Skip to content

fix(init): scaffolded CI key guidance names policy:read - #24

Merged
babaliauskas merged 1 commit into
mainfrom
fix/ci-key-policy-read
Oct 1, 2026
Merged

babaliauskas merged 1 commit into
mainfrom
fix/ci-key-policy-read

Conversation

@babaliauskas

Copy link
Copy Markdown
Collaborator

The CI key that evalshift init --ci scaffolds, and that the docs describe, was run:create + run:read. That's not enough for the default gate:

  • The action's default fail-on: policy reads the run's verdict from GET /runs/{id}/policy-check, which requires policy:read (server app/policy/service.py).
  • Without it, that call gets a 403 and the action silently falls back to fail-on: regression, printing only a warning.

This PR changes the guidance to run:create + run:read + policy:read in:

  • the scaffold template comment, with a test written first;
  • DOCS.md, llms-full.txt, docs/github-action.md and docs/hosted.md.

There's also a CHANGELOG ### Fixed entry. project:read is not needed.

This change is correct against today's server and action, so it can merge independently of the preflight redesign (evalshift-server / evalshift-action PRs).

Gate: make ci is green (2352 tests pass). An independent review confirmed the 403 fallback against the server and action code.

🤖 Generated with Claude Code

The scaffolded workflow (evalshift init --ci) defaults to
fail-on: policy, which reads the hosted policy-check endpoint
(requires policy:read). The scaffold and every doc copy of the CI
key guidance named only run:create + run:read, so a key minted per
that guidance got a 403 on the policy check and the action silently
fell back to fail-on: regression instead of the intended gate.

Add run:create + run:read + policy:read to the scaffolded workflow
comment, DOCS.md, llms-full.txt, docs/github-action.md, and
docs/hosted.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@babaliauskas
babaliauskas merged commit 722753d into main Oct 1, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant