Skip to content

ci: pass greenlight review secrets by name in greenlight-review.yml - #138

Merged
jayantk merged 1 commit into
mainfrom
hydra/i-feypsnqy/head
Oct 1, 2026
Merged

jayantk merged 1 commit into
mainfrom
hydra/i-feypsnqy/head

Conversation

@jayantk

@jayantk jayantk commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

What changed

In .github/workflows/greenlight-review.yml, the call to dourolabs/greenlight-actions/.github/workflows/greenlight-review-impl.yml@v1 now passes ANTHROPIC_API_KEY and CLAUDE_CODE_OAUTH_TOKEN by name. It no longer uses secrets: inherit.

Why

secrets: inherit passes secrets to a reusable workflow only when the caller and the reusable workflow are in the same org or enterprise. pyth-network and dourolabs are different orgs, so GitHub passed no secrets, and every review failed with "The review agent has no credential".

The impl workflow declares both secrets as optional. An unset secret renders empty, and the impl workflow treats empty as absent, so its "exactly one credential" check still works.

Required setup

The pyth-network org secret (ANTHROPIC_API_KEY or CLAUDE_CODE_OAUTH_TOKEN) must also be shared with this repo for reviews to pass. We could not verify this with the agent token.

Checks

  • Parsed the edited workflow with js-yaml.
  • grep finds no other reference to secrets: inherit in this repo.

🤖 Generated with Claude Code

secrets: inherit does not pass secrets to a reusable workflow in another
org, so the dourolabs greenlight-review-impl workflow got no credential.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@jayantk
jayantk merged commit 24e23da into main Oct 1, 2026
6 of 7 checks passed
@jayantk
jayantk deleted the hydra/i-feypsnqy/head branch October 1, 2026 13:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants