summaryrefslogtreecommitdiff
path: root/.github/workflows/claude-code-review.yml
diff options
context:
space:
mode:
Diffstat (limited to '.github/workflows/claude-code-review.yml')
-rw-r--r--.github/workflows/claude-code-review.yml17
1 files changed, 11 insertions, 6 deletions
diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml
index 2f055287c..6c8bbb03d 100644
--- a/.github/workflows/claude-code-review.yml
+++ b/.github/workflows/claude-code-review.yml
@@ -5,16 +5,18 @@ on:
# opened/reopened/ready_for_review -> first auto review
# synchronize -> auto re-review on new pushes
#
- # NOTE: pull_request (not _target) means fork PRs from non-write-access
- # contributors get NO token, so they are not auto-reviewed -> use @claude
- # on those. Same-repo branches (yours or write-access contributors) get
- # full auto-review safely.
+ # NOTE: pull_request (not _target) means fork PRs get a read-only GITHUB_TOKEN
+ # and NO repository secrets (CLAUDE_CODE_OAUTH_TOKEN), so they cannot be
+ # auto-reviewed. The job condition below skips them cleanly -> use @claude on
+ # those. Same-repo branches (yours or write-access contributors) auto-review.
types: [opened, synchronize, reopened, ready_for_review]
jobs:
claude-review:
- # Skip drafts; review real PRs only
- if: github.event.pull_request.draft == false
+ # Skip drafts, and skip fork PRs (no secrets -> would only fail noisily)
+ if: >
+ github.event.pull_request.draft == false &&
+ github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
permissions:
contents: read
@@ -34,6 +36,9 @@ jobs:
uses: anthropics/claude-code-action@v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
+ # Pairs with the actions: read permission so Claude can read CI results
+ additional_permissions: |
+ actions: read
plugin_marketplaces: 'https://github.com/anthropics/claude-code.git'
plugins: 'code-review@claude-code-plugins'
prompt: '/code-review:code-review ${{ github.repository }}/pull/${{ github.event.pull_request.number }}'