mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-21 16:18:55 +00:00
#66373 swapped GITHUB_TOKEN -> AUTOFIX_BOT_PAT across the workflows. That PAT is empty on fork PRs (forks get no repo secrets), which broke every fork PR two ways: 1. detect-changes classified with the empty PAT -> the compare API failed all 3 retries -> the classifier failed open and force-enabled the ci_review lane on EVERY fork PR. 2. The ci-reviewed / mcp-catalog-reviewed label gates then read labels with the same empty PAT via a hard-failing retry step -> the job failed with no recovery a fork contributor could perform (they can't self-add the label; re-running can't fix it). Restores the pre-#66373 fork-safe behavior without reverting the commit's real improvements (job timeouts, per-file flake retry, network-install retries): - detect-changes + ci.yml: token falls back to the built-in read-only github.token when AUTOFIX_BOT_PAT is empty. On main it uses the PAT (authoritative); on forks it uses github.token, which can read the public compare endpoint. (An input `default:` only applies on omission, not on an empty passed value — hence the explicit `|| github.token`.) - lint ci-review + supply-chain mcp-catalog gates: restore the inline `gh pr view ... || true` label read with the github.token fallback, dropping the hard-failing retry "Fetch PR labels" step. Graceful degrade to "label absent" on an API blip, same as before #66373. Same-repo enforcement is unchanged (byte-identical logic; the PAT is still used there). Fork PRs classify correctly and the gates read labels via the read-only token exactly as they did before the regression. |
||
|---|---|---|
| .. | ||
| actions | ||
| ISSUE_TEMPLATE | ||
| pr-screenshots | ||
| workflows | ||
| dependabot.yml | ||
| PULL_REQUEST_TEMPLATE.md | ||