anthropics / anthropics/claude-code-action

PR review workflow fails on forks from users without upstream write access

オープン
#974 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
area:permissions bug p2 provider:bedrock
主要言語
TypeScript
スター
8.9k
フォーク
2.1k
平均マージ
3日 9時間
マージ済み PR(30日)
10

説明

**Describe the bug**
When using `claude-code-action` in a **read-only PR review workflow** in fork repos for users without write access to upstream fails when trying to use the github token from Anthropic OIDC, with:

```
Error: Action failed with error: User does not have write access on this repository
```

The workflow only performs code review tasks — reading files, posting PR comments, and leaving inline review comments. It does not need to push commits, create branches, or modify repository contents via the GitHub API.

**To Reproduce**

The action is invoked with tools restricted to read/review operations:

```yaml
- uses: anthropics/claude-code-action@v2
with:
allowed_non_write_users: "*"
claude_args: |
--allowedTools "Read,Glob,Grep,Bash,Write,mcp__github_inline_comment__create_inline_comment"
```

(The `Write` tool here is Claude Code's local filesystem write — used to write a temp file before posting via `gh pr comment --body-file` — not a GitHub API write.)

**Expected behavior**
The GHA should not fail checking for write permission for a Github workflow that will not perform writes on the repository.

**Workaround**
passing `github_token` associated with our runner works, but then actions are not associated with `claude` bot user:

```yaml
- uses: anthropics/claude-code-action@v2
with:
github_token: ${{ github.token }}
allowed_non_write_users: "*"
claude_args: |
--allowedTools "Read,Glob,Grep,Bash,Write,mcp__github_inline_comment__create_inline_comment"
```

**API Provider**

[x] Anthropic First-Party API (default)
[x] AWS Bedrock
[x] GCP Vertex

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。