Add Claude Code GitHub Workflow - #1470
Conversation
✅ Deploy Preview for testcontainers-node ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 📝 WalkthroughWalkthroughThe pull request adds two GitHub Actions workflows. One runs Claude Code Review for selected pull-request events and permits inline comments. The other invokes Claude Code for selected issue and review activity when the configured content contains Priority: ⬇️ Low Merge Risk: 🟡 Moderate · up to Fork reviews may fail, issue assignments will not invoke Claude as configured, and bot accounts without write access may trigger Claude. Resolve the trigger and access-control behavior before merging. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The new workflows can run in response to pull requests and mention-bearing comments while supplying a stored credential to an externally maintained action. Repository-token permissions are mostly read-only, but the comment workflow does not itself check who made a mention, and the action is not pinned to an immutable revision. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 4
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Advanced
Run ID: 713435c3-b7f1-44fe-ad46-ba98c25879a8
📒 Files selected for processing (2)
.github/workflows/claude-code-review.yml.github/workflows/claude.yml
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.
| pull_request: | ||
| types: [opened, synchronize, ready_for_review, reopened] |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Handle pull requests from forks.
When a fork triggers this pull_request workflow, GitHub withholds CLAUDE_CODE_OAUTH_TOKEN. The review action cannot authenticate for those pull requests. If fork reviews are required, use a design that obtains credentials without exposing them to untrusted PR code. Otherwise, exclude fork PRs so the workflow does not run without its required credential. (docs.github.com)
| pull_request_review_comment: | ||
| types: [created] | ||
| issues: | ||
| types: [opened, assigned] |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Remove or configure the issue-assignment trigger.
When someone assigns an issue whose title or body contains @claude, this job starts. The action's v1 mention check only accepts issue title or body mentions on opened events. On assigned, it requires a matching assignee_trigger, which this workflow does not set. Remove assigned if assignments should not invoke Claude, or configure an assignee trigger and align the job condition with it. (raw.githubusercontent.com)
🤖 Installing Claude Code GitHub App
This PR adds a GitHub Actions workflow that enables Claude Code integration in our repository.
What is Claude Code?
Claude Code is an AI coding agent that can help with:
How it works
Once this PR is merged, we'll be able to interact with Claude by mentioning @claude in a pull request or issue comment.
Once the workflow is triggered, Claude will analyze the comment and surrounding context, and execute on the request in a GitHub action.
Important Notes
Security
There's more information in the Claude Code action repo.
After merging this PR, let's try mentioning @claude in a comment on any PR to get started!