Skip to content

Commit 79584f1

Browse files
committed
docs(ci): cross-reference the two verify steps, and record why they are not shared
A local composite action loads from the checkout, which in both workflows is the PR's contributor-authored tree, so sharing the step that way would run PR-controlled code with the job's write token. Each copy now names the other so a fix to the detection logic reaches both.
1 parent c368284 commit 79584f1

2 files changed

Lines changed: 14 additions & 4 deletions

File tree

‎.github/workflows/claude-code-focus-on-demand.yml‎

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -250,10 +250,13 @@ jobs:
250250
# `num_turns`, why bodies go through `@json`, why the run id is anchored
251251
# on its right, and why only bot comments count.
252252
#
253-
# This is INLINE rather than a shared script on purpose. On issue_comment
254-
# the workflow file comes from the default branch, but the checkout above
255-
# is the PR's contributor-authored tree. A script run from that tree would
256-
# execute whatever the PR changed it to, holding this job's write token.
253+
# This is INLINE rather than a shared script or a local composite action
254+
# on purpose. On issue_comment the workflow file comes from the default
255+
# branch, but the checkout above is the PR's contributor-authored tree,
256+
# and both a script and `uses: ./.github/actions/...` load from it. Either
257+
# would run whatever the PR changed it to, holding this job's write token.
258+
# A fix to the detection logic belongs in both copies; the review
259+
# workflow's step points back here.
257260
#
258261
# Metrics are diagnostic only: the run fails on no posted summary or an
259262
# action-reported error, and warns on permission denials, naming the

‎.github/workflows/claude-code-review-on-demand.yml‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -405,6 +405,13 @@ jobs:
405405
# THAT MARKER IS A CONTRACT WITH THE PROMPT. If the review-mode
406406
# instruction is ever reworded or dropped, change it here in the same
407407
# commit, or this step starts failing every run.
408+
#
409+
# A COPY OF THIS STEP lives in claude-code-focus-on-demand.yml, differing
410+
# in its marker (`Focus areas:`). A fix to the detection logic here
411+
# belongs in both. It is copied rather than shared because a local
412+
# composite action (`uses: ./.github/actions/...`) loads from the
413+
# checkout, which is the PR's contributor-authored tree, and would run
414+
# with this job's write token.
408415
- name: Verify the review actually ran
409416
if: always()
410417
env:

0 commit comments

Comments
 (0)