fix(work-items): make the lease protocol runnable without GraphQL, and specify the overengineering product-code lane #6796
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: claude-review | |
| # Automated PR code review via the ci-workflows reusable workflow. The caller | |
| # owns the triggers + GITHUB_TOKEN permission grant (a called workflow can only | |
| # downgrade them, never elevate); the reusable workflow owns the action pin and | |
| # the secret-handling safety model. | |
| # | |
| # Fork PRs receive no secrets and a read-only token, so they are simply not | |
| # reviewed by design (no token-exfiltration surface). Requires `claude-code-plugins` to be | |
| # in the CLAUDE_CODE_OAUTH_TOKEN org secret's selected-repositories scope. | |
| # Public repo: runs on the reusable's hosted default runner. | |
| on: | |
| pull_request: | |
| types: [opened, synchronize, ready_for_review, reopened] | |
| permissions: | |
| contents: read | |
| jobs: | |
| review: | |
| permissions: | |
| contents: read # checkout + read the diff | |
| pull-requests: write # post review + track_progress tracking comment | |
| id-token: write # OIDC — mints the Claude GitHub App token | |
| # Repo-wide review queue: serializes reviews so parallel PRs queue for the | |
| # shared Claude seat instead of contending for it. Job-scoped and repo-wide | |
| # by design, and deliberately distinct from the reusable's own inner group | |
| # (keyed per PR and head SHA) — a caller group sharing that name would | |
| # deadlock the call against itself. `queue: max` admits no | |
| # `cancel-in-progress`, which the two cannot be combined with anyway | |
| # (https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#jobsjob_idconcurrency). | |
| concurrency: | |
| group: claude-review-${{ github.repository }} | |
| queue: max | |
| uses: melodic-software/ci-workflows/.github/workflows/claude-review.yml@62bef7bab01e8532fedfa739879034a210e9e67d # v0.14.0 | |
| with: | |
| runner: ubuntu-24.04 | |
| # Pass only the one named secret (least privilege) rather than `secrets: | |
| # inherit`, which would forward every parent secret to the called workflow. | |
| secrets: | |
| CLAUDE_CODE_OAUTH_TOKEN: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} |