Repository navigation
Add Claude Code GitHub Workflow - #3
Conversation
Code Review - PR #3: Add Claude Code GitHub WorkflowThank you for setting up Claude Code integration! I've reviewed both workflow files and have some feedback organized by priority. 🔴 Critical Issues1. Missing Write Permissions for CommentsFile: Both Both workflows need write permissions to post comments/reviews. Currently they only have read permissions. Fix needed in permissions:
contents: write # Changed from read
pull-requests: write # Changed from read
issues: write # Changed from read
id-token: write
actions: readFix needed in permissions:
contents: read
pull-requests: write # Changed from read - needed to post review comments
issues: read
id-token: write2. Infinite Loop Risk - Code Review WorkflowFile: The automatic code review workflow will run on every PR, including:
This could create infinite loops or unnecessary reviews. Recommended fixes (choose one or combine): Option A - Exclude workflow changes: on:
pull_request:
types: [opened, synchronize]
paths-ignore:
- '.github/workflows/**'Option B - Exclude bot PRs: jobs:
claude-review:
if: github.actor != 'github-actions[bot]' && !contains(github.event.pull_request.title, '[Claude]')
runs-on: ubuntu-latestOption C - Opt-in with labels: on:
pull_request:
types: [opened, synchronize, labeled]
jobs:
claude-review:
if: contains(github.event.pull_request.labels.*.name, 'needs-review')
runs-on: ubuntu-latest🟡 Important Issues3. Missing CLAUDE.md FileFile: The review prompt references a Recommended action: 🟢 Suggestions for Improvement4. Limited Git HistoryFiles: Both workflows (line 32)
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 0 # Full history for better context
ref: ${{ github.event.pull_request.head.sha }}5. Add Workflow Run IndicatorsConsider adding a comment when the review starts to give users feedback that the review is in progress. ✅ What Looks Good
Security AssessmentOverall: Good ✅
Test CoverageN/A - These are workflow files. Consider testing after merge:
Recommendations SummaryBefore merging:
After merging (optional):
Great work setting this up! The workflows are well-structured and just need a few permission and safety adjustments before they're ready to go. 🚀 |
* evidence(OMN-14086): OCC companion for omnibase_infra PR #2263 (retrofit item #5) OMN-14086 bundles 5 independent zero-risk validator diff-scope/wiring retrofits; item #3 (omniclaude#1867) already has OCC#3679 evidence. This is item #5 (run_duplication_sweep wiring). Append-only addition of a new dod_evidence entry -- existing 4 entries/receipts untouched. Independent adversarial verification (verifier=sc-reconcile, runner= verify-14374) of omnibase_infra#2263: 12/12 focused tests green, an independent fires-on-violation proof in a CI-shaped sparse-checkout layout (real duplicate pgTable across 2 files -> FAIL/exit 1; fixed -> PASS/exit 0), plus a RED->GREEN mutation proof on the new --changed-files narrowing logic. ruff/actionlint clean. * evidence(OMN-14086): self-bind OCC evidence commit for infra PR #2263 Add-only self-binding receipt for occ-preflight eligibility, ahead of the OCC PR number existing. Distinct evidence_item_id from the existing dod-occ-pr-3679 entry.
…#6083) * evidence(OMN-15692): OCC companion for OmniNode-ai/omnibase_core#1547 OCC evidence companion for the round-#3 remediation of the MSK gateway-only enforcement rule (ruling 39, operator 2026-08-04) — omnibase_core PR #1547 fixes 7 adversarial-verification defects against the msk-direct-broker-endpoint url-authority rule: baseline self-defeat (the branch had pre-seeded the 3 only known live violations, self-defeating the guard), an anti-gaming check scoped to repo=="omnibase_core" only (blind to omnibase_infra's own baseline growth), a .env file-selection hole (Path.suffix is empty for a bare .env file), a bare-substring test-path exemption that waived deploy/latest.yaml / docker/stability-test/** / attestation.yaml, and missing .json/.tf/ Dockerfile/.env.<profile> scan-surface coverage. * evidence(OMN-15692): add self-bind entry for OCC companion PR #6083 Cites OMN-15692. * evidence(OMN-15692): PASS receipts for OCC companion PR #6083, independently verified Cites OMN-15692. runner=claude-code-subagent-omn-15692-remediation ran all 5 probes at 2026-08-05T00:42:38Z; verifier=fable-delta-0804-orchestrator (session foreground orchestrator, distinct identity) independently re-executed the same 5 probes at ~2026-08-04T23:05Z and confirmed matching results. run_timestamp records the verifier's confirming run per the adversarial-receipts convention (verifier != runner required for PASS).
… dead #2940 bindings (#7440) * evidence(OMN-16773): rebind contract onto omnibase_infra#2955, retire dead #2940 bindings OMN-16773's contract was autobound to omnibase_infra PR #2940, which closed unmerged. The three entries pinned to #2940 (dod-OmniNode-ai-omnibase_infra-pr-2940, dod-deploy-assessment, occ-self-bind-pr-7328) can never satisfy their ::pr-live-state MERGED assertion because #2940 was never merged. The actual delivered work landed via omnibase_infra#2955 (merged 8e1be3c32), already partially bound (dod-OmniNode-ai-omnibase_infra-pr-2955, dod-OmniNode-ai-omnibase_infra-pr-2955-ci, occ-self-bind-pr-7372). - Removed dod-OmniNode-ai-omnibase_infra-pr-2940 (superseded by the -pr-2955 entry) - Removed occ-self-bind-pr-7328 (superseded by occ-self-bind-pr-7372, already merged) - Repointed dod-deploy-assessment onto #2955 (ref 73b53a71773..., F-05 deploy-scope check re-run live, PASS) instead of dropping it, since no other entry covers F-05 - Updated contract summary + evidence_requirements to name #2955 - Rebound contract_sha256 on all surviving receipts to the new whole-file hash; recomputed contract_entry_sha256 for dod-deploy-assessment (only entry whose content changed) Per 2026-08-28 sprint-board adjudication (docs/tracking/2026-08-28-sprint-board-adjudication.md, recommended follow-up #3): "an OCC contract bound to a PR that closed unmerged is permanently unverifiable and should be detected at bind time." OMN-16773 * evidence(OMN-16773): self-bind OCC#7440 + rebind contract_sha256 OMN-16773 * evidence(OMN-16773): append-only-compliant rebind via supersession entries The prior two commits on this branch edited/deleted already-merged contract entries and receipt files (dod-OmniNode-ai-omnibase_infra-pr-2940, dod-deploy-assessment, occ-self-bind-pr-7328), which the OCC Append-Only Gate correctly rejected -- merged dod_evidence items and receipts are immutable. This commit restores the original three entries and their receipts byte-for-byte, then supersedes them the sanctioned way: two net-new append-only entries with evidence_artifact: supersedes_dod_evidence:<id>, per the OMN-15382 runner-supersession precedent (contracts/OMN-14968.yaml): - dod-pr-2940-rebind-16773: asserts PR #2940's real CLOSED state in the same clause as the PR reference (OMN-16087 override), so the historical entry's ::pr-live-state auto-check stops defaulting to a permanent MERGED requirement it can never satisfy. - dod-deploy-assessment-rebind-16773: re-proves the F-05 deploy-scope requirement against #2955 (merged 8e1be3c32), since the historical entry's receipt records pr_number: 2940 and can't be edited. occ-self-bind-pr-7328 needed no correction -- its own id-pinned PR (7328, the OCC companion PR) actually did merge; only the entries id-pinned or receipt-bound to product PR #2940 were unverifiable. OMN-16773
🤖 Installing Claude Code GitHub App
This PR adds a GitHub Actions workflow that enables Claude Code integration in our repository.
What is Claude Code?
Claude Code is an AI coding agent that can help with:
How it works
Once this PR is merged, we'll be able to interact with Claude by mentioning @claude in a pull request or issue comment.
Once the workflow is triggered, Claude will analyze the comment and surrounding context, and execute on the request in a GitHub action.
Important Notes
Security
There's more information in the Claude Code action repo.
After merging this PR, let's try mentioning @claude in a comment on any PR to get started!