Skip to content

PR Review Agent — failures detected 2026-06-05 #436

Description

@github-actions

PR Review Agent — Workflow Health Report

Workflow: pr-review.yml · petry-projects/.github-private
Report Date: 2026-06-05 | Analysis Window: Last 1 day


1. Executive Summary

Status: BLOCKING
Period: 2026-06-04 T15:09–T23:24 UTC
Result: 33 of 100 runs failed (33%) · 27 cancelled (cascading) · 19 succeeded · 21 skipped

Key findings:

  • Primary blocker: DON_PETRY_BOT_GH_PAT is missing the repo OAuth scope — all 32 event-triggered failures share this single root cause, onset ~19:26 UTC (after a PAT rotation event)
  • Secondary issue: One Dependabot-triggered run (#4920) received an empty GH_TOKEN because Dependabot secrets are not forwarded to the PAT variable
  • Pattern: Runs #4897–#4933 (15:09–19:25 UTC) all succeeded; failures begin abruptly at #4934 (19:25:57 UTC), consistent with a secret rotation with missing scope

Action required: Regenerate DON_PETRY_BOT_GH_PAT with repo + read:org scopes and update the secret in GitHub repository/organization settings.


2. Failure Breakdown

Failure Category Affected Runs Example Error Message
Missing token scope (repo) 32 GH_TOKEN is missing required scope: repo
Missing token entirely (Dependabot) 1 (#4920) You are not logged into any GitHub hosts. To log in, run: gh auth login
Engine rate limit (Claude/Gemini/Copilot) 0 —
GitHub API rate limit 0 —
Timeout / infrastructure 0 —
Other / unknown 0 —

Note: The 27 cancelled runs are not independent failures — they are upstream runs cancelled by the concurrency: cancel-in-progress: true policy when a newer run for the same PR slot was queued.


3. Error Patterns

Pattern A — Missing repo scope (32 runs, #4934–#4996)

Exact error message:

##[error]GH_TOKEN is missing required scope: repo
##[error]Process completed with exit code 1.

Originating step: Verify auth scopes (3rd step of the review job in current workflow version)

Originating script (inline bash in workflow):

required_scopes=(repo read:org)
for required_scope in "${required_scopes[@]}"; do
  if ! grep -qE "(^|[[:space:]])${required_scope}([[:space:]]|$)" <<< "$normalized_scopes"; then
    echo "::error::GH_TOKEN is missing required scope: ${required_scope}"
    exit 1
  fi
done

Root cause: The gh auth status output for the token github_pat_11CDFSYKQ0w50IHawIgb0w_*** (authenticated as donpetry-bot) does not contain the string repo in its Token scopes: line. The token authenticates successfully (login is confirmed) but was issued or rotated without the repo scope. The repo scope is required for cloning PR branches, listing repositories, reading PR metadata, and posting review comments via the GitHub REST API.


Pattern B — Empty GH_TOKEN on Dependabot run (1 run, #4920)

Exact error message:

You are not logged into any GitHub hosts. To log in, run: gh auth login
##[error]Process completed with exit code 1.

Originating step: Install review engine CLIs (older workflow version that embedded gh auth status inline rather than in a dedicated scope-check step)

Key diagnostic indicator from log:

Secret source: Dependabot
GH_TOKEN: 

Root cause: GitHub does not forward organization/repository secrets to workflows triggered by Dependabot pull requests unless explicit permissions are configured. The DON_PETRY_BOT_GH_PAT secret is not available to Dependabot-context runs, so GH_TOKEN resolves to an empty string and gh finds no credentials.


4. Token Scope Analysis

Token observed: github_pat_11CDFSYKQ0w50IHawIgb0w_*** (authenticated as donpetry-bot)

Scope Status Evidence
repo MISSING GH_TOKEN is missing required scope: repo — all 32 recent failures
read:org Unconfirmed Scope check exits on repo first; read:org status not confirmed from logs

Why repo scope is critical for this workflow:

  • gh pr list, gh pr view, gh pr review — all require repo
  • actions/checkout fetching PR merge refs — requires repo
  • list-prs.sh and review-batch.sh scripts that enumerate and clone repositories — require repo
  • Posting review comments via gh — requires repo

Recommendation per scope:

Missing Scope Recommendation
repo Add repo scope when regenerating DON_PETRY_BOT_GH_PAT. For a fine-grained PAT: grant Contents: Read, Pull requests: Read and write, Metadata: Read on all target repositories
read:org (verify) Confirm read:org is present in the regenerated PAT — required by list-prs.sh to enumerate org repositories

5. Recommendations

[CRITICAL] Regenerate DON_PETRY_BOT_GH_PAT with correct scopes

In GitHub → Settings → Developer settings → Personal access tokens, regenerate the PAT for donpetry-bot with classic scopes repo (full) + read:org; or if fine-grained: Contents/Read, Pull requests/Read+Write, Metadata/Read on petry-projects org repos. Then update the secret value in organization or repository settings under DON_PETRY_BOT_GH_PAT. This single change immediately restores all event-triggered review runs to the pre-19:26 success rate. Every event-triggered run is currently failing at the scope check; no PR reviews are being performed.


[HIGH] Guard against Dependabot-triggered runs receiving empty GH_TOKEN

Add a job-level condition to the review job in .github/workflows/pr-review.yml:

jobs:
  review:
    if: github.actor != 'dependabot[bot]'

Or add an early-exit step:

- name: Skip if no token
  if: env.GH_TOKEN == ''
  run: |
    echo "::warning::GH_TOKEN is empty — skipping review (Dependabot run?)"
    exit 0

Dependabot PRs cannot receive the bot PAT; the job should exit cleanly rather than fail and produce noise. This eliminates false-failure noise for Dependabot PRs and reduces cancel-in-progress churn.


[MEDIUM] Echo detected scopes in Verify auth scopes step

After the scopes_line extraction, add:

echo "Detected scopes: $normalized_scopes"

Currently, logs only show which scope is missing but not which scopes are present, making PAT rotation debugging harder. This change cuts root-cause identification time significantly if this recurs.


[MEDIUM] Add PAT expiry and scope monitoring

Create a scheduled workflow (e.g., weekly) that runs gh auth status and validates scopes on DON_PETRY_BOT_GH_PAT, alerting via issue or Slack notification if scopes are insufficient or the PAT is near expiry. The current failure mode is entirely silent until all reviews stop working; proactive monitoring catches PAT rotation gaps before they become outages.


[LOW] Pin CLAUDE_CODE_VERSION to a specific semver

Set the CLAUDE_CODE_VERSION repository variable to a specific version (e.g., 1.2.3) rather than latest. This prevents unexpected CLI breakage when a new npm release contains breaking changes.


6. Health Score

2 / 10

Complete outage of all event-triggered PR reviews since ~19:26 UTC on 2026-06-04 due to a single PAT scope regression. One manual fix — regenerating the secret with the repo scope — fully restores service. The failure is contained to a single root cause with no collateral infrastructure damage, no data loss, and a known remediation path, which prevents this from scoring lower. The 27 cancelled runs and 21 skipped runs are not independent defects; the true defect surface is the two error patterns above.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    automated-reportCreated by automated workflowhealth-checkAutomated health check report

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions