summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--.github/workflows/claude-code-review.yml7
1 files changed, 7 insertions, 0 deletions
diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml
index 59019616f..88d435c00 100644
--- a/.github/workflows/claude-code-review.yml
+++ b/.github/workflows/claude-code-review.yml
@@ -53,8 +53,15 @@ jobs:
# TEMPORARY: expose the full Claude transcript in the Actions log for
# debugging. Revert to remove once done.
show_full_output: true
+ # /code-review needs git/gh (Bash), file search, and the sub-agents it
+ # fans out (Task). This job runs ONLY on same-repo PRs (the `if` above)
+ # with a contents:read token that cannot push — so, unlike claude.yml's
+ # fork-exposed @claude job, allowlisting these is safe. Without it the
+ # headless run stalls on per-tool approval and can't read the diff or
+ # spawn reviewers. (Bash is broad; scope it to git/gh/grep if preferred.)
claude_args: |
--max-turns 50
--model claude-opus-4-8
--effort max
+ --allowedTools Bash,Read,Grep,Glob,Task,WebFetch,WebSearch,TodoWrite
# See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md