PR Review Agent — Workflow Health Report
Workflow: pr-review.yml · petry-projects/.github-private
Report Date: 2026-06-05 | Analysis Window: Last 1 day
1. Executive Summary
Status: BLOCKING
Period: 2026-06-04 T15:09–T23:24 UTC
Result: 33 of 100 runs failed (33%) · 27 cancelled (cascading) · 19 succeeded · 21 skipped
Key findings:
- Primary blocker:
DON_PETRY_BOT_GH_PAT is missing the repo OAuth scope — all 32 event-triggered failures share this single root cause, onset ~19:26 UTC (after a PAT rotation event)
- Secondary issue: One Dependabot-triggered run (#4920) received an empty
GH_TOKEN because Dependabot secrets are not forwarded to the PAT variable
- Pattern: Runs #4897–#4933 (15:09–19:25 UTC) all succeeded; failures begin abruptly at #4934 (19:25:57 UTC), consistent with a secret rotation with missing scope
Action required: Regenerate DON_PETRY_BOT_GH_PAT with repo + read:org scopes and update the secret in GitHub repository/organization settings.
2. Failure Breakdown
| Failure Category |
Affected Runs |
Example Error Message |
Missing token scope (repo) |
32 |
GH_TOKEN is missing required scope: repo |
| Missing token entirely (Dependabot) |
1 (#4920) |
You are not logged into any GitHub hosts. To log in, run: gh auth login |
| Engine rate limit (Claude/Gemini/Copilot) |
0 |
— |
| GitHub API rate limit |
0 |
— |
| Timeout / infrastructure |
0 |
— |
| Other / unknown |
0 |
— |
Note: The 27 cancelled runs are not independent failures — they are upstream runs cancelled by the concurrency: cancel-in-progress: true policy when a newer run for the same PR slot was queued.
3. Error Patterns
Pattern A — Missing repo scope (32 runs, #4934–#4996)
Exact error message:
##[error]GH_TOKEN is missing required scope: repo
##[error]Process completed with exit code 1.
Originating step: Verify auth scopes (3rd step of the review job in current workflow version)
Originating script (inline bash in workflow):
required_scopes=(repo read:org)
for required_scope in "${required_scopes[@]}"; do
if ! grep -qE "(^|[[:space:]])${required_scope}([[:space:]]|$)" <<< "$normalized_scopes"; then
echo "::error::GH_TOKEN is missing required scope: ${required_scope}"
exit 1
fi
done
Root cause: The gh auth status output for the token github_pat_11CDFSYKQ0w50IHawIgb0w_*** (authenticated as donpetry-bot) does not contain the string repo in its Token scopes: line. The token authenticates successfully (login is confirmed) but was issued or rotated without the repo scope. The repo scope is required for cloning PR branches, listing repositories, reading PR metadata, and posting review comments via the GitHub REST API.
Pattern B — Empty GH_TOKEN on Dependabot run (1 run, #4920)
Exact error message:
You are not logged into any GitHub hosts. To log in, run: gh auth login
##[error]Process completed with exit code 1.
Originating step: Install review engine CLIs (older workflow version that embedded gh auth status inline rather than in a dedicated scope-check step)
Key diagnostic indicator from log:
Secret source: Dependabot
GH_TOKEN:
Root cause: GitHub does not forward organization/repository secrets to workflows triggered by Dependabot pull requests unless explicit permissions are configured. The DON_PETRY_BOT_GH_PAT secret is not available to Dependabot-context runs, so GH_TOKEN resolves to an empty string and gh finds no credentials.
4. Token Scope Analysis
Token observed: github_pat_11CDFSYKQ0w50IHawIgb0w_*** (authenticated as donpetry-bot)
| Scope |
Status |
Evidence |
repo |
MISSING |
GH_TOKEN is missing required scope: repo — all 32 recent failures |
read:org |
Unconfirmed |
Scope check exits on repo first; read:org status not confirmed from logs |
Why repo scope is critical for this workflow:
gh pr list, gh pr view, gh pr review — all require repo
actions/checkout fetching PR merge refs — requires repo
list-prs.sh and review-batch.sh scripts that enumerate and clone repositories — require repo
- Posting review comments via
gh — requires repo
Recommendation per scope:
| Missing Scope |
Recommendation |
repo |
Add repo scope when regenerating DON_PETRY_BOT_GH_PAT. For a fine-grained PAT: grant Contents: Read, Pull requests: Read and write, Metadata: Read on all target repositories |
read:org (verify) |
Confirm read:org is present in the regenerated PAT — required by list-prs.sh to enumerate org repositories |
5. Recommendations
[CRITICAL] Regenerate DON_PETRY_BOT_GH_PAT with correct scopes
In GitHub → Settings → Developer settings → Personal access tokens, regenerate the PAT for donpetry-bot with classic scopes repo (full) + read:org; or if fine-grained: Contents/Read, Pull requests/Read+Write, Metadata/Read on petry-projects org repos. Then update the secret value in organization or repository settings under DON_PETRY_BOT_GH_PAT. This single change immediately restores all event-triggered review runs to the pre-19:26 success rate. Every event-triggered run is currently failing at the scope check; no PR reviews are being performed.
[HIGH] Guard against Dependabot-triggered runs receiving empty GH_TOKEN
Add a job-level condition to the review job in .github/workflows/pr-review.yml:
jobs:
review:
if: github.actor != 'dependabot[bot]'
Or add an early-exit step:
- name: Skip if no token
if: env.GH_TOKEN == ''
run: |
echo "::warning::GH_TOKEN is empty — skipping review (Dependabot run?)"
exit 0
Dependabot PRs cannot receive the bot PAT; the job should exit cleanly rather than fail and produce noise. This eliminates false-failure noise for Dependabot PRs and reduces cancel-in-progress churn.
[MEDIUM] Echo detected scopes in Verify auth scopes step
After the scopes_line extraction, add:
echo "Detected scopes: $normalized_scopes"
Currently, logs only show which scope is missing but not which scopes are present, making PAT rotation debugging harder. This change cuts root-cause identification time significantly if this recurs.
[MEDIUM] Add PAT expiry and scope monitoring
Create a scheduled workflow (e.g., weekly) that runs gh auth status and validates scopes on DON_PETRY_BOT_GH_PAT, alerting via issue or Slack notification if scopes are insufficient or the PAT is near expiry. The current failure mode is entirely silent until all reviews stop working; proactive monitoring catches PAT rotation gaps before they become outages.
[LOW] Pin CLAUDE_CODE_VERSION to a specific semver
Set the CLAUDE_CODE_VERSION repository variable to a specific version (e.g., 1.2.3) rather than latest. This prevents unexpected CLI breakage when a new npm release contains breaking changes.
6. Health Score
2 / 10
Complete outage of all event-triggered PR reviews since ~19:26 UTC on 2026-06-04 due to a single PAT scope regression. One manual fix — regenerating the secret with the repo scope — fully restores service. The failure is contained to a single root cause with no collateral infrastructure damage, no data loss, and a known remediation path, which prevents this from scoring lower. The 27 cancelled runs and 21 skipped runs are not independent defects; the true defect surface is the two error patterns above.
PR Review Agent — Workflow Health Report
Workflow:
pr-review.yml·petry-projects/.github-privateReport Date: 2026-06-05 | Analysis Window: Last 1 day
1. Executive Summary
Status: BLOCKING
Period: 2026-06-04 T15:09–T23:24 UTC
Result: 33 of 100 runs failed (33%) · 27 cancelled (cascading) · 19 succeeded · 21 skipped
Key findings:
DON_PETRY_BOT_GH_PATis missing therepoOAuth scope — all 32 event-triggered failures share this single root cause, onset ~19:26 UTC (after a PAT rotation event)GH_TOKENbecause Dependabot secrets are not forwarded to the PAT variableAction required: Regenerate
DON_PETRY_BOT_GH_PATwithrepo+read:orgscopes and update the secret in GitHub repository/organization settings.2. Failure Breakdown
repo)GH_TOKEN is missing required scope: repoYou are not logged into any GitHub hosts. To log in, run: gh auth login3. Error Patterns
Pattern A — Missing
reposcope (32 runs, #4934–#4996)Exact error message:
Originating step:
Verify auth scopes(3rd step of thereviewjob in current workflow version)Originating script (inline bash in workflow):
Root cause: The
gh auth statusoutput for the tokengithub_pat_11CDFSYKQ0w50IHawIgb0w_***(authenticated asdonpetry-bot) does not contain the stringrepoin itsToken scopes:line. The token authenticates successfully (login is confirmed) but was issued or rotated without thereposcope. Thereposcope is required for cloning PR branches, listing repositories, reading PR metadata, and posting review comments via the GitHub REST API.Pattern B — Empty GH_TOKEN on Dependabot run (1 run, #4920)
Exact error message:
Originating step:
Install review engine CLIs(older workflow version that embeddedgh auth statusinline rather than in a dedicated scope-check step)Key diagnostic indicator from log:
Root cause: GitHub does not forward organization/repository secrets to workflows triggered by Dependabot pull requests unless explicit permissions are configured. The
DON_PETRY_BOT_GH_PATsecret is not available to Dependabot-context runs, soGH_TOKENresolves to an empty string andghfinds no credentials.4. Token Scope Analysis
Token observed:
github_pat_11CDFSYKQ0w50IHawIgb0w_***(authenticated asdonpetry-bot)repoGH_TOKEN is missing required scope: repo— all 32 recent failuresread:orgrepofirst;read:orgstatus not confirmed from logsWhy
reposcope is critical for this workflow:gh pr list,gh pr view,gh pr review— all requirerepoactions/checkoutfetching PR merge refs — requiresrepolist-prs.shandreview-batch.shscripts that enumerate and clone repositories — requirerepogh— requiresrepoRecommendation per scope:
reporeposcope when regeneratingDON_PETRY_BOT_GH_PAT. For a fine-grained PAT: grant Contents: Read, Pull requests: Read and write, Metadata: Read on all target repositoriesread:org(verify)read:orgis present in the regenerated PAT — required bylist-prs.shto enumerate org repositories5. Recommendations
[CRITICAL] Regenerate
DON_PETRY_BOT_GH_PATwith correct scopesIn GitHub → Settings → Developer settings → Personal access tokens, regenerate the PAT for
donpetry-botwith classic scopesrepo(full) +read:org; or if fine-grained: Contents/Read, Pull requests/Read+Write, Metadata/Read onpetry-projectsorg repos. Then update the secret value in organization or repository settings underDON_PETRY_BOT_GH_PAT. This single change immediately restores all event-triggered review runs to the pre-19:26 success rate. Every event-triggered run is currently failing at the scope check; no PR reviews are being performed.[HIGH] Guard against Dependabot-triggered runs receiving empty GH_TOKEN
Add a job-level condition to the
reviewjob in.github/workflows/pr-review.yml:Or add an early-exit step:
Dependabot PRs cannot receive the bot PAT; the job should exit cleanly rather than fail and produce noise. This eliminates false-failure noise for Dependabot PRs and reduces cancel-in-progress churn.
[MEDIUM] Echo detected scopes in
Verify auth scopesstepAfter the
scopes_lineextraction, add:Currently, logs only show which scope is missing but not which scopes are present, making PAT rotation debugging harder. This change cuts root-cause identification time significantly if this recurs.
[MEDIUM] Add PAT expiry and scope monitoring
Create a scheduled workflow (e.g., weekly) that runs
gh auth statusand validates scopes onDON_PETRY_BOT_GH_PAT, alerting via issue or Slack notification if scopes are insufficient or the PAT is near expiry. The current failure mode is entirely silent until all reviews stop working; proactive monitoring catches PAT rotation gaps before they become outages.[LOW] Pin
CLAUDE_CODE_VERSIONto a specific semverSet the
CLAUDE_CODE_VERSIONrepository variable to a specific version (e.g.,1.2.3) rather thanlatest. This prevents unexpected CLI breakage when a new npm release contains breaking changes.6. Health Score
2 / 10Complete outage of all event-triggered PR reviews since ~19:26 UTC on 2026-06-04 due to a single PAT scope regression. One manual fix — regenerating the secret with the
reposcope — fully restores service. The failure is contained to a single root cause with no collateral infrastructure damage, no data loss, and a known remediation path, which prevents this from scoring lower. The 27 cancelled runs and 21 skipped runs are not independent defects; the true defect surface is the two error patterns above.