Skip to content

ci: add automated Claude PR review workflow - #33

Merged
dangrondahl merged 1 commit into
mainfrom
ci/claude-pr-review
Aug 11, 2026
Merged

dangrondahl merged 1 commit into
mainfrom
ci/claude-pr-review

Conversation

@dangrondahl

Copy link
Copy Markdown
Contributor

Closes #32. Modelled on terraform-provider-kosli's claude-review.yaml, adapted to this repo.

Three jobs, split by PR author

Job Fires on Budget
review-dependency-updates dependabot[bot] $3
review-catalog-update github-actions[bot] on chore/update-catalog $3
review-general everyone else $5

Classification uses pull_request.user.login rather than github.actor, so a job doesn't change identity when a human pushes to a bot's branch.

The catalog job

This one has no counterpart upstream, and it is the reason a third job exists. The reference's dependency prompt is about changelogs and semver, which says nothing useful about a regenerated catalog.

Instead it summarises added, removed, and changed actions, and insists that removals be confirmed against the live spec before merge. That case has come up twice: #16 was a stale branch clobbering the catalog, #18 was a genuine upstream retirement of list_artifact_approvals. The diff alone cannot tell those apart. It also greps src/, test/, and README.md for now-dangling references, and flags any $ref that survived into the catalog.

General job

The prompt checks the deliberate design decisions recorded in CLAUDE.md: three generic tools and no tool per endpoint, generated catalog, the non-throwing { error: true, ... } contract, compact JSON.stringify, the org fallback, the User-Agent header, ESM .js import extensions, strict: true, no HTTP client library, and the readOnlyHint / destructiveHint split.

Security and conventions

  • Fork PRs are skipped in all three jobs. They run without the OIDC credentials this needs, and on a public repo an unguarded trigger would let anyone spend budget.
  • OIDC federation via org-wide vars, no API key secret. This is also what makes the bot paths work: Dependabot-triggered runs cannot read Actions secrets. Confirmed working on a Dependabot PR in terraform-provider-kosli (PR 232), which is itself a public repo.
  • SHA-pinned actions with version comments, and harden-runner first in every job, matching the other three workflows.
  • Only github.repository and the PR number are interpolated, and only into prompt: — never into a run: step.

Before merging

  • Model is claude-opus-5, not the reference's claude-opus-4-8. If the federation rule doesn't permit it the first run fails loudly; switch to claude-opus-4-8, which is proven in the provider repo.
  • actions/checkout is pinned to v6.0.2 to match the rest of the repo. ci: bump actions/checkout from 6.0.2 to 7.0.1 #30 bumps it to v7.0.1 — after this merges, rebase ci: bump actions/checkout from 6.0.2 to 7.0.1 #30 and it will update all four workflows together.
  • Worth confirming mcp-server is in scope for the ANTHROPIC_* org variables. Reading that config needs admin:org, so I couldn't check.

Three jobs on pull_request, split by PR author:

- dependabot[bot]: upgrade risk, checked against how we actually use each
  dependency (SDK tool registration, vitest APIs, @types/node vs engines).
- github-actions[bot] on chore/update-catalog: what the regenerated catalog
  added, removed, and changed, with removals called out for confirmation
  against the live spec — that is the case #16 and #18 both turned on.
- everyone else: general review against the invariants documented in
  CLAUDE.md.

Fork PRs are skipped in all three. They run without the OIDC credentials this
needs, and on a public repo an unguarded trigger lets anyone spend budget.

Auth is OIDC federation via org-wide vars, which is what makes the bot paths
work at all — Dependabot-triggered runs cannot read Actions secrets.

Actions are pinned by commit SHA with version comments, and each job hardens
the runner first, matching the other workflows.

Closes #32
@dangrondahl
dangrondahl enabled auto-merge (squash) August 11, 2026 12:50
@dangrondahl
dangrondahl merged commit a64eb71 into main Aug 11, 2026
4 checks passed
@dangrondahl
dangrondahl deleted the ci/claude-pr-review branch August 11, 2026 13:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add automated Claude PR review workflow

2 participants