shoc-pr-review-runner/.github
Adam Moussa 3c541cc7b4
fix: never report an unread CI signal as missing CI
The first live run reported the reviewed PR's CI as "missing" while it was
actually green, and the model cited that as a reason to withhold approval.

Reading check-runs needs the App's checks:read permission, which the App did
not have, so the call 403'd and the fallback turned an authorization failure
into the factual claim "this PR has no CI". That is the exact failure this
runner exists to prevent, applied to a governance signal instead of a gate.

Distinguish the two: an unreadable signal is now recorded as "unknown", the
evidence report says unknown is not evidence of absent or failing CI, and the
skill tells the reviewer that a signal the runner could not read is not a
finding. Request checks:read at token mint so the signal is readable at all.

Also correct the App verification snippet in the README: listing an
installation's selected repositories needs the installation token, so the
documented /user/installations call does not work for an org admin.
2026-07-29 12:35:36 -04:00
..
workflows fix: never report an unread CI signal as missing CI 2026-07-29 12:35:36 -04:00
dependabot.yml feat: SHOC PR review runner, phase 1 2026-07-29 12:05:38 -04:00