Skip to content

fix(work-items): make the lease protocol runnable without GraphQL, and specify the overengineering product-code lane #6796

fix(work-items): make the lease protocol runnable without GraphQL, and specify the overengineering product-code lane

fix(work-items): make the lease protocol runnable without GraphQL, and specify the overengineering product-code lane #6796

Workflow file for this run

name: claude-review
# Automated PR code review via the ci-workflows reusable workflow. The caller
# owns the triggers + GITHUB_TOKEN permission grant (a called workflow can only
# downgrade them, never elevate); the reusable workflow owns the action pin and
# the secret-handling safety model.
#
# Fork PRs receive no secrets and a read-only token, so they are simply not
# reviewed by design (no token-exfiltration surface). Requires `claude-code-plugins` to be
# in the CLAUDE_CODE_OAUTH_TOKEN org secret's selected-repositories scope.
# Public repo: runs on the reusable's hosted default runner.
on:
pull_request:
types: [opened, synchronize, ready_for_review, reopened]
permissions:
contents: read
jobs:
review:
permissions:
contents: read # checkout + read the diff
pull-requests: write # post review + track_progress tracking comment
id-token: write # OIDC — mints the Claude GitHub App token
# Repo-wide review queue: serializes reviews so parallel PRs queue for the
# shared Claude seat instead of contending for it. Job-scoped and repo-wide
# by design, and deliberately distinct from the reusable's own inner group
# (keyed per PR and head SHA) — a caller group sharing that name would
# deadlock the call against itself. `queue: max` admits no
# `cancel-in-progress`, which the two cannot be combined with anyway
# (https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#jobsjob_idconcurrency).
concurrency:
group: claude-review-${{ github.repository }}
queue: max
uses: melodic-software/ci-workflows/.github/workflows/claude-review.yml@62bef7bab01e8532fedfa739879034a210e9e67d # v0.14.0
with:
runner: ubuntu-24.04
# Pass only the one named secret (least privilege) rather than `secrets:
# inherit`, which would forward every parent secret to the called workflow.
secrets:
CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}