anthropics / anthropics/claude-code-action

PR review workflow fails on forks from users without upstream write access

Open
#974 0 comments 0 reactions 0 assignees View on GitHub
area:permissions bug p2 provider:bedrock
Dominant language
TypeScript
Stars
8.9k
Forks
2.1k
Avg merge
3d 9h
Merged PRs (30d)
10

Description

**Describe the bug**
When using `claude-code-action` in a **read-only PR review workflow** in fork repos for users without write access to upstream fails when trying to use the github token from Anthropic OIDC, with:

```
Error: Action failed with error: User does not have write access on this repository
```

The workflow only performs code review tasks — reading files, posting PR comments, and leaving inline review comments. It does not need to push commits, create branches, or modify repository contents via the GitHub API.

**To Reproduce**

The action is invoked with tools restricted to read/review operations:

```yaml
- uses: anthropics/claude-code-action@v2
with:
allowed_non_write_users: "*"
claude_args: |
--allowedTools "Read,Glob,Grep,Bash,Write,mcp__github_inline_comment__create_inline_comment"
```

(The `Write` tool here is Claude Code's local filesystem write — used to write a temp file before posting via `gh pr comment --body-file` — not a GitHub API write.)

**Expected behavior**
The GHA should not fail checking for write permission for a Github workflow that will not perform writes on the repository.

**Workaround**
passing `github_token` associated with our runner works, but then actions are not associated with `claude` bot user:

```yaml
- uses: anthropics/claude-code-action@v2
with:
github_token: ${{ github.token }}
allowed_non_write_users: "*"
claude_args: |
--allowedTools "Read,Glob,Grep,Bash,Write,mcp__github_inline_comment__create_inline_comment"
```

**API Provider**

[x] Anthropic First-Party API (default)
[x] AWS Bedrock
[x] GCP Vertex

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.