|
1 | 1 | name: Claude Code Review |
2 | 2 |
|
| 3 | +# Triggers only. The implementation - author gate, runner selection, action |
| 4 | +# pins - lives in RoboFinSystems/robosystems/.github/workflows/claude-review.yml |
| 5 | +# so a claude-code-action bump is one PR instead of one per repo. |
| 6 | + |
3 | 7 | on: |
4 | 8 | issue_comment: |
5 | 9 | types: [created] |
|
12 | 16 |
|
13 | 17 | jobs: |
14 | 18 | claude: |
15 | | - # Defense-in-depth author gate: only run when the triggering actor is a repo |
16 | | - # OWNER/MEMBER/COLLABORATOR, so a drive-by comment from an outside account |
17 | | - # cannot invoke Claude or drain Claude usage. This repo is public, so the |
18 | | - # gate is load-bearing, not decorative. |
19 | | - if: | |
20 | | - (github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude') && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association)) || |
21 | | - (github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude') && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association)) || |
22 | | - (github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude') && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.review.author_association)) || |
23 | | - (github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')) && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.issue.author_association)) |
24 | | - runs-on: ubuntu-latest |
25 | | - timeout-minutes: 15 |
| 19 | + # Granted here as well as in the called workflow: a called workflow's jobs |
| 20 | + # cannot exceed the permissions of the caller's GITHUB_TOKEN. |
26 | 21 | permissions: |
27 | 22 | contents: read |
28 | 23 | pull-requests: read |
29 | 24 | issues: read |
| 25 | + actions: read |
30 | 26 | id-token: write |
31 | | - actions: read # Required for Claude to read CI results on PRs |
32 | | - steps: |
33 | | - - name: Checkout repository |
34 | | - uses: actions/checkout@v7 |
35 | | - with: |
36 | | - fetch-depth: 1 |
37 | | - |
38 | | - - name: Run Claude Code |
39 | | - id: claude |
40 | | - uses: anthropics/claude-code-action@a874e9ecd7bb36efdad65429c6b35815f5a08f10 # v1 |
41 | | - with: |
42 | | - claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} |
43 | | - |
44 | | - # This is an optional setting that allows Claude to read CI results on PRs |
45 | | - additional_permissions: | |
46 | | - actions: read |
47 | | -
|
48 | | - # Optional: Give a custom prompt to Claude. If this is not specified, Claude will perform the instructions specified in the comment that tagged it. |
49 | | - # prompt: 'Update the pull request description to include a summary of changes.' |
50 | | - |
51 | | - # Optional: Add claude_args to customize behavior and configuration |
52 | | - # See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md |
53 | | - # or https://docs.claude.com/en/docs/claude-code/cli-reference for available options |
54 | | - # claude_args: '--allowed-tools Bash(gh pr:*)' |
| 27 | + uses: RoboFinSystems/robosystems/.github/workflows/claude-review.yml@main |
| 28 | + secrets: inherit |
0 commit comments