.github/.github/workflows/claude-code-review.yaml
Adam Moussa 6ab1889bb8 Fix claude-code-action input names
direct_prompt and review_comments are not valid inputs for
claude-code-action@v1. Use prompt instead.
2026-05-06 19:40:31 -04:00

31 lines
960 B
YAML

name: Claude Code Review
on:
workflow_call:
secrets:
anthropic_api_key:
required: true
permissions:
contents: read
pull-requests: write
jobs:
claude-review:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: anthropics/claude-code-action@v1
with:
anthropic_api_key: ${{ secrets.anthropic_api_key }}
prompt: |
Review this pull request. Focus on:
- Code correctness and potential bugs
- Security issues (hardcoded secrets, injection, OWASP top 10)
- Sea Haven conventions: kebab-case resource names, secrets in AWS Secrets Manager (not env vars), Lambda defaults (Python 3.12+, arm64, explicit 60-day log retention)
- README accuracy if changed
Post findings as inline review comments. Be concise — flag real issues, skip nitpicks.