Run lint as a plain CI job so fork PRs report status - #1494
Conversation
wearerequired/lint-action reports results by creating ESLint/Prettier check runs, which needs checks: write. GitHub gives pull_request runs from forks a read-only token, so check-run creation 403s, the step still passes (continue_on_error), and the required ESLint/Prettier checks stay pending forever, blocking merge (e.g. #1477). Replace it with a single `lint` job that runs the existing `lint` and `format:check` scripts, so the job itself fails on lint errors, and drop the now-unused checks: write permission. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
AI Agent Review (openai, openai-astra)Nothing to flag. The new
Before merging: if branch protection on This review did not run CI, so it can't say whether the job passes. If there are existing |
AI Agent Review LGTM (openai, openai-astra)LGTM. No blocking findings were found. LGTM. This PR removes What I checked in the checkout:
Notes that are not line findings:
I can't run anything in this environment, so I couldn't confirm the workflow passes in CI. |
Resolve the .github/workflows/ci.yml conflict with #1494, which moved linting out of the build job into its own lint job. Drop the old wearerequired/lint-action step and keep this branch's Type check step in the build job, between npm install and Build. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Description of the change
PRs opened from forks can't be merged without an admin override, because the required
ESLintandPrettierchecks never show up (e.g. #1477).Cause:
wearerequired/lint-actiondoesn't pass or fail the job itself. It reports results by creating separateESLint/Prettiercheck runs through the Checks API, which needschecks: write. GitHub always givespull_requestruns from forks a read-only token, whatever the workflow'spermissions:block says, so creating the check runs fails:Because the action runs with
continue_on_error: true, the step still passes. So on fork PRs the required checks stay pending forever, and a fork PR with real lint errors would still finish green.Fix: replace the action with a single
lintjob that runs the existingnpm run lint -- --max-warnings 0andnpm run format:checkscripts, so the job itself fails on lint errors. This also:checks: writepermission, which only the action usedTrade-off: we lose the action's inline annotations on the diff. They never worked for fork PRs anyway.
mastercurrently requires theESLintandPrettierchecks, and this PR no longer produces them, so this PR will itself show as blocked until the rule changes. A repo admin needs to update Settings → Branches → master → Required status checks:ESLintandPrettierlintDo this right before merging. Once it's done, open PRs that haven't merged this change yet won't report
lintuntil they're updated from master (which the strict up-to-date rule already requires).Type of change
Related issues
Checklists
Development
npm run lint -- --max-warnings 0andnpm run format:checkboth pass on this branch)Code review
🤖 Generated with Claude Code