gh api returns error JSON on 404, which made the variable non-empty. Check exit code instead of output content. |
||
|---|---|---|
| .github/workflows | ||
| scripts | ||
| .gitignore | ||
| README.md | ||
.github
Organization-level GitHub configuration for Sea Haven Industries.
What's in here
Reusable Workflows
.github/workflows/claude-code-review.yaml — Reusable PR review workflow powered by Claude Code. Individual repos call this via a thin wrapper workflow. Reviews for code correctness, security issues, and Sea Haven conventions (kebab-case, secrets placement, Lambda defaults).
.github/workflows/compliance-audit.yaml — Scheduled weekly audit (Mondays 10am ET) that checks all org repos for compliance with Sea Haven conventions. Creates GitHub issues on repos with violations. Can also be triggered manually via workflow_dispatch.
Scripts
scripts/rollout-review-workflow.sh — One-time script to push the thin PR review wrapper workflow to all org repos via the GitHub API. Creates a branch and PR on each repo.
Setup
1. Create a GitHub App
- Go to Organization Settings > Developer settings > GitHub Apps > New GitHub App
- Name it
claude-code-ci(or similar) - Set Homepage URL to your org URL
- Disable Webhook (uncheck "Active")
- Set these Repository permissions:
- Contents: Read and write
- Issues: Read and write
- Metadata: Read-only
- Pull requests: Read and write
- Set Where can this app be installed? to "Only on this account"
- Click Create GitHub App
- Note the App ID from the app's settings page
- Under Private keys, click Generate a private key — save the
.pemfile
2. Install the App
- From the app's settings page, click Install App
- Select
Sea-Haven-Industries - Choose All repositories
3. Add org-level secrets
Go to Organization Settings > Secrets and variables > Actions and add:
| Secret | Value |
|---|---|
ANTHROPIC_API_KEY |
Your Claude API key |
CLAUDE_CI_APP_ID |
The App ID from step 1 |
CLAUDE_CI_APP_PRIVATE_KEY |
The full contents of the .pem file from step 1 |
4. Roll out PR reviews to repos
./scripts/rollout-review-workflow.sh
This creates a PR on each repo adding the thin wrapper workflow. Review and merge them, then delete the add-claude-review branches.