Repository navigation
ci: fix fallback reviewer token permissions (checks/statuses read, GITHUB_TOKEN read-only) - #115
Conversation
Unlisted workflow scopes are none, so loadPrEvidence could not see CodeRabbit check-runs or commit statuses. Keep GITHUB_TOKEN read-only and omit CODEX_GITHUB_TOKEN from pull_request runs. Co-authored-by: Jonathan Borgwing <DevVig@users.noreply.github.com>
|
Warning Review limit reachedEnable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Next included review available in 15 minutes. View limit detailsLimit details: You’ve used the included review currently available. Your 69 included PR review attempts over the past 7 days set your current allowance at 1 review per hour. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (2)
Comment |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It changes CI workflow token permissions and PAT exposure boundaries, a security-sensitive area that warrants final human sign-off.
Review effort: Balanced
Findings: None
What changed in this PR
This PR hardens the token handling for the CodeRabbit→Codex fallback reviewer workflow. It corrects the GITHUB_TOKEN scopes so the read-only evidence collection (CodeRabbit check-runs and commit statuses) actually works, while keeping all writes on the CODEX_GITHUB_TOKEN PAT and preventing that PAT from being exposed to PR-checked-out code on pull_request runs. It is a follow-up to #114, which introduced the fallback reviewer.
Changes:
- Downgrade
GITHUB_TOKENpull-requests/issuesfromwritetoreadand addchecks: readandstatuses: readsoloadPrEvidenceno longer silently gets empty check-run/status lists. - Omit
CODEX_GITHUB_TOKENfrompull_requestruns (which are always dry-run) so the PAT is not available when PR code is checked out. - Document the read-only token posture in
docs/ops/pr-review-policy.md.
| File | Description |
|---|---|
.github/workflows/coderabbit-fallback-review.yml |
Adjusts GITHUB_TOKEN permissions (read-only + checks/statuses read) and gates the PAT env out of pull_request runs. |
docs/ops/pr-review-policy.md |
Adds a sentence noting the workflow token is read-only plus checks/statuses read, with writes via CODEX_GITHUB_TOKEN. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
What
Give the fallback reviewer
GITHUB_TOKENchecks: readandstatuses: read, drop unused write scopes, and omitCODEX_GITHUB_TOKENfrompull_requestruns.Why
Unlisted workflow permission scopes are
none.loadPrEvidencereads CodeRabbit check-runs and commit statuses; those 403s were swallowed into empty lists, so in-progress and rate-limit evidence never appeared. Writes already go throughCODEX_GITHUB_TOKEN. Same-repopull_requestjobs check out PR code, so they must not receive the PAT.Follow-up to #114 (Jon approved the fallback-only rollout on Oct 5, 2026).
How was this tested?
.github/workflows/coderabbit-fallback-review.ymlpermissions and step env against GitHub’s unlisted-scope-is-none ruledocs/ops/pr-review-policy.mdunder Automatic Codex fallbackChecklist