open-swe/agent/middleware
Johannes du Plessis 89f886e2fe
fix: request actions read for sandbox logs (#1642)
* fix: request actions read for sandbox logs

Request optional Actions read permission for sandbox proxy tokens, with fallback for installations that have not approved it yet. Update setup docs and prompt guidance for safe GitHub Actions log usage.

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>

* fix: restore actions:read scope after workflow push

After an approved workflow push, the guard was restoring the proxy with
BASE_RUNTIME_PROXY_TOKEN_PERMISSIONS, which excludes the actions: read
scope this PR adds. Restore with RUNTIME_PROXY_TOKEN_PERMISSIONS (which
includes actions: read) and fall back to BASE if the install hasn't
granted Actions read — mirroring the pattern in _create_sandbox_with_proxy.

Addresses review comment on PR #1642.

---------

Co-authored-by: open-swe[bot] <open-swe@users.noreply.github.com>
2026-06-29 13:28:13 -07:00
..
__init__.py feat: restore forced tool call to prevent premature run stops (#1622) 2026-06-26 14:39:46 -07:00
check_message_queue.py fix: update Slack trace reply on web handoff (#1630) 2026-06-29 10:22:01 -07:00
ensure_no_empty_msg.py feat: restore forced tool call to prevent premature run stops (#1622) 2026-06-26 14:39:46 -07:00
exclude_tools.py feat: add reviewer graph + eval target wiring (#1241) 2026-05-06 10:15:58 -07:00
model_fallback.py feat(open-swe): stream agent chat via @langchain/react v2 protocol (#1475) 2026-06-11 09:54:35 -07:00
notify_step_limit.py fix: notify users via Slack when agent hits model call step limit (#1204) 2026-05-01 14:24:25 -07:00
plan_mode.py feat: publish plans from sandbox files (#1635) 2026-06-29 13:02:55 -07:00
refresh_github_proxy.py fix: refresh sandbox GitHub proxy token before mid-run expiry (#1496) 2026-06-11 10:59:21 -07:00
refresh_slack_status.py fix Slack assistant status endpoint (#1272) 2026-05-08 13:07:32 -07:00
repair_orphaned_tool_calls.py fix: repair orphaned tool calls before model calls (#1604) 2026-06-24 12:58:10 -07:00
sandbox_circuit_breaker.py fix: recover from mid-run sandbox death (#1274) 2026-05-08 12:55:36 -07:00
sanitize_thinking_blocks.py fix: sanitize malformed Anthropic thinking blocks (#1357) 2026-05-28 16:15:13 -07:00
sanitize_tool_inputs.py fix: coerce malformed integer strings in read_file offset/limit params (#1216) 2026-05-01 14:29:48 -07:00
settle_review_check.py fix: settle incomplete review check as neutral, not failure (#1501) 2026-06-11 13:03:34 -07:00
tool_artifact.py feat(open-swe): stream agent chat via @langchain/react v2 protocol (#1475) 2026-06-11 09:54:35 -07:00
tool_error_handler.py fix: keep sandbox backend stable across recovery (#1294)w 2026-05-11 16:03:38 -07:00
workflow_push_guard.py fix: request actions read for sandbox logs (#1642) 2026-06-29 13:28:13 -07:00