diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml index 01456be..54166c7 100644 --- a/.github/workflows/claude.yml +++ b/.github/workflows/claude.yml @@ -1,5 +1,9 @@ name: Claude Code Review +# Triggers only. The implementation - author gate, runner selection, action +# pins - lives in RoboFinSystems/robosystems/.github/workflows/claude-review.yml +# so a claude-code-action bump is one PR instead of one per repo. + on: issue_comment: types: [created] @@ -12,43 +16,13 @@ on: jobs: claude: - # Defense-in-depth author gate: only run when the triggering actor is a repo - # OWNER/MEMBER/COLLABORATOR, so a drive-by comment from an outside account - # cannot invoke Claude or drain Claude usage. This repo is public, so the - # gate is load-bearing, not decorative. - if: | - (github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude') && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association)) || - (github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude') && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association)) || - (github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude') && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.review.author_association)) || - (github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')) && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.issue.author_association)) - runs-on: ubuntu-latest - timeout-minutes: 15 + # Granted here as well as in the called workflow: a called workflow's jobs + # cannot exceed the permissions of the caller's GITHUB_TOKEN. permissions: contents: read pull-requests: read issues: read + actions: read id-token: write - actions: read # Required for Claude to read CI results on PRs - steps: - - name: Checkout repository - uses: actions/checkout@v7 - with: - fetch-depth: 1 - - - name: Run Claude Code - id: claude - uses: anthropics/claude-code-action@a874e9ecd7bb36efdad65429c6b35815f5a08f10 # v1 - with: - claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} - - # This is an optional setting that allows Claude to read CI results on PRs - additional_permissions: | - actions: read - - # Optional: Give a custom prompt to Claude. If this is not specified, Claude will perform the instructions specified in the comment that tagged it. - # prompt: 'Update the pull request description to include a summary of changes.' - - # Optional: Add claude_args to customize behavior and configuration - # See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md - # or https://docs.claude.com/en/docs/claude-code/cli-reference for available options - # claude_args: '--allowed-tools Bash(gh pr:*)' + uses: RoboFinSystems/robosystems/.github/workflows/claude-review.yml@main + secrets: inherit