Make Claude Code Review advisory so expired OAuth does not fail PRs - #87
Merged
Conversation
The review action has returned is_error:true at $0 cost on every PR since 2026-07-15 (CLAUDE_CODE_OAUTH_TOKEN rejected or quota exhausted). Keep the job, allow cursor[bot], and continue-on-error so a rotated secret resumes reviews without blocking CI. Co-authored-by: Muhammad Rafiq <mohabbis@users.noreply.github.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
mohabbis
marked this pull request as ready for review
August 31, 2026 18:10
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why this PR exists
#86 merged with a red Claude Code Review / claude-review check.
CI / testwas already green. This PR lands the repo-side fix so that check no longer fails PRs.Root cause
Two stacked failures, both in
anthropics/claude-code-action@v1:Bot actor (Cursor PRs). The action rejects non-human actors unless they are listed in
allowed_bots. Cursor Cloud Agents open/push ascursor[bot], so the job died immediately withWorkflow initiated by non-human actor: cursor.Expired or quota-exhausted OAuth (every PR since 2026-07-15). After the actor check, the SDK returns
subtype: successwithis_error: true,num_turns: 1, andtotal_cost_usd: 0— it never calls the model. The same envelope appears on human-authored PRs. Full output is hidden; this matches Anthropic issues whereCLAUDE_CODE_OAUTH_TOKENis a 401 or a 429. That secret cannot be rotated from this PR.Fix
allowed_bots: cursor,cursor[bot]so Cursor-opened PRs can run the review.continue-on-error: trueon the review step, plus a warning annotation when it fails. Review stays wired so a rotated token starts posting again; it no longer fails the check.AGENTS.md/CLAUDE.mdnote the workflow is advisory.To restore actual review comments, re-mint the token locally with
claude setup-tokenand update theCLAUDE_CODE_OAUTH_TOKENrepo secret.