mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-31 19:16:29 +00:00
#66373 swapped GITHUB_TOKEN -> AUTOFIX_BOT_PAT across the workflows. That PAT is empty on fork PRs (forks get no repo secrets), which broke every fork PR two ways: 1. detect-changes classified with the empty PAT -> the compare API failed all 3 retries -> the classifier failed open and force-enabled the ci_review lane on EVERY fork PR. 2. The ci-reviewed / mcp-catalog-reviewed label gates then read labels with the same empty PAT via a hard-failing retry step -> the job failed with no recovery a fork contributor could perform (they can't self-add the label; re-running can't fix it). Restores the pre-#66373 fork-safe behavior without reverting the commit's real improvements (job timeouts, per-file flake retry, network-install retries): - detect-changes + ci.yml: token falls back to the built-in read-only github.token when AUTOFIX_BOT_PAT is empty. On main it uses the PAT (authoritative); on forks it uses github.token, which can read the public compare endpoint. (An input `default:` only applies on omission, not on an empty passed value — hence the explicit `|| github.token`.) - lint ci-review + supply-chain mcp-catalog gates: restore the inline `gh pr view ... || true` label read with the github.token fallback, dropping the hard-failing retry "Fetch PR labels" step. Graceful degrade to "label absent" on an API blip, same as before #66373. Same-repo enforcement is unchanged (byte-identical logic; the PAT is still used there). Fork PRs classify correctly and the gates read labels via the read-only token exactly as they did before the regression.
This commit is contained in:
parent
ae1cd746cb
commit
1e01a4bbe7
4 changed files with 27 additions and 21 deletions
7
.github/actions/detect-changes/action.yml
vendored
7
.github/actions/detect-changes/action.yml
vendored
|
|
@ -47,7 +47,12 @@ runs:
|
|||
id: classify
|
||||
shell: bash
|
||||
env:
|
||||
GH_TOKEN: ${{ inputs.github-token }}
|
||||
# Fall back to the built-in read-only token when the caller passes an
|
||||
# empty value. Fork PRs get no repo secrets, so AUTOFIX_BOT_PAT is ""
|
||||
# there, and an input `default:` only applies when the input is omitted,
|
||||
# not when it's passed empty. Without this fallback the compare API
|
||||
# fails on forks and the classifier fails open (every lane forced on).
|
||||
GH_TOKEN: ${{ inputs.github-token || github.token }}
|
||||
REPO: ${{ github.repository }}
|
||||
EVENT_NAME: ${{ github.event_name }}
|
||||
BASE_SHA: ${{ github.event.pull_request.base.sha }}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue