PR comments
Carrick comments contract-drift findings on your pull requests, posted by the GitHub App, on by default and toggled per project.
The Carrick GitHub App evaluates proposed code changes on pull requests against the project index, posting feedback when cross-service contracts drift or break. Carrick updates a single comment in place on subsequent pushes to prevent pull request comment clutter.
Setup and activation
PR comments are enabled by default for all connected repositories in a project. Once you install the Carrick GitHub App and connect your repositories, contract validation comments appear on pull requests without requiring additional workflow configuration.
Because the GitHub App handles comment publication directly, your GitHub Actions workflow requires no pull-requests: write permissions or custom comment steps.
To disable or re-enable PR comments for a project, adjust the PR comments toggle on the project settings page in the Carrick dashboard.
Reported findings
On every pull request push, Carrick compares the proposed changes against the current project index and reports:
- Missing or modified operations: Outbound client calls targeting endpoints, GraphQL fields, WebSocket events, or pub/sub topics that are missing or modified in producer services.
- Type mismatches: Incompatible request bodies, query parameters, or response payload types between producers and consumers.
- Dependency version conflicts: Packages pinned to conflicting versions across services in the same project.
- Configuration suggestions: Calls constructed using unclassified environment variables, prompting you to declare them in
carrick.json.
When all cross-service calls match existing contracts, Carrick posts an explicit confirmation stating that all cross-service calls match the indexed contracts, distinguishing verified pull requests from unverified ones.
Fork pull requests
Carrick skips scanning pull requests originating from repository forks. Because GitHub withholds Actions OIDC tokens on fork-triggered workflow runs, the Carrick Action logs a notice and exits with status 0 to avoid failing external pull request checks.
Related
- Quickstart covers repository connection and workflow setup.
- carrick.json explains how to classify outbound calls to prevent unclassified variable warnings.
- Task skills details agent skills for investigating and resolving contract drift.