Skip to content

Add Claude Code GitHub Workflow - #3

Merged
jonahgabriel merged 2 commits into
mainfrom
add-claude-github-actions-1766199618476
Dec 20, 2025
Merged

jonahgabriel merged 2 commits into
mainfrom
add-claude-github-actions-1766199618476

Conversation

@jonahgabriel

Copy link
Copy Markdown
Contributor

🤖 Installing Claude Code GitHub App

This PR adds a GitHub Actions workflow that enables Claude Code integration in our repository.

What is Claude Code?

Claude Code is an AI coding agent that can help with:

  • Bug fixes and improvements
  • Documentation updates
  • Implementing new features
  • Code reviews and suggestions
  • Writing tests
  • And more!

How it works

Once this PR is merged, we'll be able to interact with Claude by mentioning @claude in a pull request or issue comment.
Once the workflow is triggered, Claude will analyze the comment and surrounding context, and execute on the request in a GitHub action.

Important Notes

  • This workflow won't take effect until this PR is merged
  • @claude mentions won't work until after the merge is complete
  • The workflow runs automatically whenever Claude is mentioned in PR or issue comments
  • Claude gets access to the entire PR or issue context including files, diffs, and previous comments

Security

  • Our Anthropic API key is securely stored as a GitHub Actions secret
  • Only users with write access to the repository can trigger the workflow
  • All Claude runs are stored in the GitHub Actions run history
  • Claude's default tools are limited to reading/writing files and interacting with our repo by creating comments, branches, and commits.
  • We can add more allowed tools by adding them to the workflow file like:
allowed_tools: Bash(npm install),Bash(npm run build),Bash(npm run lint),Bash(npm run test)

There's more information in the Claude Code action repo.

After merging this PR, let's try mentioning @claude in a comment on any PR to get started!

@jonahgabriel
jonahgabriel merged commit 5efe647 into main Dec 20, 2025
2 checks passed
@jonahgabriel
jonahgabriel deleted the add-claude-github-actions-1766199618476 branch December 20, 2025 03:00
@claude

claude Bot commented Dec 20, 2025

Copy link
Copy Markdown

Code Review - PR #3: Add Claude Code GitHub Workflow

Thank you for setting up Claude Code integration! I've reviewed both workflow files and have some feedback organized by priority.

🔴 Critical Issues

1. Missing Write Permissions for Comments

File: Both claude.yml and claude-code-review.yml

Both workflows need write permissions to post comments/reviews. Currently they only have read permissions.

Fix needed in claude.yml (line 22-26):

permissions:
  contents: write      # Changed from read
  pull-requests: write # Changed from read
  issues: write        # Changed from read
  id-token: write
  actions: read

Fix needed in claude-code-review.yml (line 22-26):

permissions:
  contents: read
  pull-requests: write # Changed from read - needed to post review comments
  issues: read
  id-token: write

2. Infinite Loop Risk - Code Review Workflow

File: .github/workflows/claude-code-review.yml

The automatic code review workflow will run on every PR, including:

  • This setup PR itself
  • PRs created by Claude
  • PRs that update the workflow files

This could create infinite loops or unnecessary reviews.

Recommended fixes (choose one or combine):

Option A - Exclude workflow changes:

on:
  pull_request:
    types: [opened, synchronize]
    paths-ignore:
      - '.github/workflows/**'

Option B - Exclude bot PRs:

jobs:
  claude-review:
    if: github.actor != 'github-actions[bot]' && !contains(github.event.pull_request.title, '[Claude]')
    runs-on: ubuntu-latest

Option C - Opt-in with labels:

on:
  pull_request:
    types: [opened, synchronize, labeled]

jobs:
  claude-review:
    if: contains(github.event.pull_request.labels.*.name, 'needs-review')
    runs-on: ubuntu-latest

🟡 Important Issues

3. Missing CLAUDE.md File

File: .github/workflows/claude-code-review.yml (line 50)

The review prompt references a CLAUDE.md file that doesn't exist in the repository. Claude will handle this gracefully but won't have style guidance.

