()
| 1771 | ['gh', 'api', `repos/{owner}/{repo}/issues/comments/${commentId}`, '-X', 'PATCH', '-F', 'body=@-'], |
| 1772 | { cwd: rootDir, input: markedBody }, |
| 1773 | ); |
| 1774 | log.dim(' Updated PR comment'); |
| 1775 | } else { |
| 1776 | await runArgsAsync(['gh', 'pr', 'comment', validPr, '--body-file', '-'], { |
| 1777 | cwd: rootDir, |
| 1778 | input: markedBody, |
| 1779 | }); |
| 1780 | log.dim(' Posted PR comment'); |
| 1781 | } |
| 1782 | } catch (err) { |
| 1783 | log.warn(` Failed to comment on PR: ${err instanceof Error ? err.message : err}`); |
| 1784 | // Most common cause: the workflow is on `pull_request` and this is a fork PR, |
| 1785 | // so GITHUB_TOKEN is read-only. Surface that explicitly — otherwise contributors |
| 1786 | // see a red check with no comment and no clue why. |
| 1787 | if (process.env.GITHUB_EVENT_NAME === 'pull_request' && isForkPr()) { |
| 1788 | log.warn( |
| 1789 | ' This PR is from a fork. Fork PRs running on `pull_request` get a read-only token\n' + |
| 1790 | ' and cannot post comments. Switch the workflow to `pull_request_target` —\n' + |
| 1791 | ' see https://bumpy.varlock.dev/docs/github-actions', |
| 1792 | ); |
| 1793 | } |
| 1794 | } |
| 1795 | } |
| 1796 | |
| 1797 | function detectPrBranch(rootDir: string): string | null { |
| 1798 | // GitHub Actions sets GITHUB_HEAD_REF for pull_request events |
no test coverage detected
searching dependent graphs…