From 58447f6d8633ed3270eb75685eb0b06ffe1b184b Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 13 May 2026 17:40:17 -0400 Subject: [PATCH] Remove custom Claude Code Review workflow (#27) Replaced by the official Claude Code GitHub App, which handles @claude mentions, review requests, and PR triggers natively. --- .github/workflows/claude-code-review.yaml | 85 ----------------------- 1 file changed, 85 deletions(-) delete mode 100644 .github/workflows/claude-code-review.yaml diff --git a/.github/workflows/claude-code-review.yaml b/.github/workflows/claude-code-review.yaml deleted file mode 100644 index 16e00f1..0000000 --- a/.github/workflows/claude-code-review.yaml +++ /dev/null @@ -1,85 +0,0 @@ -name: Claude Code Review - -on: - workflow_dispatch: - inputs: - repository: - description: "Target repository (e.g., Sea-Haven-Industries/meal-order-manager)" - required: true - type: string - pr_number: - description: Pull request number to review - required: true - type: string - workflow_call: - inputs: - direct_call: - description: Bypass event filtering (set automatically for reusable workflow callers) - type: boolean - default: true - secrets: - anthropic_api_key: - required: true - -permissions: - contents: read - pull-requests: write - issues: read - id-token: write - -jobs: - claude-review: - if: >- - github.event_name == 'workflow_dispatch' || - inputs.direct_call == true - runs-on: ubuntu-latest - timeout-minutes: 10 - steps: - - name: Generate GitHub App token - if: github.event_name == 'workflow_dispatch' - id: app-token - uses: actions/create-github-app-token@v1 - with: - app-id: ${{ secrets.CLAUDE_CI_APP_ID }} - private-key: ${{ secrets.CLAUDE_CI_APP_PRIVATE_KEY }} - owner: Sea-Haven-Industries - - - uses: actions/checkout@v4 - with: - repository: ${{ inputs.repository || github.repository }} - token: ${{ steps.app-token.outputs.token || github.token }} - fetch-depth: 1 - - - uses: anthropics/claude-code-action@v1 - with: - anthropic_api_key: ${{ secrets.anthropic_api_key || secrets.ANTHROPIC_API_KEY }} - github_token: ${{ steps.app-token.outputs.token || github.token }} - allowed_bots: '*' - trigger_phrase: '@claude' - prompt: | - REPO: ${{ inputs.repository || github.repository }} - PR NUMBER: ${{ inputs.pr_number || github.event.pull_request.number || github.event.issue.number }} - - Review this pull request. Only comment on: - - Bugs or logic errors - - Security vulnerabilities (hardcoded secrets, injection, OWASP top 10) - - Breaking changes or regressions - - Sea Haven convention violations: kebab-case resource names, secrets in AWS Secrets Manager (not env vars or SSM), Lambda defaults (Python 3.12+/Node 22.x, arm64, explicit 60-day log retention) - - Do NOT comment on: - - Style, formatting, or naming preferences - - Minor refactoring suggestions - - Performance unless it is a measurable regression - - Things that are already consistent with the existing codebase - - Limit to 5 inline comments maximum. If the PR looks good, leave a single top-level comment saying so — do not force issues where there are none. - - Use `gh pr comment` for top-level feedback. - Use `mcp__github_inline_comment__create_inline_comment` (with `confirmed: true`) for specific code issues. - Only post GitHub comments — do not submit review text as messages. - - claude_args: | - --allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)" - env: - GH_REPO: ${{ inputs.repository || github.repository }} - GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }}