Skip to content

ci: allow Codex review for contributors with access via GH team - #987

Merged
jakeaturner merged 1 commit into
stagingfrom
ci/codex-review-gate
Sep 29, 2026
Merged

jakeaturner merged 1 commit into
stagingfrom
ci/codex-review-gate

Conversation

@jakeaturner

Copy link
Copy Markdown
Collaborator

No description provided.

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

No actionable issues found in the PR’s changes to .github/workflows/codex-review.yml. The gate checks effective repository permissions, preserves the same-repository restriction, and fails explicitly on unexpected API errors.

Validation was limited to static review; the workflow was not executed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Custom repository roles may be rejected, and the gate unnecessarily receives write access.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Adds team-derived repository permission checks before running Codex reviews.

Changes:

  • Adds an authorization gate for same-repository PRs.
  • Runs Codex only when the author has sufficient access.
File Description
.github/​workflows/​codex-review.yml Adds the permission gate and connects it to the Codex job.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/codex-review.yml Outdated
Comment thread .github/workflows/codex-review.yml Outdated
Copilot AI balanced review requested due to automatic review settings September 29, 2026 21:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The gate safely handles permission lookup failures and restricts secret-bearing review runs to authorized same-repository contributors.

Review effort: Balanced
Findings: None

Resolved since last review (2)

@jakeaturner
jakeaturner merged commit 5f8026c into staging Sep 29, 2026
9 checks passed
@jakeaturner
jakeaturner deleted the ci/codex-review-gate branch September 29, 2026 21:17
@libretexts-bot

Copy link
Copy Markdown
Collaborator

🎉 This PR is included in version 2.154.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants