You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Single failure caused by empty GH_TOKEN on a Dependabot-triggered run — gh auth status exits 1 with "not logged into any GitHub hosts"
9 cancellations are concurrency-group auto-cancels (burst of events at 00:48–00:50 UTC); expected behavior, not a defect
20 skips are idempotency/no-eligible-PRs exits in the engine; expected behavior
Action required: Confirm whether Dependabot runs should have access to DON_PETRY_BOT_GH_PAT; if yes, configure Dependabot secret access at the repo or org level.
You are not logged into any GitHub hosts. To log in, run: gh auth login
##[error]gh auth status failed
##[error]Process completed with exit code 1.
Step: "Validate GH_TOKEN auth + scopes" (the inline gh auth status check block in pr-review.yml)
Script: Inline shell in pr-review.yml — the block starting set -euo pipefail / if auth_status="$(gh auth status 2>&1)")
Root cause: The env block in the job logs shows GH_TOKEN: (empty string). The run header reports Secret source: Dependabot. GitHub restricts which secrets Dependabot-triggered workflows can access: repository secrets are accessible only if explicitly granted, and secrets: inherit in the calling workflow (pr-review-trigger.yml) passes only the secrets that the Dependabot context actually resolved. DON_PETRY_BOT_GH_PAT was not resolved, so GH_TOKEN arrived as empty, and gh CLI fell back to "not logged in."
Scopes currently present: None — GH_TOKEN is empty; gh auth status cannot authenticate at all.
Scopes missing / insufficient:
Scope
Why needed
Status
repo
Read PR content, submit reviews
Missing (token absent)
read:org
Resolve team-based reviewer requests
Missing (token absent)
Recommendation:
The token itself is not reaching the Dependabot job. Fix the secret delivery first (see Recommendations §5) — scope validation is moot until the token is present.
Once the token is delivered, the existing scope-check logic in pr-review.yml will validate repo + read:org or contents + pull_requests:write automatically.
5. Recommendations
Grant Dependabot access to DON_PETRY_BOT_GH_PAT
What: In the GitHub repo settings → Secrets and variables → Dependabot → add DON_PETRY_BOT_GH_PAT (if it is a repository secret) or ensure it is an org-level Dependabot secret. No workflow file changes needed.
Why: GitHub isolates Dependabot from Actions secrets by default; secrets: inherit in pr-review-trigger.yml can only forward secrets that Dependabot was granted access to. Without this, every Dependabot-opened or -synchronized PR will hit the same auth failure.
Expected impact: Eliminates this failure class entirely for Dependabot-triggered runs.
Urgency: HIGH — reproducible on every Dependabot PR event; currently one failure but will recur whenever Dependabot opens or updates a PR.
Consider skipping review for Dependabot PRs at the trigger level
What: Add a job-level condition to pr-review-trigger.yml — e.g., if: github.actor != 'dependabot[bot]' — as a fallback if granting Dependabot the PAT secret is undesirable for security reasons.
Why: Dependabot PRs are machine-generated dependency bumps; human review may not be necessary and the secret isolation issue makes the workflow reliably fail for them.
Expected impact: Converts failures for Dependabot runs into clean skips, eliminating noise without requiring secret reconfiguration.
Urgency: MEDIUM — adopt only if option 1 above is not pursued.
Investigate cancellation burst at 00:48–00:50 UTC
What: Inspect what triggered the 7 simultaneous workflow runs at 00:49–00:50 UTC (runs #26395–#26403). If it is a check_suite fanout for a large PR, consider narrowing the check_suite filter (e.g., only check_suite events from specific apps).
Why: While concurrency-group cancellation is working correctly, a burst of 7+ simultaneous triggers suggests a high-frequency event source that could eventually cause queuing or cost impact.
Urgency: LOW — system is self-healing via concurrency; cosmetic/cost issue only.
6. Health Score
Health: 8/10 — One isolated auth failure on a Dependabot-triggered run; all other runs succeed, skip, or cancel expectedly, and the fix is a single secret-access configuration change.
1. Executive Summary
Status: WARNING
Period: 2026-06-18T23:31:14Z – 2026-06-19T07:46:41Z
Result: 1 of 100 runs failed (1%); 9 cancelled (9%); 20 skipped (20%)
Key findings:
GH_TOKENon a Dependabot-triggered run —gh auth statusexits 1 with "not logged into any GitHub hosts"Action required: Confirm whether Dependabot runs should have access to
DON_PETRY_BOT_GH_PAT; if yes, configure Dependabot secret access at the repo or org level.2. Failure Breakdown
You are not logged into any GitHub hosts. To log in, run: gh auth login→gh auth status failed3. Error Patterns
Category: Missing GH_TOKEN (Dependabot secret isolation)
Exact error from run #26464:
gh auth statuscheck block inpr-review.yml)pr-review.yml— the block startingset -euo pipefail/if auth_status="$(gh auth status 2>&1)")GH_TOKEN:(empty string). The run header reportsSecret source: Dependabot. GitHub restricts which secrets Dependabot-triggered workflows can access: repository secrets are accessible only if explicitly granted, andsecrets: inheritin the calling workflow (pr-review-trigger.yml) passes only the secrets that the Dependabot context actually resolved.DON_PETRY_BOT_GH_PATwas not resolved, soGH_TOKENarrived as empty, andghCLI fell back to "not logged in."PR_URL_OVERRIDE: https://github.com/petry-projects/.github-private/pull/779), which is likely a Dependabot PR.4. Token Scope Analysis
From the failing run's env block:
GH_TOKENCLAUDE_CODE_OAUTH_TOKENCOPILOT_GITHUB_TOKENScopes currently present: None —
GH_TOKENis empty;gh auth statuscannot authenticate at all.Scopes missing / insufficient:
reporead:orgRecommendation:
pr-review.ymlwill validaterepo+read:orgorcontents+pull_requests:writeautomatically.5. Recommendations
Grant Dependabot access to
DON_PETRY_BOT_GH_PATDON_PETRY_BOT_GH_PAT(if it is a repository secret) or ensure it is an org-level Dependabot secret. No workflow file changes needed.secrets: inheritinpr-review-trigger.ymlcan only forward secrets that Dependabot was granted access to. Without this, every Dependabot-opened or -synchronized PR will hit the same auth failure.Consider skipping review for Dependabot PRs at the trigger level
pr-review-trigger.yml— e.g.,if: github.actor != 'dependabot[bot]'— as a fallback if granting Dependabot the PAT secret is undesirable for security reasons.Investigate cancellation burst at 00:48–00:50 UTC
check_suitefilter (e.g., onlycheck_suiteevents from specific apps).6. Health Score
Health: 8/10 — One isolated auth failure on a Dependabot-triggered run; all other runs succeed, skip, or cancel expectedly, and the fix is a single secret-access configuration change.