fix(ci): gate auto-fix to same-repo human runs (#1663)

## Summary

The `workflow_run` auto-fix job has write permissions and checks out the triggering PR branch. It now runs only when all three conditions hold:

- the tracked CI workflow failed on a pull request;
- the pull request branch belongs to this repository, not a fork;
- the triggering actor is not a bot account.

The same-repository check closes the privileged fork boundary. The generic `[bot]` suffix check covers Polylane, Graphite, Dependabot, and other GitHub App bot users without maintaining a name list.

## Validation

- `go run github.com/rhysd/actionlint/cmd/actionlint@v1.7.12 .github/workflows/claude-auto-fix-ci.yml`
- YAML parse with the repository's installed parser
- Final diff audit: one workflow, +3/-1, no added comments

Human-triggered same-repository pull requests keep the existing auto-fix behavior.
This commit is contained in:
Dhravya 2026-09-18 05:46:34 +00:00
parent 69327ca1c6
commit bf2db3dc79
No known key found for this signature in database
GPG key ID: 135A27003CF4F6CB

View file

@ -17,7 +17,9 @@ jobs:
auto-fix:
if: |
github.event.workflow_run.conclusion == 'failure' &&
github.event.workflow_run.pull_requests[0]
github.event.workflow_run.pull_requests[0] &&
github.event.workflow_run.head_repository.full_name == github.event.workflow_run.repository.full_name &&
!endsWith(github.event.workflow_run.actor.login, '[bot]')
runs-on: ubuntu-latest
timeout-minutes: 30
steps: