mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 05:53:12 +00:00
Update Claude review: tighter prompt, tool restrictions, manual dispatch (#8)
* Update Claude review: tighter prompt, tool restrictions, manual dispatch * Add draft PR guard to skip reviews on draft PRs
This commit is contained in:
parent
e8305b3666
commit
086c6e1341
1 changed files with 32 additions and 8 deletions
40
.github/workflows/claude-code-review.yaml
vendored
40
.github/workflows/claude-code-review.yaml
vendored
|
|
@ -1,8 +1,14 @@
|
|||
name: Claude Code Review
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
pr_number:
|
||||
description: Pull request number to review
|
||||
required: true
|
||||
type: string
|
||||
pull_request:
|
||||
types: [opened, synchronize]
|
||||
types: [opened, ready_for_review]
|
||||
workflow_call:
|
||||
secrets:
|
||||
anthropic_api_key:
|
||||
|
|
@ -15,21 +21,39 @@ permissions:
|
|||
|
||||
jobs:
|
||||
claude-review:
|
||||
if: github.event.pull_request.draft == false
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 10
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
fetch-depth: 1
|
||||
|
||||
- uses: anthropics/claude-code-action@v1
|
||||
with:
|
||||
anthropic_api_key: ${{ secrets.anthropic_api_key || secrets.ANTHROPIC_API_KEY }}
|
||||
allowed_bots: '*'
|
||||
prompt: |
|
||||
Review this pull request. Focus on:
|
||||
- Code correctness and potential bugs
|
||||
- Security issues (hardcoded secrets, injection, OWASP top 10)
|
||||
- Sea Haven conventions: kebab-case resource names, secrets in AWS Secrets Manager (not env vars), Lambda defaults (Python 3.12+, arm64, explicit 60-day log retention)
|
||||
- README accuracy if changed
|
||||
Post findings as inline review comments. Be concise — flag real issues, skip nitpicks.
|
||||
REPO: ${{ github.repository }}
|
||||
PR NUMBER: ${{ github.event.pull_request.number || github.event.inputs.pr_number }}
|
||||
|
||||
Review this pull request. Only comment on:
|
||||
- Bugs or logic errors
|
||||
- Security vulnerabilities (hardcoded secrets, injection, OWASP top 10)
|
||||
- Breaking changes or regressions
|
||||
- Sea Haven convention violations: kebab-case resource names, secrets in AWS Secrets Manager (not env vars or SSM), Lambda defaults (Python 3.12+/Node 22.x, arm64, explicit 60-day log retention)
|
||||
|
||||
Do NOT comment on:
|
||||
- Style, formatting, or naming preferences
|
||||
- Minor refactoring suggestions
|
||||
- Performance unless it is a measurable regression
|
||||
- Things that are already consistent with the existing codebase
|
||||
|
||||
Limit to 5 inline comments maximum. If the PR looks good, leave a single top-level comment saying so — do not force issues where there are none.
|
||||
|
||||
Use `gh pr comment` for top-level feedback.
|
||||
Use `mcp__github_inline_comment__create_inline_comment` (with `confirmed: true`) for specific code issues.
|
||||
Only post GitHub comments — do not submit review text as messages.
|
||||
|
||||
claude_args: |
|
||||
--allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)"
|
||||
Loading…
Add table
Reference in a new issue