ci: allow Codex review for contributors with access via GH team - #987
Conversation
|
No actionable issues found in the PR’s changes to Validation was limited to static review; the workflow was not executed. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Custom repository roles may be rejected, and the gate unnecessarily receives write access.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds team-derived repository permission checks before running Codex reviews.
Changes:
- Adds an authorization gate for same-repository PRs.
- Runs Codex only when the author has sufficient access.
| File | Description |
|---|---|
.github/workflows/codex-review.yml |
Adds the permission gate and connects it to the Codex job. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
3567107 to
c7cbd63
Compare
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The gate safely handles permission lookup failures and restricts secret-bearing review runs to authorized same-repository contributors.
Review effort: Balanced
Findings: None
Resolved since last review (2)
|
🎉 This PR is included in version 2.154.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |

No description provided.