Skip to content

CI: stop a failing Claude review from blocking Dependabot bumps - #1228

Open
JeanMarcMilletScality wants to merge 1 commit into
development/1.0from
improvement/skip-code-review-on-dependabot
Open

JeanMarcMilletScality wants to merge 1 commit into
development/1.0from
improvement/skip-code-review-on-dependabot

Conversation

@JeanMarcMilletScality

@JeanMarcMilletScality JeanMarcMilletScality commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

TL;DR — Every Dependabot pull request carried a review / claude-review check that failed before it ran, leaving approved dependency bumps unmergeable; the job is now skipped on them.

Context / Why

Four Dependabot bumps are open against development/1.0 and none can merge — #1203 is approved and still held at the build gate. The only red check on each is review / claude-review, which fails in two seconds while the reusable workflow call is evaluated:

Secret GCP_WORKLOAD_IDENTITY_PROVIDER is required, but not provided while calling.

GitHub runs Dependabot's pull_request events against the Dependabot secret store rather than the Actions one, so secrets: inherit hands over nothing. Nothing about the bump itself is wrong, and retrying cannot clear it.

Skipping the job emits no check at all rather than a green one. That is safe here: #1092 merged in May with no review / claude-review check run on its commit.

🔍 Review focus

  • 🟡 Moderate.github/workflows/review.yml › the if: expression — inverted or misspelled, it silently drops review from every pull request. This one is the test: it is human-authored, and review / claude-review passed on it.

🧪 How to test

Once merged, comment @dependabot rebase on one of the open bumps, then confirm the review job is skipped and no review / claude-review check appears on it.

Follow-up

  • The four open bumps need a rebase after this lands to pick up the guard, or a privileged /bypass_build_status to merge as they stand.

🤖 Generated with Claude Code

@bert-e

bert-e commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Hello jeanmarcmilletscality,

My role is to assist you with the merge of this
pull request. Please type @bert-e help to get information
on this process, or consult the user documentation.

Available options
name description privileged authored
/after_pull_request Wait for the given pull request id to be merged before continuing with the current one.
/bypass_author_approval Bypass the pull request author's approval
/bypass_build_status Bypass the build and test status
/bypass_commit_size Bypass the check on the size of the changeset TBA
/bypass_incompatible_branch Bypass the check on the source branch prefix
/bypass_jira_check Bypass the Jira issue check
/bypass_peer_approval Bypass the pull request peers' approval
/bypass_leader_approval Bypass the pull request leaders' approval
/bypass_source_branch_lineage Bypass the cross-branch contamination check
/approve Instruct Bert-E that the author has approved the pull request. ✍️
/create_pull_requests Allow the creation of integration pull requests.
/create_integration_branches Allow the creation of integration branches.
/no_octopus Prevent Wall-E from doing any octopus merge and use multiple consecutive merge instead
/unanimity Change review acceptance criteria from one reviewer at least to all reviewers
/wait Instruct Bert-E not to run until further notice.
Available commands
name description privileged
/help Print Bert-E's manual in the pull request.
/status Print Bert-E's current status in the pull request.
/clear Remove all comments from Bert-E from the history TBA
/retry Re-start a fresh build TBA
/build Re-start a fresh build TBA
/force_reset Delete integration branches & pull requests, and restart merge process from the beginning.
/reset Try to remove integration branches unless there are commits on them which do not appear on the source branch.

Status report is not available.

@bert-e

bert-e commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Waiting for approval

The following approvals are needed before I can proceed with the merge:

  • the author

  • one peer

Peer approvals must include at least 1 approval from the following list:

Dependabot's pull_request events run against the Dependabot secret store
rather than the Actions one, so `secrets: inherit` supplies nothing and the
reusable workflow call is rejected before any step runs. The resulting red
check left approved dependency bumps unmergeable behind Bert-E's build gate.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@JeanMarcMilletScality
JeanMarcMilletScality force-pushed the improvement/skip-code-review-on-dependabot branch from 55387b2 to a1226eb Compare September 21, 2026 15:40
@JeanMarcMilletScality
JeanMarcMilletScality marked this pull request as ready for review September 21, 2026 15:43

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants