From 97d932a38495ce2c9ebf6ce7922f3c689d8d9e2e Mon Sep 17 00:00:00 2001 From: Matysh Date: Thu, 13 Aug 2026 12:01:38 +0300 Subject: [PATCH] ci: fix OIDC permission and review the issue branch MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The first live run failed with "Could not fetch an OIDC token": the action needs id-token: write to authenticate the GitHub App. The reviewer also checked out dev, where the material under review does not exist yet — specs and code are committed to issue/-slug. The job now switches to that branch when it is pushed, and warns loudly when it is not. Issue: #114 User-Visible: no --- .github/workflows/process.yml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/.github/workflows/process.yml b/.github/workflows/process.yml index 0a533721..f6694e3b 100644 --- a/.github/workflows/process.yml +++ b/.github/workflows/process.yml @@ -26,6 +26,9 @@ concurrency: permissions: contents: read issues: write + # Обязательно: claude-code-action получает OIDC-токен для авторизации + # GitHub App. Без этого прогон падает с «Could not fetch an OIDC token». + id-token: write jobs: guard: @@ -91,6 +94,23 @@ jobs: - uses: actions/setup-node@v4 with: { node-version: 22 } + # Материал ревью живёт в ветке задачи: ТЗ в docs/specs/ и код коммитятся + # в issue/-slug. Если ветка запушена — переключаемся на неё, иначе + # ревьюер прочитает dev и не найдёт того, что должен оценивать. + - name: Перейти на ветку задачи + env: + NUM: ${{ github.event.issue.number }} + run: | + branch=$(git ls-remote --heads origin "issue/${NUM}-*" \ + | head -1 | sed 's|.*refs/heads/||') + if [ -n "$branch" ]; then + git checkout -q "origin/$branch" + echo "материал ревью: ветка $branch, $(git rev-parse --short HEAD)" + else + echo "::warning::ветка issue/${NUM}-* не найдена на origin — ревью пойдёт по dev" + echo "МАТЕРИАЛ НЕ ЗАПУШЕН" >> "$GITHUB_STEP_SUMMARY" + fi + - name: Review id: review uses: anthropics/claude-code-action@v1