mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 09:23:11 +00:00
workflow_call invocations inherit the caller's event_name, so github.event_name == 'workflow_call' never matches. The caller's event context passes through and is handled by the existing issue_comment/review_requested conditions.
73 lines
No EOL
2.7 KiB
YAML
73 lines
No EOL
2.7 KiB
YAML
name: Claude Code Review
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
pr_number:
|
|
description: Pull request number to review
|
|
required: true
|
|
type: string
|
|
issue_comment:
|
|
types: [created]
|
|
pull_request_review_comment:
|
|
types: [created]
|
|
pull_request:
|
|
types: [review_requested]
|
|
workflow_call:
|
|
secrets:
|
|
anthropic_api_key:
|
|
required: true
|
|
|
|
permissions:
|
|
contents: read
|
|
pull-requests: write
|
|
issues: read
|
|
id-token: write
|
|
|
|
jobs:
|
|
claude-review:
|
|
if: >-
|
|
(github.event_name == 'issue_comment' &&
|
|
contains(github.event.comment.body, '@claude') &&
|
|
github.event.issue.pull_request) ||
|
|
(github.event_name == 'pull_request_review_comment' &&
|
|
contains(github.event.comment.body, '@claude')) ||
|
|
(github.event_name == 'pull_request' &&
|
|
github.event.requested_team.slug == 'claude') ||
|
|
github.event_name == 'workflow_dispatch'
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 1
|
|
|
|
- uses: anthropics/claude-code-action@v1
|
|
with:
|
|
anthropic_api_key: ${{ secrets.anthropic_api_key || secrets.ANTHROPIC_API_KEY }}
|
|
allowed_bots: '*'
|
|
trigger_phrase: '@claude'
|
|
prompt: |
|
|
REPO: ${{ github.repository }}
|
|
PR NUMBER: ${{ github.event.pull_request.number || github.event.issue.number || github.event.inputs.pr_number }}
|
|
|
|
Review this pull request. Only comment on:
|
|
- Bugs or logic errors
|
|
- Security vulnerabilities (hardcoded secrets, injection, OWASP top 10)
|
|
- Breaking changes or regressions
|
|
- Sea Haven convention violations: kebab-case resource names, secrets in AWS Secrets Manager (not env vars or SSM), Lambda defaults (Python 3.12+/Node 22.x, arm64, explicit 60-day log retention)
|
|
|
|
Do NOT comment on:
|
|
- Style, formatting, or naming preferences
|
|
- Minor refactoring suggestions
|
|
- Performance unless it is a measurable regression
|
|
- Things that are already consistent with the existing codebase
|
|
|
|
Limit to 5 inline comments maximum. If the PR looks good, leave a single top-level comment saying so — do not force issues where there are none.
|
|
|
|
Use `gh pr comment` for top-level feedback.
|
|
Use `mcp__github_inline_comment__create_inline_comment` (with `confirmed: true`) for specific code issues.
|
|
Only post GitHub comments — do not submit review text as messages.
|
|
|
|
claude_args: |
|
|
--allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)" |