Skip to content
LatchkeyLatchkey home

GitHub Actions "This workflow is awaiting approval from required reviewers"

When a job targets an environment with a required-reviewers protection rule, the job pauses before running until a designated reviewer approves the deployment.

What this error means

A deploy job is paused with a banner that it is awaiting approval from required reviewers.

github-actions
This workflow is awaiting approval from required reviewers.
The job targeting environment 'production' is paused until a reviewer approves.

Diagnose it: what token do you actually have?

Permission failures in Actions are almost never about your repository settings alone. Three things combine: the default GITHUB_TOKEN permission set for the repo or organization, the permissions: block in the workflow, and whether the event is a fork pull request, which downgrades the token to read-only regardless of everything else.

.github/workflows/ci.yml
- name: Show the token scopes actually granted
  run: |
    curl -sI -H "Authorization: Bearer $GITHUB_TOKEN" \
      https://api.github.com/ | grep -i "^x-oauth-scopes\|^x-accepted"
    echo "event: ${{ github.event_name }}"
    echo "fork PR: ${{ github.event.pull_request.head.repo.fork }}"
  env:
    GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

Common causes

Environment required-reviewers rule

The targeted environment has a protection rule listing reviewers who must approve each deployment.

How to fix it

Approve the deployment

  1. A listed reviewer opens the run and clicks Review deployments, then Approve and deploy.
  2. If the wait timer is configured, the job also respects that delay.

Adjust reviewers if unintended

  1. Open Settings > Environments > the environment > Required reviewers.
  2. Update the reviewer list or remove the rule if it should not gate this environment.

Grant the narrowest permission that works

Declaring a permissions: block switches the job from the repository default to exactly what you list, so an incomplete block is a common cause of a new failure right after someone tightened security. List every scope the job needs, not just the one that failed.

.github/workflows/ci.yml
permissions:
  contents: read        # checkout
  packages: write       # push to GHCR
  id-token: write       # OIDC to a cloud provider
  pull-requests: write  # comment on or label a PR
  checks: write         # publish check runs

How to prevent it

  • Make sure at least one available reviewer is configured per protected environment.
  • Document who approves production deployments.

Frequently asked questions

What causes GitHub Actions "This workflow is awaiting approval from required reviewers"?
environment required-reviewers rule. The targeted environment has a protection rule listing reviewers who must approve each deployment.
How do I fix GitHub Actions "This workflow is awaiting approval from required reviewers"?
There are 2 fixes depending on which cause you have: approve the deployment and adjust reviewers if unintended. Work through them in order, since the first is the most common.
What does GitHub Actions "This workflow is awaiting approval from required reviewers" actually mean?
A deploy job is paused with a banner that it is awaiting approval from required reviewers.
How do I stop GitHub Actions "This workflow is awaiting approval from required reviewers" happening again?
Make sure at least one available reviewer is configured per protected environment. The prevention section lists 2 changes that keep it from recurring.

Related guides

References

Not every red build is your code. Latchkey repairs the ones that are not, on the runner. Start free → 30-day trial · No credit card