03:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants