You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The review check has been passing without reviewing anything since 2026-08-03. It reports conclusion=success while the action skips, so every PR merged since then looked reviewed and wasn't.
This is self-inflicted and I caused it. Sequence:
claude-code-action validates that the workflow file it's running from is identical to the copy on the repository's default branch (main here). If it isn't, it skips — and exits success, not failure:
##[warning]Skipping action due to workflow validation: Workflow validation failed.
The workflow file must exist and have identical content to the version on the
repository's default branch.
...
Exiting due to workflow validation skip
##[end-action id=...run;outcome=success;conclusion=success;duration_ms=1724]
On 2026-08-03Skip the AI review job on Dependabot PRs #423 merged the Dependabot-skip guard into .github/workflows/claude-code-review.yml on dev. main still has the 2026-07-26 version ("Skip review on release PRs; widen the reviewer tool allowlist"). The only difference is the 8-line dependabot comment plus github.actor != 'dependabot[bot]' &&.
Every PR targets dev. So the running workflow never matches main, validation fails, and the action skips — on every PR, silently, green.
Confirmed on two PRs opened today (#426 and #427): both review jobs completed "successfully" in 12-13 seconds, versus the ~4-5 minutes a real review of the same size takes in the sibling repo, and both logs contain the validation-failure warning. Neither produced a review.
The tell is the duration. A green review check that finishes in ~12s has not read anything.
Expected Behavior
Either the review actually runs on PRs to dev, or the check fails loudly when it can't. A skip that reports success is worse than no check, because it manufactures confidence.
Suggested Fix
Sync main's copy of claude-code-review.yml with dev's so validation passes. Two ways:
Cherry-pick the workflow file onto main directly — fixes it immediately, no release needed. My recommendation, since the change is a comment plus one if: condition with no runtime effect on main.
Wait for the next dev → main release, which syncs it as a side effect. Correct but leaves the gate dead until then.
Worth knowing either way: PRs that themselves modify workflow files will always skip review under this validation model, which is by design and called out in the action's own message. #427 touches three workflow files, so its review would skip even with main synced. That's acceptable as long as it's understood rather than mistaken for a passing review.
Additional Context
Two things I'd flag beyond the fix:
This is the second false-green of the same shape I've hit today (the other was in PerformanceMonitor: a green review check with no review comment). The general lesson is that "check is green" and "check did its job" are different claims, and for the review gate specifically the cheap discriminator is job duration — seconds means skipped.
The irony worth recording: Skip the AI review job on Dependabot PRs #423 was itself merged with 0 review comments, which is exactly what this bug predicts. The change that disabled the gate was the first PR to benefit from it being disabled.
Component
CI
Describe the Bug
The
reviewcheck has been passing without reviewing anything since 2026-08-03. It reportsconclusion=successwhile the action skips, so every PR merged since then looked reviewed and wasn't.This is self-inflicted and I caused it. Sequence:
claude-code-actionvalidates that the workflow file it's running from is identical to the copy on the repository's default branch (mainhere). If it isn't, it skips — and exits success, not failure:On 2026-08-03 Skip the AI review job on Dependabot PRs #423 merged the Dependabot-skip guard into
.github/workflows/claude-code-review.ymlon dev.mainstill has the 2026-07-26 version ("Skip review on release PRs; widen the reviewer tool allowlist"). The only difference is the 8-line dependabot comment plusgithub.actor != 'dependabot[bot]' &&.Every PR targets dev. So the running workflow never matches
main, validation fails, and the action skips — on every PR, silently, green.Confirmed on two PRs opened today (#426 and #427): both
reviewjobs completed "successfully" in 12-13 seconds, versus the ~4-5 minutes a real review of the same size takes in the sibling repo, and both logs contain the validation-failure warning. Neither produced a review.The tell is the duration. A green
reviewcheck that finishes in ~12s has not read anything.Expected Behavior
Either the review actually runs on PRs to
dev, or the check fails loudly when it can't. A skip that reports success is worse than no check, because it manufactures confidence.Suggested Fix
Sync
main's copy ofclaude-code-review.ymlwithdev's so validation passes. Two ways:maindirectly — fixes it immediately, no release needed. My recommendation, since the change is a comment plus oneif:condition with no runtime effect onmain.dev→mainrelease, which syncs it as a side effect. Correct but leaves the gate dead until then.Worth knowing either way: PRs that themselves modify workflow files will always skip review under this validation model, which is by design and called out in the action's own message. #427 touches three workflow files, so its review would skip even with
mainsynced. That's acceptable as long as it's understood rather than mistaken for a passing review.Additional Context
Two things I'd flag beyond the fix:
reviewcheck with no review comment). The general lesson is that "check is green" and "check did its job" are different claims, and for the review gate specifically the cheap discriminator is job duration — seconds means skipped.