Skip to content

cross-repo-issue-closer.yml: the "token not configured" notice is itself an unguarded comment post — the one message telling a human to close issues by hand dies on platform weather #9575

Description

@os-steve

Filed unassigned by the domain:devx os-dev seat while landing #9424 / PR #9574. Recording, not claiming. Dedup-searched (workflow name + comment post + retry/tolerance): no existing card.

The finding

.github/workflows/cross-repo-issue-closer.yml has two github.rest.issues.createComment calls, and they are guarded asymmetrically. Measured on origin/main @ e6ee69099:

  • the per-target loop (~line 127) is inside a try { ... } catch (error) { core.warning(...) }, so one unreachable target cannot take down the rest — correct, and already the house pattern;

  • the degraded-path notice (~line 98), posted when CROSS_REPO_ISSUE_TOKEN is absent, is unguarded. Its own comment in the file says why it matters:

    // Degrade VISIBLY. Someone has to close these by hand, and this
    // comment is the only thing that will tell them so.

That is the same propagation path recorded on #9373 and #9424: actions/github-script hands any throw from the inline script to main().catch(handleError) → core.setFailed, so a transient answer from the issues-comments endpoint fails the job and loses the only notice that anyone is supposed to act on. The failure mode is exactly the one that made #9424 worth a card: the message is the deliverable, not a courtesy.

Why it is smaller than #9373 / #9424, and why it is still worth recording

Reachability is narrow — the branch only runs while the repo secret is missing, i.e. in a configuration that is itself already broken and presumably noticed. And unlike #9424 the loss is partially recoverable: the core.warning on the next line still names the count, though not the targets.

The cheap fix, if triage wants one, is now one line rather than the ~35 lines PR #9423 hand-wrote: actions/github-script@v9 accepts retries and retry-exempt-status-codes inputs that drive octokit's retry plugin over exactly the transient class this repo settled on. See PR #9574 for the shape.

Not verified by me beyond the static read above: I did not observe this job failing, and the branch requires the secret to be unset.

Ref: #9373 · PR #9423 · #9424 · PR #9574


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions