Skip to content

PR Review Agent — failures detected 2026-06-19 #788

Description

@github-actions

1. Executive Summary

Status: WARNING
Period: 2026-06-18T23:31:14Z – 2026-06-19T07:46:41Z
Result: 1 of 100 runs failed (1%); 9 cancelled (9%); 20 skipped (20%)

Key findings:

  • Single failure caused by empty GH_TOKEN on a Dependabot-triggered run — gh auth status exits 1 with "not logged into any GitHub hosts"
  • 9 cancellations are concurrency-group auto-cancels (burst of events at 00:48–00:50 UTC); expected behavior, not a defect
  • 20 skips are idempotency/no-eligible-PRs exits in the engine; expected behavior

Action required: Confirm whether Dependabot runs should have access to DON_PETRY_BOT_GH_PAT; if yes, configure Dependabot secret access at the repo or org level.


2. Failure Breakdown

Failure Category Affected Runs Example Error Message
Permission / auth error — missing token (Dependabot secret isolation) #26464 (1 run) You are not logged into any GitHub hosts. To log in, run: gh auth login → gh auth status failed

3. Error Patterns

Category: Missing GH_TOKEN (Dependabot secret isolation)

Exact error from run #26464:

You are not logged into any GitHub hosts. To log in, run: gh auth login
##[error]gh auth status failed
##[error]Process completed with exit code 1.
  • Step: "Validate GH_TOKEN auth + scopes" (the inline gh auth status check block in pr-review.yml)
  • Script: Inline shell in pr-review.yml — the block starting set -euo pipefail / if auth_status="$(gh auth status 2>&1)")
  • Root cause: The env block in the job logs shows GH_TOKEN: (empty string). The run header reports Secret source: Dependabot. GitHub restricts which secrets Dependabot-triggered workflows can access: repository secrets are accessible only if explicitly granted, and secrets: inherit in the calling workflow (pr-review-trigger.yml) passes only the secrets that the Dependabot context actually resolved. DON_PETRY_BOT_GH_PAT was not resolved, so GH_TOKEN arrived as empty, and gh CLI fell back to "not logged in."
  • Triggered by: The run was processing PR chore(deps): bump the actions group across 1 directory with 4 updates #779 (PR_URL_OVERRIDE: https://github.com/petry-projects/.github-private/pull/779), which is likely a Dependabot PR.

4. Token Scope Analysis

From the failing run's env block:

Token field Value observed
GH_TOKEN (empty)
CLAUDE_CODE_OAUTH_TOKEN (empty — redacted or absent)
COPILOT_GITHUB_TOKEN (empty — redacted or absent)

Scopes currently present: None — GH_TOKEN is empty; gh auth status cannot authenticate at all.

Scopes missing / insufficient:

Scope Why needed Status
repo Read PR content, submit reviews Missing (token absent)
read:org Resolve team-based reviewer requests Missing (token absent)

Recommendation:

  • The token itself is not reaching the Dependabot job. Fix the secret delivery first (see Recommendations §5) — scope validation is moot until the token is present.
  • Once the token is delivered, the existing scope-check logic in pr-review.yml will validate repo + read:org or contents + pull_requests:write automatically.

5. Recommendations

  1. Grant Dependabot access to DON_PETRY_BOT_GH_PAT

    • What: In the GitHub repo settings → Secrets and variables → Dependabot → add DON_PETRY_BOT_GH_PAT (if it is a repository secret) or ensure it is an org-level Dependabot secret. No workflow file changes needed.
    • Why: GitHub isolates Dependabot from Actions secrets by default; secrets: inherit in pr-review-trigger.yml can only forward secrets that Dependabot was granted access to. Without this, every Dependabot-opened or -synchronized PR will hit the same auth failure.
    • Expected impact: Eliminates this failure class entirely for Dependabot-triggered runs.
    • Urgency: HIGH — reproducible on every Dependabot PR event; currently one failure but will recur whenever Dependabot opens or updates a PR.
  2. Consider skipping review for Dependabot PRs at the trigger level

    • What: Add a job-level condition to pr-review-trigger.yml — e.g., if: github.actor != 'dependabot[bot]' — as a fallback if granting Dependabot the PAT secret is undesirable for security reasons.
    • Why: Dependabot PRs are machine-generated dependency bumps; human review may not be necessary and the secret isolation issue makes the workflow reliably fail for them.
    • Expected impact: Converts failures for Dependabot runs into clean skips, eliminating noise without requiring secret reconfiguration.
    • Urgency: MEDIUM — adopt only if option 1 above is not pursued.
  3. Investigate cancellation burst at 00:48–00:50 UTC

    • What: Inspect what triggered the 7 simultaneous workflow runs at 00:49–00:50 UTC (runs #26395–#26403). If it is a check_suite fanout for a large PR, consider narrowing the check_suite filter (e.g., only check_suite events from specific apps).
    • Why: While concurrency-group cancellation is working correctly, a burst of 7+ simultaneous triggers suggests a high-frequency event source that could eventually cause queuing or cost impact.
    • Expected impact: Reduced unnecessary workflow starts.
    • Urgency: LOW — system is self-healing via concurrency; cosmetic/cost issue only.

6. Health Score

Health: 8/10 — One isolated auth failure on a Dependabot-triggered run; all other runs succeed, skip, or cancel expectedly, and the fix is a single secret-access configuration change.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    automated-reportCreated by automated workflowhealth-checkAutomated health check report

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions