From ec47d8ee9ba8036ae3f1df574161741fa7e75e17 Mon Sep 17 00:00:00 2001 From: "Joseph T. French" Date: Wed, 2 Sep 2026 00:10:36 -0500 Subject: [PATCH] chore(ci): call the shared claude-review workflow Reduces claude.yml to its triggers and permissions grant; the author gate, runner selection and the claude-code-action and checkout pins now come from RoboFinSystems/robosystems/.github/workflows/claude-review.yml, where they are maintained once rather than in each repo. Also picks up the SHA-pinned checkout from the shared workflow - this repo was on the mutable actions/checkout@v7 tag. No behaviour change: the gate and permissions are identical, and select-runner returns ["ubuntu-latest"] without an API call while RUNNER_LABELS is github-hosted. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_0113UQ7evQKHNf1L1tFiZzLD --- .github/workflows/claude.yml | 44 ++++++++---------------------------- 1 file changed, 9 insertions(+), 35 deletions(-) diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml index 01456be..54166c7 100644 --- a/.github/workflows/claude.yml +++ b/.github/workflows/claude.yml @@ -1,5 +1,9 @@ name: Claude Code Review +# Triggers only. The implementation - author gate, runner selection, action +# pins - lives in RoboFinSystems/robosystems/.github/workflows/claude-review.yml +# so a claude-code-action bump is one PR instead of one per repo. + on: issue_comment: types: [created] @@ -12,43 +16,13 @@ on: jobs: claude: - # Defense-in-depth author gate: only run when the triggering actor is a repo - # OWNER/MEMBER/COLLABORATOR, so a drive-by comment from an outside account - # cannot invoke Claude or drain Claude usage. This repo is public, so the - # gate is load-bearing, not decorative. - if: | - (github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude') && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association)) || - (github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude') && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.comment.author_association)) || - (github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude') && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.review.author_association)) || - (github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')) && contains(fromJSON('["OWNER","MEMBER","COLLABORATOR"]'), github.event.issue.author_association)) - runs-on: ubuntu-latest - timeout-minutes: 15 + # Granted here as well as in the called workflow: a called workflow's jobs + # cannot exceed the permissions of the caller's GITHUB_TOKEN. permissions: contents: read pull-requests: read issues: read + actions: read id-token: write - actions: read # Required for Claude to read CI results on PRs - steps: - - name: Checkout repository - uses: actions/checkout@v7 - with: - fetch-depth: 1 - - - name: Run Claude Code - id: claude - uses: anthropics/claude-code-action@a874e9ecd7bb36efdad65429c6b35815f5a08f10 # v1 - with: - claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} - - # This is an optional setting that allows Claude to read CI results on PRs - additional_permissions: | - actions: read - - # Optional: Give a custom prompt to Claude. If this is not specified, Claude will perform the instructions specified in the comment that tagged it. - # prompt: 'Update the pull request description to include a summary of changes.' - - # Optional: Add claude_args to customize behavior and configuration - # See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md - # or https://docs.claude.com/en/docs/claude-code/cli-reference for available options - # claude_args: '--allowed-tools Bash(gh pr:*)' + uses: RoboFinSystems/robosystems/.github/workflows/claude-review.yml@main + secrets: inherit