Skip to content

Sync claude-code-review.yml to main so the review gate validates again - #429

Merged
erikdarlingdata merged 1 commit into
mainfrom
sync/claude-review-workflow-to-main
Aug 11, 2026
Merged

erikdarlingdata merged 1 commit into
mainfrom
sync/claude-review-workflow-to-main

Conversation

@erikdarlingdata

Copy link
Copy Markdown
Owner

What does this PR do?

Fixes #428.

Cherry-picks 6decaf8 from dev onto main so .github/workflows/claude-code-review.yml is byte-identical on the default branch again. claude-code-action validates the running workflow file against the default-branch copy and silently skips with conclusion=success on any mismatch, so this 8-line drift (the Dependabot skip from #423) disabled the review gate on every PR since 2026-08-03.

Direct push to main is blocked by repository rules, hence this PR. The review check on this PR will itself skip by design (it modifies the workflow file). Verification that the gate is live again happens separately: re-run the review on #426 and confirm the log shows a real review (token spend, no validation warning).

🤖 Generated with Claude Code

Every Dependabot PR carried a red X from the review check, which failed
twice over instead of reviewing: claude-code-action rejects non-human
actors outright ("Workflow initiated by non-human actor: dependabot"),
and a dependabot-triggered run draws from the Dependabot secret store,
not the Actions one, so CLAUDE_CODE_OAUTH_TOKEN was empty regardless.
Both open bumps (#420, #422) build and pass tests; only this check
blocked them. A version bump has nothing an AI review would catch that
build-and-test doesn't, so skip - neutral, not red - in the same spirit
as the existing draft/fork/release-PR exclusions.

Cherry-picked from dev (6decaf8) directly onto main because
claude-code-action validates the running workflow file against the
default-branch copy and silently skips with conclusion=success on any
mismatch. This 8-line drift disabled the review gate on every PR since
2026-08-03.

Fixes #428

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@erikdarlingdata
erikdarlingdata merged commit 5bcfdaa into main Aug 11, 2026
3 of 4 checks passed
@erikdarlingdata
erikdarlingdata deleted the sync/claude-review-workflow-to-main branch August 11, 2026 21:53
@claude

claude Bot commented Aug 11, 2026

Copy link
Copy Markdown

Reviewed. This is a pure CI workflow sync (.github/workflows/claude-code-review.yml only, +8/-0), cherry-picking the Dependabot skip condition from dev onto main. No application, T-SQL, or PlanViewer code is touched, so none of the correctness/untrusted-input/versioning conventions apply here.

The added condition (github.actor != 'dependabot[bot]') is straightforward and matches the documented rationale (non-human actor rejection + empty OAuth token from the Dependabot secret store). Logic reads correctly alongside the existing draft/fork/release-PR skip conditions — no precedence issues. Nothing to flag.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] The review check has passed without reviewing since 2026-08-03 — workflow validation skips but exits success

1 participant