Posts finalized review comments to GitHub as a pending review after critique iteration is complete.
Post finalized comments to a GitHub review. Pending is the default. Submission is a separate authorized mutation with fail-closed target and head verification.
Reference: Follow Core Review Principles and Authorization Preflight from
paw-review-workflow.
Read both artifacts from .paw/reviews/<identifier>/:
ReviewComments.mdfinalized**Final**: markerReady for GitHub postingReviewContext.mdReview Platform: githubPreflight Status: passedIf these conditions fail, report the exact blocker. Do not create or submit a review.
For Azure DevOps or local contexts, skip GitHub mutations and use the artifact-only flow.
| Condition | Action |
|---|---|
Authorization absent; action pending |
Create or reuse a pending review, then stop |
Explicit authorization; action submit |
Create or reuse the exact pending review, verify the authorization tuple, then submit |
| Authorization ambiguous or preflight blocked | Stop before mutation and report the conflict |
| Requested mutation unavailable | Preserve artifacts and report capability unavailable |
| Review already submitted | Report the terminal state; do not replay |
Allowed submission events are APPROVE, REQUEST_CHANGES, and COMMENT.
Read the target, head, capability, requested action, authorization, event, and authorized pending-review value from ReviewContext.md.
Filter ReviewComments.md:
Ready for GitHub postingSkipped**Final**: markers, and PAW artifact names localResolve one candidate review ID:
Authorized Pending Review ID from ReviewContext.md.bind-created-review as a sentinel, not a concrete recovery ID.If both artifacts contain concrete IDs and they differ, block and report the mismatch. Do not create a duplicate.
Before any mutation, use GitHub read capabilities to resolve:
The repository and PR must match ReviewContext.md. A closed PR, missing target, or head mismatch blocks mutation.
If the head changed:
Preflight Status: blocked: head changed and the observed head in ReviewContext.md.If no candidate review ID is recorded:
Status: Posting in progress.Authorized Pending Review is bind-created-review, replace it in ReviewContext.md with the returned ID.If a candidate review ID is recorded:
Authorized Pending Review is bind-created-review, replace it with the re-resolved pending review ID before evaluating submission.For either path, compare the finalized comments with locally recorded and live pending-review comment IDs. Add only missing comments and record each returned comment ID before continuing.
Update ReviewComments.md after comment posting completes:
**Status**: Posted to GitHub pending review
**Pending Review ID**: <id>
**Comments Posted**: <posted> of <finalized>
Each posted comment records its GitHub comment ID. Skipped comments remain unposted in the artifact.
If Requested Output Action is pending, stop with the pending review.
For submit, require:
Submission Authorization: explicitImmediately before submission, re-read live GitHub state and verify this tuple:
repository + PR + live head + pending review ID + event
Every value must be present and equal to the authorization recorded in ReviewContext.md. On absence, ambiguity, mismatch, permission failure, or changed state:
When the tuple matches, submit that review with the authorized event. Record the submitted review ID, event, head, and timestamp in both artifacts.
A submitted review is terminal for this workflow run:
Treat each PR as a separate authorization boundary:
When the platform is Azure DevOps or local, or executable GitHub capability is unavailable:
An explicit unsupported submission request must have been reported before the Understanding stage. Do not silently convert it to artifact-only output.
True invariants
Defaults
User-configurable policy
Report one of: