From d3c81493f09e2bb5a92f53c3bf5427d8bd5da199 Mon Sep 17 00:00:00 2001 From: jnasbyupgrade Date: Mon, 13 Jul 2026 18:12:19 -0500 Subject: [PATCH 1/3] Add Claude Code GitHub Actions workflows Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/claude-code-review.yml | 52 ++++++++++++++++++++++++ .github/workflows/claude.yml | 48 ++++++++++++++++++++++ 2 files changed, 100 insertions(+) create mode 100644 .github/workflows/claude-code-review.yml create mode 100644 .github/workflows/claude.yml diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml new file mode 100644 index 0000000..b1f6cd5 --- /dev/null +++ b/.github/workflows/claude-code-review.yml @@ -0,0 +1,52 @@ +name: Claude Code Review + +# Runs on PRs INTO this repo. We use pull_request_target (not pull_request) so +# that PRs from a fork can access CLAUDE_CODE_OAUTH_TOKEN — GitHub withholds +# secrets from `pull_request` runs triggered by forks, which is why the plain +# `pull_request` version never worked for fork PRs. +# +# SECURITY: pull_request_target runs in the BASE repo with secrets and a +# write-capable token. The job is gated to PRs from the trusted `jnasbyupgrade` +# fork only — an arbitrary external fork can never trigger this secret-bearing +# job. The workflow file always comes from the base branch (master), so a PR +# cannot modify the reviewer that runs on it. We check out the PR head only for +# read context (persist-credentials: false) and never build or execute PR code. +on: + pull_request_target: + types: [opened, synchronize, reopened, ready_for_review] + +concurrency: + group: claude-review-${{ github.event.pull_request.number }} + cancel-in-progress: true + +jobs: + claude-review: + # Trusted fork only, and skip drafts (don't spend API/CI on unfinished PRs). + # To add more trusted owners, extend the head-owner check. + if: >- + github.event.pull_request.draft == false && + github.event.pull_request.head.repo.owner.login == 'jnasbyupgrade' + runs-on: ubuntu-latest + timeout-minutes: 30 + permissions: + contents: read + pull-requests: write # post the review comments + id-token: write + steps: + - name: Check out PR head (read-only context) + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + with: + repository: ${{ github.event.pull_request.head.repo.full_name }} + ref: ${{ github.event.pull_request.head.sha }} + fetch-depth: 1 + persist-credentials: false + + - name: Run Claude Code Review + uses: anthropics/claude-code-action@e90deca47693f9457b72f2b53c17d7c445a87342 # v1 + with: + claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} + # NOTE: plugin_marketplaces can't be pinned — it tracks the + # marketplace repo's default branch (upstream anthropics/claude-code). + plugin_marketplaces: 'https://github.com/anthropics/claude-code.git' + plugins: 'code-review@claude-code-plugins' + prompt: '/code-review:code-review ${{ github.repository }}/pull/${{ github.event.pull_request.number }}' diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml new file mode 100644 index 0000000..b5638d2 --- /dev/null +++ b/.github/workflows/claude.yml @@ -0,0 +1,48 @@ +name: Claude Code + +on: + issue_comment: + types: [created] + pull_request_review_comment: + types: [created] + issues: + types: [opened, assigned] + pull_request_review: + types: [submitted] + +# Serialize per issue/PR. cancel-in-progress is false on purpose: cancelling +# would kill Claude mid-response if another comment lands while it's working. +concurrency: + group: claude-${{ github.event.issue.number || github.event.pull_request.number }} + cancel-in-progress: false + +jobs: + claude: + if: | + (github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) || + (github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) || + (github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) || + (github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude'))) + runs-on: ubuntu-latest + timeout-minutes: 30 + permissions: + contents: read + pull-requests: read + issues: read + id-token: write + actions: read # Required for Claude to read CI results on PRs + steps: + - name: Checkout repository + uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + with: + fetch-depth: 1 + persist-credentials: false + + - name: Run Claude Code + id: claude + uses: anthropics/claude-code-action@e90deca47693f9457b72f2b53c17d7c445a87342 # v1 + with: + claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} + # Allows Claude to read CI results on PRs + additional_permissions: | + actions: read From b9f120c06c38345b03fdde1c37afcda3e3daae9a Mon Sep 17 00:00:00 2001 From: jnasbyupgrade Date: Mon, 13 Jul 2026 18:21:52 -0500 Subject: [PATCH 2/3] ci: track major-version action tags instead of pinned SHAs Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/claude-code-review.yml | 6 ++++-- .github/workflows/claude.yml | 6 ++++-- 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml index b1f6cd5..377996a 100644 --- a/.github/workflows/claude-code-review.yml +++ b/.github/workflows/claude-code-review.yml @@ -34,7 +34,9 @@ jobs: id-token: write steps: - name: Check out PR head (read-only context) - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + # Intentionally tracks the major-version tag (not a pinned SHA) so + # upstream fixes are picked up automatically. + uses: actions/checkout@v4 with: repository: ${{ github.event.pull_request.head.repo.full_name }} ref: ${{ github.event.pull_request.head.sha }} @@ -42,7 +44,7 @@ jobs: persist-credentials: false - name: Run Claude Code Review - uses: anthropics/claude-code-action@e90deca47693f9457b72f2b53c17d7c445a87342 # v1 + uses: anthropics/claude-code-action@v1 with: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} # NOTE: plugin_marketplaces can't be pinned — it tracks the diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml index b5638d2..b316236 100644 --- a/.github/workflows/claude.yml +++ b/.github/workflows/claude.yml @@ -33,14 +33,16 @@ jobs: actions: read # Required for Claude to read CI results on PRs steps: - name: Checkout repository - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + # Intentionally tracks the major-version tag (not a pinned SHA) so + # upstream fixes are picked up automatically. + uses: actions/checkout@v4 with: fetch-depth: 1 persist-credentials: false - name: Run Claude Code id: claude - uses: anthropics/claude-code-action@e90deca47693f9457b72f2b53c17d7c445a87342 # v1 + uses: anthropics/claude-code-action@v1 with: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} # Allows Claude to read CI results on PRs From 3b5fa0001edbaf718ce279ef7dc275a2b25dcde1 Mon Sep 17 00:00:00 2001 From: jnasbyupgrade Date: Mon, 13 Jul 2026 18:28:12 -0500 Subject: [PATCH 3/3] ci: drop concurrency limit from the @claude workflow Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/claude.yml | 8 ++------ 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml index b316236..c85ec00 100644 --- a/.github/workflows/claude.yml +++ b/.github/workflows/claude.yml @@ -10,12 +10,8 @@ on: pull_request_review: types: [submitted] -# Serialize per issue/PR. cancel-in-progress is false on purpose: cancelling -# would kill Claude mid-response if another comment lands while it's working. -concurrency: - group: claude-${{ github.event.issue.number || github.event.pull_request.number }} - cancel-in-progress: false - +# No concurrency limit: @claude mentions are independent, read-only requests; +# serializing would only delay responses and cancelling would drop them. jobs: claude: if: |