Recommended action:
Either create a CLAUDE.md with your coding conventions or update the prompt to reference existing docs (README.md has naming conventions).

🟢 Suggestions for Improvement

4. Limited Git History

Files: Both workflows (line 32)

fetch-depth: 1 limits Claude to seeing only the latest commit. For better context in reviews, consider:

- name: Checkout repository
  uses: actions/checkout@v4
  with:
    fetch-depth: 0  # Full history for better context
    ref: ${{ github.event.pull_request.head.sha }}

5. Add Workflow Run Indicators

Consider adding a comment when the review starts to give users feedback that the review is in progress.

✅ What Looks Good

  • ✅ Proper use of GitHub Actions secrets for API token
  • ✅ Appropriate permissions scoping (just needs write access added)
  • ✅ Clear and comprehensive PR description
  • ✅ Good use of the official Claude Code action
  • ✅ Appropriate trigger conditions for interactive workflow
  • ✅ Comments explaining optional configurations

Security Assessment

Overall: Good ✅

  • Secrets are properly stored and referenced
  • Permissions follow least-privilege (just need write for comments)
  • No exposure of sensitive data
  • allowed_tools appropriately restricts Claude to GitHub CLI read operations in code review workflow
  • No dangerous commands allowed

Test Coverage

N/A - These are workflow files. Consider testing after merge:

  1. Create a test PR and verify auto-review triggers
  2. Comment with @claude on an issue
  3. Verify no infinite loops occur

Recommendations Summary

Before merging:

  1. ✅ Add write permissions for pull-requests and issues
  2. ✅ Add protection against infinite loops (workflow path exclusion recommended)
  3. ✅ Update CLAUDE.md reference or create the file

After merging (optional):

  • Consider increasing fetch-depth for better context
  • Add workflow status indicators
  • Create CLAUDE.md with project-specific conventions

Great work setting this up! The workflows are well-structured and just need a few permission and safety adjustments before they're ready to go. 🚀

jonahgabriel added a commit that referenced this pull request Jul 12, 2026
* evidence(OMN-14086): OCC companion for omnibase_infra PR #2263 (retrofit item #5)

OMN-14086 bundles 5 independent zero-risk validator diff-scope/wiring
retrofits; item #3 (omniclaude#1867) already has OCC#3679 evidence.
This is item #5 (run_duplication_sweep wiring). Append-only addition
of a new dod_evidence entry -- existing 4 entries/receipts untouched.

Independent adversarial verification (verifier=sc-reconcile, runner=
verify-14374) of omnibase_infra#2263: 12/12 focused tests green, an
independent fires-on-violation proof in a CI-shaped sparse-checkout
layout (real duplicate pgTable across 2 files -> FAIL/exit 1; fixed
-> PASS/exit 0), plus a RED->GREEN mutation proof on the new
--changed-files narrowing logic. ruff/actionlint clean.

* evidence(OMN-14086): self-bind OCC evidence commit for infra PR #2263

Add-only self-binding receipt for occ-preflight eligibility, ahead of
the OCC PR number existing. Distinct evidence_item_id from the
existing dod-occ-pr-3679 entry.
jonahgabriel added a commit that referenced this pull request Aug 5, 2026
…#6083)

* evidence(OMN-15692): OCC companion for OmniNode-ai/omnibase_core#1547

OCC evidence companion for the round-#3 remediation of the MSK
gateway-only enforcement rule (ruling 39, operator 2026-08-04) —
omnibase_core PR #1547 fixes 7 adversarial-verification defects against
the msk-direct-broker-endpoint url-authority rule: baseline self-defeat
(the branch had pre-seeded the 3 only known live violations, self-defeating
the guard), an anti-gaming check scoped to repo=="omnibase_core" only
(blind to omnibase_infra's own baseline growth), a .env file-selection
hole (Path.suffix is empty for a bare .env file), a bare-substring
test-path exemption that waived deploy/latest.yaml /
docker/stability-test/** / attestation.yaml, and missing .json/.tf/
Dockerfile/.env.<profile> scan-surface coverage.

* evidence(OMN-15692): add self-bind entry for OCC companion PR #6083

Cites OMN-15692.

* evidence(OMN-15692): PASS receipts for OCC companion PR #6083, independently verified

Cites OMN-15692. runner=claude-code-subagent-omn-15692-remediation ran all
5 probes at 2026-08-05T00:42:38Z; verifier=fable-delta-0804-orchestrator
(session foreground orchestrator, distinct identity) independently
re-executed the same 5 probes at ~2026-08-04T23:05Z and confirmed matching
results. run_timestamp records the verifier's confirming run per the
adversarial-receipts convention (verifier != runner required for PASS).
jonahgabriel added a commit that referenced this pull request Aug 28, 2026
… dead #2940 bindings (#7440)

* evidence(OMN-16773): rebind contract onto omnibase_infra#2955, retire dead #2940 bindings

OMN-16773's contract was autobound to omnibase_infra PR #2940, which closed
unmerged. The three entries pinned to #2940 (dod-OmniNode-ai-omnibase_infra-pr-2940,
dod-deploy-assessment, occ-self-bind-pr-7328) can never satisfy their
::pr-live-state MERGED assertion because #2940 was never merged.

The actual delivered work landed via omnibase_infra#2955 (merged 8e1be3c32),
already partially bound (dod-OmniNode-ai-omnibase_infra-pr-2955,
dod-OmniNode-ai-omnibase_infra-pr-2955-ci, occ-self-bind-pr-7372).

- Removed dod-OmniNode-ai-omnibase_infra-pr-2940 (superseded by the -pr-2955 entry)
- Removed occ-self-bind-pr-7328 (superseded by occ-self-bind-pr-7372, already merged)
- Repointed dod-deploy-assessment onto #2955 (ref 73b53a71773..., F-05 deploy-scope
  check re-run live, PASS) instead of dropping it, since no other entry covers F-05
- Updated contract summary + evidence_requirements to name #2955
- Rebound contract_sha256 on all surviving receipts to the new whole-file hash;
  recomputed contract_entry_sha256 for dod-deploy-assessment (only entry whose
  content changed)

Per 2026-08-28 sprint-board adjudication (docs/tracking/2026-08-28-sprint-board-adjudication.md,
recommended follow-up #3): "an OCC contract bound to a PR that closed unmerged is
permanently unverifiable and should be detected at bind time."

OMN-16773

* evidence(OMN-16773): self-bind OCC#7440 + rebind contract_sha256

OMN-16773

* evidence(OMN-16773): append-only-compliant rebind via supersession entries

The prior two commits on this branch edited/deleted already-merged contract
entries and receipt files (dod-OmniNode-ai-omnibase_infra-pr-2940,
dod-deploy-assessment, occ-self-bind-pr-7328), which the OCC Append-Only
Gate correctly rejected -- merged dod_evidence items and receipts are
immutable.

This commit restores the original three entries and their receipts
byte-for-byte, then supersedes them the sanctioned way: two net-new
append-only entries with evidence_artifact: supersedes_dod_evidence:<id>,
per the OMN-15382 runner-supersession precedent (contracts/OMN-14968.yaml):

- dod-pr-2940-rebind-16773: asserts PR #2940's real CLOSED state in the
  same clause as the PR reference (OMN-16087 override), so the historical
  entry's ::pr-live-state auto-check stops defaulting to a permanent
  MERGED requirement it can never satisfy.
- dod-deploy-assessment-rebind-16773: re-proves the F-05 deploy-scope
  requirement against #2955 (merged 8e1be3c32), since the historical
  entry's receipt records pr_number: 2940 and can't be edited.

occ-self-bind-pr-7328 needed no correction -- its own id-pinned PR (7328,
the OCC companion PR) actually did merge; only the entries id-pinned or
receipt-bound to product PR #2940 were unverifiable.

OMN-16773
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant