Skip to content

ci(security-review): drop pull_request_review trigger (broken on fork PRs) - #1310

Merged
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets
May 20, 2026
Merged

ci(security-review): drop pull_request_review trigger (broken on fork PRs)#1310
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets

Conversation

@tejaskash

@tejaskashtejaskash commented May 19, 2026

Copy link
Copy Markdown
Contributor

Why

The pull_request_review trigger was added to give maintainers a way to authorize the security review on community (fork) PRs by approving the review. It works on same-repo PRs but fails silently on fork PRs: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, regardless of the reviewer's access level. Today's run on PR #1299 (fork from notgitika) is the proof — the workflow fired, the auth gate passed, then Generate GitHub App token crashed with Input required and not supplied: app-id because vars.APP_ID and secrets.APP_PRIVATE_KEY both resolved to empty.

The pull_request_target event with the labeled action does receive secrets on fork PRs and is the only trigger that actually works end-to-end for community contributions.

What changes

  • Remove pull_request_review from the workflow triggers.
  • Drop the related branches in the auth job (filter clause, isApproval path, review.state == 'approved' check).
  • Update CONTRIBUTING.md to direct maintainers to the safe-to-review label and explain why approving review isn't the trigger.
  • Same-repo maintainer-authored PRs continue to auto-run on opened / reopened / synchronize exactly as before.
  • Community PRs require the safe-to-review label, gated on the labeler's write access.

Test plan

  • Land this. On the next community fork PR, apply safe-to-review and confirm the workflow runs end-to-end (App token resolves, label adds, Bedrock review runs, inline comments + summary post).
  • On a same-repo PR, confirm opened continues to auto-run as before.
  • On a same-repo PR, confirm an approving review no longer triggers the workflow (since the trigger was removed).

…njected on fork PRs
GitHub does not inject repo/org secrets (vars.APP_ID, secrets.APP_PRIVATE_KEY,
the Bedrock OIDC role) into workflows triggered by pull_request_review when the
PR head is a fork, regardless of the reviewer's access level. Approving a fork
PR therefore fired the workflow but the App-token step crashed with 'Input
required and not supplied: app-id' because vars.APP_ID resolved to empty.
The label-on-pull_request_target path does inject secrets and is the only
trigger that works end-to-end for fork PRs. Drop the pull_request_review
trigger entirely; same-repo maintainer PRs auto-run on opened/synchronize as
before, community PRs require the safe-to-review label.
@tejaskash
tejaskash requested a review from a teamMay 19, 2026 19:29
@github-actionsgithub-actionsBot added the size/s PR size: S label May 19, 2026
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.14.0.tgz

How to install

gh release download pr-1310-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.14.0.tgz

@github-actions

github-actionsBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.72%9272 / 21204
🔵Statements42.97%9839 / 22896
🔵Functions40.44%1604 / 3966
🔵Branches40.45%6029 / 14903
Generated in workflow #3134 for commit 9ea4f79 by the Vitest Coverage Report Action

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — the rationale is correct: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, so the trigger could never have completed the App-token step on community PRs. Removing it (plus the corresponding branches in the auth filter, the auth step if, and the isApproval script path) is the right fix, and the concurrency group cleanup is consistent with that.

The same-repo auto-run path (opened/reopened/synchronize gated on PR author) and the community label path (safe-to-review gated on the labeler) both still resolve correctly through the simplified if and the simplified script. CONTRIBUTING.md is updated to match.

Nothing blocking from me. One trivial nit you can ignore: the comment on lines 96–97 of .github/workflows/pr-security-review.yml still references pull_request_review events as a reason the default GITHUB_TOKEN is read-only — that event no longer triggers the workflow, so the reference is stale. Worth a one-line update next time you're in the file but not worth blocking on.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
Hweinstock
Hweinstock previously approved these changes May 19, 2026

@HweinstockHweinstock left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing!

notgitika
notgitika previously approved these changes May 19, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM thank you!

…ry on cancel
Three fixes rolled in:
1. Use the SDK's bundled /security-review slash command instead of inlining
the prompt. The Claude Code SDK that ships with anthropics/claude-code-action
exposes /security-review as a registered slash command (visible in the
'slash_commands' list its system init prints). It drives its own
git-diff-based context, sub-task fan-out, and false-positive filtering.
We were re-implementing all of that in a 23 KB inline prompt, plus a
fragile build step that crashed on fork PRs because
.github/prompts/security-review.md doesn't exist on the head ref.
Drops .github/prompts/security-review.md, the Build/Read prompt steps,
and the python templating. Workflow is ~300 lines lighter.
2. Concurrency: cancel-in-progress: false. Cancelling a run mid-analysis
leaves the buffer file empty but lets the if: always() summary step
fire, posting a misleading 'no high-confidence findings' comment.
Letting both runs complete is the safer default.
3. Summary step branches on steps.review.conclusion. Only post a real
findings count when the review step actually completed; on
failure/cancellation/skip, post a transparent status that says the run
didn't complete and a later run will replace it.
@tejaskash
tejaskash dismissed stale reviews from notgitika and Hweinstock via 9ea4f79May 20, 2026 15:22
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/s PR size: S labels May 20, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@tejaskash
tejaskash merged commit 43607fa into mainMay 20, 2026
27 of 28 checks passed
@tejaskash
tejaskash deleted the fix-fork-secrets branch May 20, 2026 16:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tejaskash@Hweinstock@notgitika@agentcore-cli-automation
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
ci(security-review): drop pull_request_review trigger (broken on fork PRs) by tejaskash · Pull Request #1310 · aws/agentcore-cli · GitHub
Skip to content

ci(security-review): drop pull_request_review trigger (broken on fork PRs) - #1310

Merged
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets
May 20, 2026
Merged

ci(security-review): drop pull_request_review trigger (broken on fork PRs)#1310
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets

Conversation

@tejaskash

@tejaskashtejaskash commented May 19, 2026

Copy link
Copy Markdown
Contributor

Why

The pull_request_review trigger was added to give maintainers a way to authorize the security review on community (fork) PRs by approving the review. It works on same-repo PRs but fails silently on fork PRs: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, regardless of the reviewer's access level. Today's run on PR #1299 (fork from notgitika) is the proof — the workflow fired, the auth gate passed, then Generate GitHub App token crashed with Input required and not supplied: app-id because vars.APP_ID and secrets.APP_PRIVATE_KEY both resolved to empty.

The pull_request_target event with the labeled action does receive secrets on fork PRs and is the only trigger that actually works end-to-end for community contributions.

What changes

  • Remove pull_request_review from the workflow triggers.
  • Drop the related branches in the auth job (filter clause, isApproval path, review.state == 'approved' check).
  • Update CONTRIBUTING.md to direct maintainers to the safe-to-review label and explain why approving review isn't the trigger.
  • Same-repo maintainer-authored PRs continue to auto-run on opened / reopened / synchronize exactly as before.
  • Community PRs require the safe-to-review label, gated on the labeler's write access.

Test plan

  • Land this. On the next community fork PR, apply safe-to-review and confirm the workflow runs end-to-end (App token resolves, label adds, Bedrock review runs, inline comments + summary post).
  • On a same-repo PR, confirm opened continues to auto-run as before.
  • On a same-repo PR, confirm an approving review no longer triggers the workflow (since the trigger was removed).

…njected on fork PRs
GitHub does not inject repo/org secrets (vars.APP_ID, secrets.APP_PRIVATE_KEY,
the Bedrock OIDC role) into workflows triggered by pull_request_review when the
PR head is a fork, regardless of the reviewer's access level. Approving a fork
PR therefore fired the workflow but the App-token step crashed with 'Input
required and not supplied: app-id' because vars.APP_ID resolved to empty.
The label-on-pull_request_target path does inject secrets and is the only
trigger that works end-to-end for fork PRs. Drop the pull_request_review
trigger entirely; same-repo maintainer PRs auto-run on opened/synchronize as
before, community PRs require the safe-to-review label.
@tejaskash
tejaskash requested a review from a teamMay 19, 2026 19:29
@github-actionsgithub-actionsBot added the size/s PR size: S label May 19, 2026
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.14.0.tgz

How to install

gh release download pr-1310-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.14.0.tgz

@github-actions

github-actionsBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.72%9272 / 21204
🔵Statements42.97%9839 / 22896
🔵Functions40.44%1604 / 3966
🔵Branches40.45%6029 / 14903
Generated in workflow #3134 for commit 9ea4f79 by the Vitest Coverage Report Action

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — the rationale is correct: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, so the trigger could never have completed the App-token step on community PRs. Removing it (plus the corresponding branches in the auth filter, the auth step if, and the isApproval script path) is the right fix, and the concurrency group cleanup is consistent with that.

The same-repo auto-run path (opened/reopened/synchronize gated on PR author) and the community label path (safe-to-review gated on the labeler) both still resolve correctly through the simplified if and the simplified script. CONTRIBUTING.md is updated to match.

Nothing blocking from me. One trivial nit you can ignore: the comment on lines 96–97 of .github/workflows/pr-security-review.yml still references pull_request_review events as a reason the default GITHUB_TOKEN is read-only — that event no longer triggers the workflow, so the reference is stale. Worth a one-line update next time you're in the file but not worth blocking on.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
Hweinstock
Hweinstock previously approved these changes May 19, 2026

@HweinstockHweinstock left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing!

notgitika
notgitika previously approved these changes May 19, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM thank you!

…ry on cancel
Three fixes rolled in:
1. Use the SDK's bundled /security-review slash command instead of inlining
the prompt. The Claude Code SDK that ships with anthropics/claude-code-action
exposes /security-review as a registered slash command (visible in the
'slash_commands' list its system init prints). It drives its own
git-diff-based context, sub-task fan-out, and false-positive filtering.
We were re-implementing all of that in a 23 KB inline prompt, plus a
fragile build step that crashed on fork PRs because
.github/prompts/security-review.md doesn't exist on the head ref.
Drops .github/prompts/security-review.md, the Build/Read prompt steps,
and the python templating. Workflow is ~300 lines lighter.
2. Concurrency: cancel-in-progress: false. Cancelling a run mid-analysis
leaves the buffer file empty but lets the if: always() summary step
fire, posting a misleading 'no high-confidence findings' comment.
Letting both runs complete is the safer default.
3. Summary step branches on steps.review.conclusion. Only post a real
findings count when the review step actually completed; on
failure/cancellation/skip, post a transparent status that says the run
didn't complete and a later run will replace it.
@tejaskash
tejaskash dismissed stale reviews from notgitika and Hweinstock via 9ea4f79May 20, 2026 15:22
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/s PR size: S labels May 20, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@tejaskash
tejaskash merged commit 43607fa into mainMay 20, 2026
27 of 28 checks passed
@tejaskash
tejaskash deleted the fix-fork-secrets branch May 20, 2026 16:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tejaskash@Hweinstock@notgitika@agentcore-cli-automation
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(security-review): drop pull_request_review trigger (broken on fork PRs) by tejaskash · Pull Request #1310 · aws/agentcore-cli · GitHub
Skip to content

ci(security-review): drop pull_request_review trigger (broken on fork PRs) - #1310

Merged
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets
May 20, 2026
Merged

ci(security-review): drop pull_request_review trigger (broken on fork PRs)#1310
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets

Conversation

@tejaskash

@tejaskashtejaskash commented May 19, 2026

Copy link
Copy Markdown
Contributor

Why

The pull_request_review trigger was added to give maintainers a way to authorize the security review on community (fork) PRs by approving the review. It works on same-repo PRs but fails silently on fork PRs: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, regardless of the reviewer's access level. Today's run on PR #1299 (fork from notgitika) is the proof — the workflow fired, the auth gate passed, then Generate GitHub App token crashed with Input required and not supplied: app-id because vars.APP_ID and secrets.APP_PRIVATE_KEY both resolved to empty.

The pull_request_target event with the labeled action does receive secrets on fork PRs and is the only trigger that actually works end-to-end for community contributions.

What changes

  • Remove pull_request_review from the workflow triggers.
  • Drop the related branches in the auth job (filter clause, isApproval path, review.state == 'approved' check).
  • Update CONTRIBUTING.md to direct maintainers to the safe-to-review label and explain why approving review isn't the trigger.
  • Same-repo maintainer-authored PRs continue to auto-run on opened / reopened / synchronize exactly as before.
  • Community PRs require the safe-to-review label, gated on the labeler's write access.

Test plan

  • Land this. On the next community fork PR, apply safe-to-review and confirm the workflow runs end-to-end (App token resolves, label adds, Bedrock review runs, inline comments + summary post).
  • On a same-repo PR, confirm opened continues to auto-run as before.
  • On a same-repo PR, confirm an approving review no longer triggers the workflow (since the trigger was removed).

…njected on fork PRs
GitHub does not inject repo/org secrets (vars.APP_ID, secrets.APP_PRIVATE_KEY,
the Bedrock OIDC role) into workflows triggered by pull_request_review when the
PR head is a fork, regardless of the reviewer's access level. Approving a fork
PR therefore fired the workflow but the App-token step crashed with 'Input
required and not supplied: app-id' because vars.APP_ID resolved to empty.
The label-on-pull_request_target path does inject secrets and is the only
trigger that works end-to-end for fork PRs. Drop the pull_request_review
trigger entirely; same-repo maintainer PRs auto-run on opened/synchronize as
before, community PRs require the safe-to-review label.
@tejaskash
tejaskash requested a review from a teamMay 19, 2026 19:29
@github-actionsgithub-actionsBot added the size/s PR size: S label May 19, 2026
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.14.0.tgz

How to install

gh release download pr-1310-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.14.0.tgz

@github-actions

github-actionsBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.72%9272 / 21204
🔵Statements42.97%9839 / 22896
🔵Functions40.44%1604 / 3966
🔵Branches40.45%6029 / 14903
Generated in workflow #3134 for commit 9ea4f79 by the Vitest Coverage Report Action

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — the rationale is correct: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, so the trigger could never have completed the App-token step on community PRs. Removing it (plus the corresponding branches in the auth filter, the auth step if, and the isApproval script path) is the right fix, and the concurrency group cleanup is consistent with that.

The same-repo auto-run path (opened/reopened/synchronize gated on PR author) and the community label path (safe-to-review gated on the labeler) both still resolve correctly through the simplified if and the simplified script. CONTRIBUTING.md is updated to match.

Nothing blocking from me. One trivial nit you can ignore: the comment on lines 96–97 of .github/workflows/pr-security-review.yml still references pull_request_review events as a reason the default GITHUB_TOKEN is read-only — that event no longer triggers the workflow, so the reference is stale. Worth a one-line update next time you're in the file but not worth blocking on.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
Hweinstock
Hweinstock previously approved these changes May 19, 2026

@HweinstockHweinstock left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing!

notgitika
notgitika previously approved these changes May 19, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM thank you!

…ry on cancel
Three fixes rolled in:
1. Use the SDK's bundled /security-review slash command instead of inlining
the prompt. The Claude Code SDK that ships with anthropics/claude-code-action
exposes /security-review as a registered slash command (visible in the
'slash_commands' list its system init prints). It drives its own
git-diff-based context, sub-task fan-out, and false-positive filtering.
We were re-implementing all of that in a 23 KB inline prompt, plus a
fragile build step that crashed on fork PRs because
.github/prompts/security-review.md doesn't exist on the head ref.
Drops .github/prompts/security-review.md, the Build/Read prompt steps,
and the python templating. Workflow is ~300 lines lighter.
2. Concurrency: cancel-in-progress: false. Cancelling a run mid-analysis
leaves the buffer file empty but lets the if: always() summary step
fire, posting a misleading 'no high-confidence findings' comment.
Letting both runs complete is the safer default.
3. Summary step branches on steps.review.conclusion. Only post a real
findings count when the review step actually completed; on
failure/cancellation/skip, post a transparent status that says the run
didn't complete and a later run will replace it.
@tejaskash
tejaskash dismissed stale reviews from notgitika and Hweinstock via 9ea4f79May 20, 2026 15:22
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/s PR size: S labels May 20, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@tejaskash
tejaskash merged commit 43607fa into mainMay 20, 2026
27 of 28 checks passed
@tejaskash
tejaskash deleted the fix-fork-secrets branch May 20, 2026 16:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tejaskash@Hweinstock@notgitika@agentcore-cli-automation
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(security-review): drop pull_request_review trigger (broken on fork PRs) by tejaskash · Pull Request #1310 · aws/agentcore-cli · GitHub
Skip to content

ci(security-review): drop pull_request_review trigger (broken on fork PRs) - #1310

Merged
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets
May 20, 2026
Merged

ci(security-review): drop pull_request_review trigger (broken on fork PRs)#1310
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets

Conversation

@tejaskash

@tejaskashtejaskash commented May 19, 2026

Copy link
Copy Markdown
Contributor

Why

The pull_request_review trigger was added to give maintainers a way to authorize the security review on community (fork) PRs by approving the review. It works on same-repo PRs but fails silently on fork PRs: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, regardless of the reviewer's access level. Today's run on PR #1299 (fork from notgitika) is the proof — the workflow fired, the auth gate passed, then Generate GitHub App token crashed with Input required and not supplied: app-id because vars.APP_ID and secrets.APP_PRIVATE_KEY both resolved to empty.

The pull_request_target event with the labeled action does receive secrets on fork PRs and is the only trigger that actually works end-to-end for community contributions.

What changes

  • Remove pull_request_review from the workflow triggers.
  • Drop the related branches in the auth job (filter clause, isApproval path, review.state == 'approved' check).
  • Update CONTRIBUTING.md to direct maintainers to the safe-to-review label and explain why approving review isn't the trigger.
  • Same-repo maintainer-authored PRs continue to auto-run on opened / reopened / synchronize exactly as before.
  • Community PRs require the safe-to-review label, gated on the labeler's write access.

Test plan

  • Land this. On the next community fork PR, apply safe-to-review and confirm the workflow runs end-to-end (App token resolves, label adds, Bedrock review runs, inline comments + summary post).
  • On a same-repo PR, confirm opened continues to auto-run as before.
  • On a same-repo PR, confirm an approving review no longer triggers the workflow (since the trigger was removed).

…njected on fork PRs
GitHub does not inject repo/org secrets (vars.APP_ID, secrets.APP_PRIVATE_KEY,
the Bedrock OIDC role) into workflows triggered by pull_request_review when the
PR head is a fork, regardless of the reviewer's access level. Approving a fork
PR therefore fired the workflow but the App-token step crashed with 'Input
required and not supplied: app-id' because vars.APP_ID resolved to empty.
The label-on-pull_request_target path does inject secrets and is the only
trigger that works end-to-end for fork PRs. Drop the pull_request_review
trigger entirely; same-repo maintainer PRs auto-run on opened/synchronize as
before, community PRs require the safe-to-review label.
@tejaskash
tejaskash requested a review from a teamMay 19, 2026 19:29
@github-actionsgithub-actionsBot added the size/s PR size: S label May 19, 2026
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.14.0.tgz

How to install

gh release download pr-1310-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.14.0.tgz

@github-actions

github-actionsBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.72%9272 / 21204
🔵Statements42.97%9839 / 22896
🔵Functions40.44%1604 / 3966
🔵Branches40.45%6029 / 14903
Generated in workflow #3134 for commit 9ea4f79 by the Vitest Coverage Report Action

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — the rationale is correct: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, so the trigger could never have completed the App-token step on community PRs. Removing it (plus the corresponding branches in the auth filter, the auth step if, and the isApproval script path) is the right fix, and the concurrency group cleanup is consistent with that.

The same-repo auto-run path (opened/reopened/synchronize gated on PR author) and the community label path (safe-to-review gated on the labeler) both still resolve correctly through the simplified if and the simplified script. CONTRIBUTING.md is updated to match.

Nothing blocking from me. One trivial nit you can ignore: the comment on lines 96–97 of .github/workflows/pr-security-review.yml still references pull_request_review events as a reason the default GITHUB_TOKEN is read-only — that event no longer triggers the workflow, so the reference is stale. Worth a one-line update next time you're in the file but not worth blocking on.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
Hweinstock
Hweinstock previously approved these changes May 19, 2026

@HweinstockHweinstock left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing!

notgitika
notgitika previously approved these changes May 19, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM thank you!

…ry on cancel
Three fixes rolled in:
1. Use the SDK's bundled /security-review slash command instead of inlining
the prompt. The Claude Code SDK that ships with anthropics/claude-code-action
exposes /security-review as a registered slash command (visible in the
'slash_commands' list its system init prints). It drives its own
git-diff-based context, sub-task fan-out, and false-positive filtering.
We were re-implementing all of that in a 23 KB inline prompt, plus a
fragile build step that crashed on fork PRs because
.github/prompts/security-review.md doesn't exist on the head ref.
Drops .github/prompts/security-review.md, the Build/Read prompt steps,
and the python templating. Workflow is ~300 lines lighter.
2. Concurrency: cancel-in-progress: false. Cancelling a run mid-analysis
leaves the buffer file empty but lets the if: always() summary step
fire, posting a misleading 'no high-confidence findings' comment.
Letting both runs complete is the safer default.
3. Summary step branches on steps.review.conclusion. Only post a real
findings count when the review step actually completed; on
failure/cancellation/skip, post a transparent status that says the run
didn't complete and a later run will replace it.
@tejaskash
tejaskash dismissed stale reviews from notgitika and Hweinstock via 9ea4f79May 20, 2026 15:22
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/s PR size: S labels May 20, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@tejaskash
tejaskash merged commit 43607fa into mainMay 20, 2026
27 of 28 checks passed
@tejaskash
tejaskash deleted the fix-fork-secrets branch May 20, 2026 16:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tejaskash@Hweinstock@notgitika@agentcore-cli-automation
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' ci(security-review): drop pull_request_review trigger (broken on fork PRs) by tejaskash · Pull Request #1310 · aws/agentcore-cli · GitHub
Skip to content

ci(security-review): drop pull_request_review trigger (broken on fork PRs) - #1310

Merged
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets
May 20, 2026
Merged

ci(security-review): drop pull_request_review trigger (broken on fork PRs)#1310
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets

Conversation

@tejaskash

@tejaskashtejaskash commented May 19, 2026

Copy link
Copy Markdown
Contributor

Why

The pull_request_review trigger was added to give maintainers a way to authorize the security review on community (fork) PRs by approving the review. It works on same-repo PRs but fails silently on fork PRs: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, regardless of the reviewer's access level. Today's run on PR #1299 (fork from notgitika) is the proof — the workflow fired, the auth gate passed, then Generate GitHub App token crashed with Input required and not supplied: app-id because vars.APP_ID and secrets.APP_PRIVATE_KEY both resolved to empty.

The pull_request_target event with the labeled action does receive secrets on fork PRs and is the only trigger that actually works end-to-end for community contributions.

What changes

  • Remove pull_request_review from the workflow triggers.
  • Drop the related branches in the auth job (filter clause, isApproval path, review.state == 'approved' check).
  • Update CONTRIBUTING.md to direct maintainers to the safe-to-review label and explain why approving review isn't the trigger.
  • Same-repo maintainer-authored PRs continue to auto-run on opened / reopened / synchronize exactly as before.
  • Community PRs require the safe-to-review label, gated on the labeler's write access.

Test plan

  • Land this. On the next community fork PR, apply safe-to-review and confirm the workflow runs end-to-end (App token resolves, label adds, Bedrock review runs, inline comments + summary post).
  • On a same-repo PR, confirm opened continues to auto-run as before.
  • On a same-repo PR, confirm an approving review no longer triggers the workflow (since the trigger was removed).

…njected on fork PRs
GitHub does not inject repo/org secrets (vars.APP_ID, secrets.APP_PRIVATE_KEY,
the Bedrock OIDC role) into workflows triggered by pull_request_review when the
PR head is a fork, regardless of the reviewer's access level. Approving a fork
PR therefore fired the workflow but the App-token step crashed with 'Input
required and not supplied: app-id' because vars.APP_ID resolved to empty.
The label-on-pull_request_target path does inject secrets and is the only
trigger that works end-to-end for fork PRs. Drop the pull_request_review
trigger entirely; same-repo maintainer PRs auto-run on opened/synchronize as
before, community PRs require the safe-to-review label.
@tejaskash
tejaskash requested a review from a teamMay 19, 2026 19:29
@github-actionsgithub-actionsBot added the size/s PR size: S label May 19, 2026
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.14.0.tgz

How to install

gh release download pr-1310-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.14.0.tgz

@github-actions

github-actionsBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.72%9272 / 21204
🔵Statements42.97%9839 / 22896
🔵Functions40.44%1604 / 3966
🔵Branches40.45%6029 / 14903
Generated in workflow #3134 for commit 9ea4f79 by the Vitest Coverage Report Action

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — the rationale is correct: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, so the trigger could never have completed the App-token step on community PRs. Removing it (plus the corresponding branches in the auth filter, the auth step if, and the isApproval script path) is the right fix, and the concurrency group cleanup is consistent with that.

The same-repo auto-run path (opened/reopened/synchronize gated on PR author) and the community label path (safe-to-review gated on the labeler) both still resolve correctly through the simplified if and the simplified script. CONTRIBUTING.md is updated to match.

Nothing blocking from me. One trivial nit you can ignore: the comment on lines 96–97 of .github/workflows/pr-security-review.yml still references pull_request_review events as a reason the default GITHUB_TOKEN is read-only — that event no longer triggers the workflow, so the reference is stale. Worth a one-line update next time you're in the file but not worth blocking on.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
Hweinstock
Hweinstock previously approved these changes May 19, 2026

@HweinstockHweinstock left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing!

notgitika
notgitika previously approved these changes May 19, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM thank you!

…ry on cancel
Three fixes rolled in:
1. Use the SDK's bundled /security-review slash command instead of inlining
the prompt. The Claude Code SDK that ships with anthropics/claude-code-action
exposes /security-review as a registered slash command (visible in the
'slash_commands' list its system init prints). It drives its own
git-diff-based context, sub-task fan-out, and false-positive filtering.
We were re-implementing all of that in a 23 KB inline prompt, plus a
fragile build step that crashed on fork PRs because
.github/prompts/security-review.md doesn't exist on the head ref.
Drops .github/prompts/security-review.md, the Build/Read prompt steps,
and the python templating. Workflow is ~300 lines lighter.
2. Concurrency: cancel-in-progress: false. Cancelling a run mid-analysis
leaves the buffer file empty but lets the if: always() summary step
fire, posting a misleading 'no high-confidence findings' comment.
Letting both runs complete is the safer default.
3. Summary step branches on steps.review.conclusion. Only post a real
findings count when the review step actually completed; on
failure/cancellation/skip, post a transparent status that says the run
didn't complete and a later run will replace it.
@tejaskash
tejaskash dismissed stale reviews from notgitika and Hweinstock via 9ea4f79May 20, 2026 15:22
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/s PR size: S labels May 20, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@tejaskash
tejaskash merged commit 43607fa into mainMay 20, 2026
27 of 28 checks passed
@tejaskash
tejaskash deleted the fix-fork-secrets branch May 20, 2026 16:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tejaskash@Hweinstock@notgitika@agentcore-cli-automation
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(security-review): drop pull_request_review trigger (broken on fork PRs) by tejaskash · Pull Request #1310 · aws/agentcore-cli · GitHub
Skip to content

ci(security-review): drop pull_request_review trigger (broken on fork PRs) - #1310

Merged
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets
May 20, 2026
Merged

ci(security-review): drop pull_request_review trigger (broken on fork PRs)#1310
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets

Conversation

@tejaskash

@tejaskashtejaskash commented May 19, 2026

Copy link
Copy Markdown
Contributor

Why

The pull_request_review trigger was added to give maintainers a way to authorize the security review on community (fork) PRs by approving the review. It works on same-repo PRs but fails silently on fork PRs: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, regardless of the reviewer's access level. Today's run on PR #1299 (fork from notgitika) is the proof — the workflow fired, the auth gate passed, then Generate GitHub App token crashed with Input required and not supplied: app-id because vars.APP_ID and secrets.APP_PRIVATE_KEY both resolved to empty.

The pull_request_target event with the labeled action does receive secrets on fork PRs and is the only trigger that actually works end-to-end for community contributions.

What changes

  • Remove pull_request_review from the workflow triggers.
  • Drop the related branches in the auth job (filter clause, isApproval path, review.state == 'approved' check).
  • Update CONTRIBUTING.md to direct maintainers to the safe-to-review label and explain why approving review isn't the trigger.
  • Same-repo maintainer-authored PRs continue to auto-run on opened / reopened / synchronize exactly as before.
  • Community PRs require the safe-to-review label, gated on the labeler's write access.

Test plan

  • Land this. On the next community fork PR, apply safe-to-review and confirm the workflow runs end-to-end (App token resolves, label adds, Bedrock review runs, inline comments + summary post).
  • On a same-repo PR, confirm opened continues to auto-run as before.
  • On a same-repo PR, confirm an approving review no longer triggers the workflow (since the trigger was removed).

…njected on fork PRs
GitHub does not inject repo/org secrets (vars.APP_ID, secrets.APP_PRIVATE_KEY,
the Bedrock OIDC role) into workflows triggered by pull_request_review when the
PR head is a fork, regardless of the reviewer's access level. Approving a fork
PR therefore fired the workflow but the App-token step crashed with 'Input
required and not supplied: app-id' because vars.APP_ID resolved to empty.
The label-on-pull_request_target path does inject secrets and is the only
trigger that works end-to-end for fork PRs. Drop the pull_request_review
trigger entirely; same-repo maintainer PRs auto-run on opened/synchronize as
before, community PRs require the safe-to-review label.
@tejaskash
tejaskash requested a review from a teamMay 19, 2026 19:29
@github-actionsgithub-actionsBot added the size/s PR size: S label May 19, 2026
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.14.0.tgz

How to install

gh release download pr-1310-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.14.0.tgz

@github-actions

github-actionsBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.72%9272 / 21204
🔵Statements42.97%9839 / 22896
🔵Functions40.44%1604 / 3966
🔵Branches40.45%6029 / 14903
Generated in workflow #3134 for commit 9ea4f79 by the Vitest Coverage Report Action

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — the rationale is correct: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, so the trigger could never have completed the App-token step on community PRs. Removing it (plus the corresponding branches in the auth filter, the auth step if, and the isApproval script path) is the right fix, and the concurrency group cleanup is consistent with that.

The same-repo auto-run path (opened/reopened/synchronize gated on PR author) and the community label path (safe-to-review gated on the labeler) both still resolve correctly through the simplified if and the simplified script. CONTRIBUTING.md is updated to match.

Nothing blocking from me. One trivial nit you can ignore: the comment on lines 96–97 of .github/workflows/pr-security-review.yml still references pull_request_review events as a reason the default GITHUB_TOKEN is read-only — that event no longer triggers the workflow, so the reference is stale. Worth a one-line update next time you're in the file but not worth blocking on.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
Hweinstock
Hweinstock previously approved these changes May 19, 2026

@HweinstockHweinstock left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing!

notgitika
notgitika previously approved these changes May 19, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM thank you!

…ry on cancel
Three fixes rolled in:
1. Use the SDK's bundled /security-review slash command instead of inlining
the prompt. The Claude Code SDK that ships with anthropics/claude-code-action
exposes /security-review as a registered slash command (visible in the
'slash_commands' list its system init prints). It drives its own
git-diff-based context, sub-task fan-out, and false-positive filtering.
We were re-implementing all of that in a 23 KB inline prompt, plus a
fragile build step that crashed on fork PRs because
.github/prompts/security-review.md doesn't exist on the head ref.
Drops .github/prompts/security-review.md, the Build/Read prompt steps,
and the python templating. Workflow is ~300 lines lighter.
2. Concurrency: cancel-in-progress: false. Cancelling a run mid-analysis
leaves the buffer file empty but lets the if: always() summary step
fire, posting a misleading 'no high-confidence findings' comment.
Letting both runs complete is the safer default.
3. Summary step branches on steps.review.conclusion. Only post a real
findings count when the review step actually completed; on
failure/cancellation/skip, post a transparent status that says the run
didn't complete and a later run will replace it.
@tejaskash
tejaskash dismissed stale reviews from notgitika and Hweinstock via 9ea4f79May 20, 2026 15:22
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/s PR size: S labels May 20, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@tejaskash
tejaskash merged commit 43607fa into mainMay 20, 2026
27 of 28 checks passed
@tejaskash
tejaskash deleted the fix-fork-secrets branch May 20, 2026 16:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tejaskash@Hweinstock@notgitika@agentcore-cli-automation
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(security-review): drop pull_request_review trigger (broken on fork PRs) by tejaskash · Pull Request #1310 · aws/agentcore-cli · GitHub
Skip to content

ci(security-review): drop pull_request_review trigger (broken on fork PRs) - #1310

Merged
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets
May 20, 2026
Merged

ci(security-review): drop pull_request_review trigger (broken on fork PRs)#1310
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets

Conversation

@tejaskash

@tejaskashtejaskash commented May 19, 2026

Copy link
Copy Markdown
Contributor

Why

The pull_request_review trigger was added to give maintainers a way to authorize the security review on community (fork) PRs by approving the review. It works on same-repo PRs but fails silently on fork PRs: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, regardless of the reviewer's access level. Today's run on PR #1299 (fork from notgitika) is the proof — the workflow fired, the auth gate passed, then Generate GitHub App token crashed with Input required and not supplied: app-id because vars.APP_ID and secrets.APP_PRIVATE_KEY both resolved to empty.

The pull_request_target event with the labeled action does receive secrets on fork PRs and is the only trigger that actually works end-to-end for community contributions.

What changes

  • Remove pull_request_review from the workflow triggers.
  • Drop the related branches in the auth job (filter clause, isApproval path, review.state == 'approved' check).
  • Update CONTRIBUTING.md to direct maintainers to the safe-to-review label and explain why approving review isn't the trigger.
  • Same-repo maintainer-authored PRs continue to auto-run on opened / reopened / synchronize exactly as before.
  • Community PRs require the safe-to-review label, gated on the labeler's write access.

Test plan

  • Land this. On the next community fork PR, apply safe-to-review and confirm the workflow runs end-to-end (App token resolves, label adds, Bedrock review runs, inline comments + summary post).
  • On a same-repo PR, confirm opened continues to auto-run as before.
  • On a same-repo PR, confirm an approving review no longer triggers the workflow (since the trigger was removed).

…njected on fork PRs
GitHub does not inject repo/org secrets (vars.APP_ID, secrets.APP_PRIVATE_KEY,
the Bedrock OIDC role) into workflows triggered by pull_request_review when the
PR head is a fork, regardless of the reviewer's access level. Approving a fork
PR therefore fired the workflow but the App-token step crashed with 'Input
required and not supplied: app-id' because vars.APP_ID resolved to empty.
The label-on-pull_request_target path does inject secrets and is the only
trigger that works end-to-end for fork PRs. Drop the pull_request_review
trigger entirely; same-repo maintainer PRs auto-run on opened/synchronize as
before, community PRs require the safe-to-review label.
@tejaskash
tejaskash requested a review from a teamMay 19, 2026 19:29
@github-actionsgithub-actionsBot added the size/s PR size: S label May 19, 2026
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.14.0.tgz

How to install

gh release download pr-1310-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.14.0.tgz

@github-actions

github-actionsBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.72%9272 / 21204
🔵Statements42.97%9839 / 22896
🔵Functions40.44%1604 / 3966
🔵Branches40.45%6029 / 14903
Generated in workflow #3134 for commit 9ea4f79 by the Vitest Coverage Report Action

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — the rationale is correct: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, so the trigger could never have completed the App-token step on community PRs. Removing it (plus the corresponding branches in the auth filter, the auth step if, and the isApproval script path) is the right fix, and the concurrency group cleanup is consistent with that.

The same-repo auto-run path (opened/reopened/synchronize gated on PR author) and the community label path (safe-to-review gated on the labeler) both still resolve correctly through the simplified if and the simplified script. CONTRIBUTING.md is updated to match.

Nothing blocking from me. One trivial nit you can ignore: the comment on lines 96–97 of .github/workflows/pr-security-review.yml still references pull_request_review events as a reason the default GITHUB_TOKEN is read-only — that event no longer triggers the workflow, so the reference is stale. Worth a one-line update next time you're in the file but not worth blocking on.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
Hweinstock
Hweinstock previously approved these changes May 19, 2026

@HweinstockHweinstock left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing!

notgitika
notgitika previously approved these changes May 19, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM thank you!

…ry on cancel
Three fixes rolled in:
1. Use the SDK's bundled /security-review slash command instead of inlining
the prompt. The Claude Code SDK that ships with anthropics/claude-code-action
exposes /security-review as a registered slash command (visible in the
'slash_commands' list its system init prints). It drives its own
git-diff-based context, sub-task fan-out, and false-positive filtering.
We were re-implementing all of that in a 23 KB inline prompt, plus a
fragile build step that crashed on fork PRs because
.github/prompts/security-review.md doesn't exist on the head ref.
Drops .github/prompts/security-review.md, the Build/Read prompt steps,
and the python templating. Workflow is ~300 lines lighter.
2. Concurrency: cancel-in-progress: false. Cancelling a run mid-analysis
leaves the buffer file empty but lets the if: always() summary step
fire, posting a misleading 'no high-confidence findings' comment.
Letting both runs complete is the safer default.
3. Summary step branches on steps.review.conclusion. Only post a real
findings count when the review step actually completed; on
failure/cancellation/skip, post a transparent status that says the run
didn't complete and a later run will replace it.
@tejaskash
tejaskash dismissed stale reviews from notgitika and Hweinstock via 9ea4f79May 20, 2026 15:22
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/s PR size: S labels May 20, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@tejaskash
tejaskash merged commit 43607fa into mainMay 20, 2026
27 of 28 checks passed
@tejaskash
tejaskash deleted the fix-fork-secrets branch May 20, 2026 16:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tejaskash@Hweinstock@notgitika@agentcore-cli-automation
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); ci(security-review): drop pull_request_review trigger (broken on fork PRs) by tejaskash · Pull Request #1310 · aws/agentcore-cli · GitHub
Skip to content

ci(security-review): drop pull_request_review trigger (broken on fork PRs) - #1310

Merged
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets
May 20, 2026
Merged

ci(security-review): drop pull_request_review trigger (broken on fork PRs)#1310
tejaskash merged 2 commits into
mainfrom
fix-fork-secrets

Conversation

@tejaskash

@tejaskashtejaskash commented May 19, 2026

Copy link
Copy Markdown
Contributor

Why

The pull_request_review trigger was added to give maintainers a way to authorize the security review on community (fork) PRs by approving the review. It works on same-repo PRs but fails silently on fork PRs: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, regardless of the reviewer's access level. Today's run on PR #1299 (fork from notgitika) is the proof — the workflow fired, the auth gate passed, then Generate GitHub App token crashed with Input required and not supplied: app-id because vars.APP_ID and secrets.APP_PRIVATE_KEY both resolved to empty.

The pull_request_target event with the labeled action does receive secrets on fork PRs and is the only trigger that actually works end-to-end for community contributions.

What changes

  • Remove pull_request_review from the workflow triggers.
  • Drop the related branches in the auth job (filter clause, isApproval path, review.state == 'approved' check).
  • Update CONTRIBUTING.md to direct maintainers to the safe-to-review label and explain why approving review isn't the trigger.
  • Same-repo maintainer-authored PRs continue to auto-run on opened / reopened / synchronize exactly as before.
  • Community PRs require the safe-to-review label, gated on the labeler's write access.

Test plan

  • Land this. On the next community fork PR, apply safe-to-review and confirm the workflow runs end-to-end (App token resolves, label adds, Bedrock review runs, inline comments + summary post).
  • On a same-repo PR, confirm opened continues to auto-run as before.
  • On a same-repo PR, confirm an approving review no longer triggers the workflow (since the trigger was removed).

…njected on fork PRs
GitHub does not inject repo/org secrets (vars.APP_ID, secrets.APP_PRIVATE_KEY,
the Bedrock OIDC role) into workflows triggered by pull_request_review when the
PR head is a fork, regardless of the reviewer's access level. Approving a fork
PR therefore fired the workflow but the App-token step crashed with 'Input
required and not supplied: app-id' because vars.APP_ID resolved to empty.
The label-on-pull_request_target path does inject secrets and is the only
trigger that works end-to-end for fork PRs. Drop the pull_request_review
trigger entirely; same-repo maintainer PRs auto-run on opened/synchronize as
before, community PRs require the safe-to-review label.
@tejaskash
tejaskash requested a review from a teamMay 19, 2026 19:29
@github-actionsgithub-actionsBot added the size/s PR size: S label May 19, 2026
@github-actionsgithub-actionsBot added the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 19, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.14.0.tgz

How to install

gh release download pr-1310-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.14.0.tgz

@github-actions

github-actionsBot commented May 19, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines43.72%9272 / 21204
🔵Statements42.97%9839 / 22896
🔵Functions40.44%1604 / 3966
🔵Branches40.45%6029 / 14903
Generated in workflow #3134 for commit 9ea4f79 by the Vitest Coverage Report Action

@agentcore-cli-automationagentcore-cli-automation left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — the rationale is correct: GitHub does not inject repo/org secrets into pull_request_review runs when the PR head is a fork, so the trigger could never have completed the App-token step on community PRs. Removing it (plus the corresponding branches in the auth filter, the auth step if, and the isApproval script path) is the right fix, and the concurrency group cleanup is consistent with that.

The same-repo auto-run path (opened/reopened/synchronize gated on PR author) and the community label path (safe-to-review gated on the labeler) both still resolve correctly through the simplified if and the simplified script. CONTRIBUTING.md is updated to match.

Nothing blocking from me. One trivial nit you can ignore: the comment on lines 96–97 of .github/workflows/pr-security-review.yml still references pull_request_review events as a reason the default GITHUB_TOKEN is read-only — that event no longer triggers the workflow, so the reference is stale. Worth a one-line update next time you're in the file but not worth blocking on.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 19, 2026
Hweinstock
Hweinstock previously approved these changes May 19, 2026

@HweinstockHweinstock left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing!

notgitika
notgitika previously approved these changes May 19, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM thank you!

…ry on cancel
Three fixes rolled in:
1. Use the SDK's bundled /security-review slash command instead of inlining
the prompt. The Claude Code SDK that ships with anthropics/claude-code-action
exposes /security-review as a registered slash command (visible in the
'slash_commands' list its system init prints). It drives its own
git-diff-based context, sub-task fan-out, and false-positive filtering.
We were re-implementing all of that in a 23 KB inline prompt, plus a
fragile build step that crashed on fork PRs because
.github/prompts/security-review.md doesn't exist on the head ref.
Drops .github/prompts/security-review.md, the Build/Read prompt steps,
and the python templating. Workflow is ~300 lines lighter.
2. Concurrency: cancel-in-progress: false. Cancelling a run mid-analysis
leaves the buffer file empty but lets the if: always() summary step
fire, posting a misleading 'no high-confidence findings' comment.
Letting both runs complete is the safer default.
3. Summary step branches on steps.review.conclusion. Only post a real
findings count when the review step actually completed; on
failure/cancellation/skip, post a transparent status that says the run
didn't complete and a later run will replace it.
@tejaskash
tejaskash dismissed stale reviews from notgitika and Hweinstock via 9ea4f79May 20, 2026 15:22
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label May 20, 2026
@github-actionsgithub-actionsBot added size/m PR size: M and removed size/s PR size: S labels May 20, 2026

@notgitikanotgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

@tejaskash
tejaskash merged commit 43607fa into mainMay 20, 2026
27 of 28 checks passed
@tejaskash
tejaskash deleted the fix-fork-secrets branch May 20, 2026 16:08
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/mPR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@tejaskash@Hweinstock@notgitika@agentcore-cli-automation