From 6b896eb4631a3a52cf5ded1c4a90b0a99b07a6c6 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 13 May 2026 17:20:29 -0400 Subject: [PATCH] Add cross-repo dispatch to Claude Code Review (#26) Use GitHub App token (CLAUDE_CI_APP_ID) for cross-repo access when dispatching reviews via workflow_dispatch. Remove issue_comment, pull_request_review_comment, and review_requested triggers since org-level workflows don't propagate those events to other repos. --- .github/workflows/claude-code-review.yaml | 38 +++++++++++++---------- 1 file changed, 22 insertions(+), 16 deletions(-) diff --git a/.github/workflows/claude-code-review.yaml b/.github/workflows/claude-code-review.yaml index 4c53cae..16e00f1 100644 --- a/.github/workflows/claude-code-review.yaml +++ b/.github/workflows/claude-code-review.yaml @@ -3,16 +3,14 @@ name: Claude Code Review on: workflow_dispatch: inputs: + repository: + description: "Target repository (e.g., Sea-Haven-Industries/meal-order-manager)" + required: true + type: string pr_number: description: Pull request number to review required: true type: string - issue_comment: - types: [created] - pull_request_review_comment: - types: [created] - pull_request: - types: [review_requested] workflow_call: inputs: direct_call: @@ -32,30 +30,35 @@ permissions: jobs: claude-review: if: >- - (github.event_name == 'issue_comment' && - contains(github.event.comment.body, '@claude') && - github.event.issue.pull_request) || - (github.event_name == 'pull_request_review_comment' && - contains(github.event.comment.body, '@claude')) || - (github.event_name == 'pull_request' && - github.event.requested_team.slug == 'claude') || github.event_name == 'workflow_dispatch' || inputs.direct_call == true runs-on: ubuntu-latest timeout-minutes: 10 steps: + - name: Generate GitHub App token + if: github.event_name == 'workflow_dispatch' + id: app-token + uses: actions/create-github-app-token@v1 + with: + app-id: ${{ secrets.CLAUDE_CI_APP_ID }} + private-key: ${{ secrets.CLAUDE_CI_APP_PRIVATE_KEY }} + owner: Sea-Haven-Industries + - uses: actions/checkout@v4 with: + repository: ${{ inputs.repository || github.repository }} + token: ${{ steps.app-token.outputs.token || github.token }} fetch-depth: 1 - uses: anthropics/claude-code-action@v1 with: anthropic_api_key: ${{ secrets.anthropic_api_key || secrets.ANTHROPIC_API_KEY }} + github_token: ${{ steps.app-token.outputs.token || github.token }} allowed_bots: '*' trigger_phrase: '@claude' prompt: | - REPO: ${{ github.repository }} - PR NUMBER: ${{ github.event.pull_request.number || github.event.issue.number || github.event.inputs.pr_number }} + REPO: ${{ inputs.repository || github.repository }} + PR NUMBER: ${{ inputs.pr_number || github.event.pull_request.number || github.event.issue.number }} Review this pull request. Only comment on: - Bugs or logic errors @@ -76,4 +79,7 @@ jobs: Only post GitHub comments — do not submit review text as messages. claude_args: | - --allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)" \ No newline at end of file + --allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)" + env: + GH_REPO: ${{ inputs.repository || github.repository }} + GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }}