Repository navigation
ci: add automated Claude PR review workflow - #33
Merged
Merged
Conversation
Three jobs on pull_request, split by PR author: - dependabot[bot]: upgrade risk, checked against how we actually use each dependency (SDK tool registration, vitest APIs, @types/node vs engines). - github-actions[bot] on chore/update-catalog: what the regenerated catalog added, removed, and changed, with removals called out for confirmation against the live spec — that is the case #16 and #18 both turned on. - everyone else: general review against the invariants documented in CLAUDE.md. Fork PRs are skipped in all three. They run without the OIDC credentials this needs, and on a public repo an unguarded trigger lets anyone spend budget. Auth is OIDC federation via org-wide vars, which is what makes the bot paths work at all — Dependabot-triggered runs cannot read Actions secrets. Actions are pinned by commit SHA with version comments, and each job hardens the runner first, matching the other workflows. Closes #32
dangrondahl
enabled auto-merge (squash)
August 11, 2026 12:50
FayeSGW
approved these changes
Aug 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #32. Modelled on terraform-provider-kosli's
claude-review.yaml, adapted to this repo.Three jobs, split by PR author
review-dependency-updatesdependabot[bot]review-catalog-updategithub-actions[bot]onchore/update-catalogreview-generalClassification uses
pull_request.user.loginrather thangithub.actor, so a job doesn't change identity when a human pushes to a bot's branch.The catalog job
This one has no counterpart upstream, and it is the reason a third job exists. The reference's dependency prompt is about changelogs and semver, which says nothing useful about a regenerated catalog.
Instead it summarises added, removed, and changed actions, and insists that removals be confirmed against the live spec before merge. That case has come up twice: #16 was a stale branch clobbering the catalog, #18 was a genuine upstream retirement of
list_artifact_approvals. The diff alone cannot tell those apart. It also grepssrc/,test/, andREADME.mdfor now-dangling references, and flags any$refthat survived into the catalog.General job
The prompt checks the deliberate design decisions recorded in
CLAUDE.md: three generic tools and no tool per endpoint, generated catalog, the non-throwing{ error: true, ... }contract, compactJSON.stringify, theorgfallback, theUser-Agentheader, ESM.jsimport extensions,strict: true, no HTTP client library, and thereadOnlyHint/destructiveHintsplit.Security and conventions
terraform-provider-kosli(PR 232), which is itself a public repo.harden-runnerfirst in every job, matching the other three workflows.github.repositoryand the PR number are interpolated, and only intoprompt:— never into arun:step.Before merging
claude-opus-5, not the reference'sclaude-opus-4-8. If the federation rule doesn't permit it the first run fails loudly; switch toclaude-opus-4-8, which is proven in the provider repo.actions/checkoutis pinned to v6.0.2 to match the rest of the repo. ci: bump actions/checkout from 6.0.2 to 7.0.1 #30 bumps it to v7.0.1 — after this merges, rebase ci: bump actions/checkout from 6.0.2 to 7.0.1 #30 and it will update all four workflows together.mcp-serveris in scope for theANTHROPIC_*org variables. Reading that config needsadmin:org, so I couldn't check.