Skip to content

Commit 981e6bf

Browse files
committed
"Update Claude PR Assistant workflow"
1 parent 84c0b36 commit 981e6bf

1 file changed

Lines changed: 16 additions & 80 deletions

File tree

.github/workflows/claude.yml

Lines changed: 16 additions & 80 deletions
Original file line numberDiff line numberDiff line change
@@ -17,98 +17,34 @@ jobs:
1717
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
1818
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
1919
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
20-
2120
runs-on: ubuntu-latest
2221
permissions:
2322
contents: read
2423
pull-requests: read
2524
issues: read
2625
id-token: write
26+
actions: read # Required for Claude to read CI results on PRs
2727
steps:
28-
- name: Check user permissions
29-
id: check_membership
30-
uses: actions/github-script@v7
31-
with:
32-
script: |
33-
let actor;
34-
if (context.eventName === 'issue_comment') {
35-
actor = context.payload.comment.user.login;
36-
} else if (context.eventName === 'pull_request_review_comment') {
37-
actor = context.payload.comment.user.login;
38-
} else if (context.eventName === 'pull_request_review') {
39-
actor = context.payload.review.user.login;
40-
} else if (context.eventName === 'issues') {
41-
actor = context.payload.issue.user.login;
42-
}
43-
44-
console.log(`Checking permissions for user: ${actor}`);
45-
46-
// List of explicitly allowed users (organization members)
47-
const allowedUsers = [
48-
'phernandez',
49-
'groksrc',
50-
'nellins',
51-
'bm-claudeai'
52-
];
53-
54-
if (allowedUsers.includes(actor)) {
55-
console.log(`User ${actor} is in the allowed list`);
56-
core.setOutput('is_member', true);
57-
return;
58-
}
59-
60-
// Fallback: Check if user has repository permissions
61-
try {
62-
const collaboration = await github.rest.repos.getCollaboratorPermissionLevel({
63-
owner: context.repo.owner,
64-
repo: context.repo.repo,
65-
username: actor
66-
});
67-
68-
const permission = collaboration.data.permission;
69-
console.log(`User ${actor} has permission level: ${permission}`);
70-
71-
// Allow if user has push access or higher (write, maintain, admin)
72-
const allowed = ['write', 'maintain', 'admin'].includes(permission);
73-
74-
core.setOutput('is_member', allowed);
75-
76-
if (!allowed) {
77-
core.notice(`User ${actor} does not have sufficient repository permissions (has: ${permission})`);
78-
}
79-
} catch (error) {
80-
console.log(`Error checking permissions: ${error.message}`);
81-
82-
// Final fallback: Check if user is a public member of the organization
83-
try {
84-
const membership = await github.rest.orgs.getMembershipForUser({
85-
org: 'basicmachines-co',
86-
username: actor
87-
});
88-
89-
const allowed = membership.data.state === 'active';
90-
core.setOutput('is_member', allowed);
91-
92-
if (!allowed) {
93-
core.notice(`User ${actor} is not a public member of basicmachines-co organization`);
94-
}
95-
} catch (membershipError) {
96-
console.log(`Error checking organization membership: ${membershipError.message}`);
97-
core.setOutput('is_member', false);
98-
core.notice(`User ${actor} does not have access to this repository`);
99-
}
100-
}
101-
10228
- name: Checkout repository
103-
if: steps.check_membership.outputs.is_member == 'true'
10429
uses: actions/checkout@v4
10530
with:
10631
fetch-depth: 1
10732

10833
- name: Run Claude Code
109-
if: steps.check_membership.outputs.is_member == 'true'
11034
id: claude
111-
uses: anthropics/claude-code-action@beta
35+
uses: anthropics/claude-code-action@v1
11236
with:
113-
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
114-
allowed_tools: Bash(uv run pytest),Bash(uv run ruff check . --fix),Bash(uv run ruff format .),Bash(uv run pyright),Bash(just test),Bash(just lint),Bash(just format),Bash(just type-check),Bash(just check),Read,Write,Edit,MultiEdit,Glob,Grep,LS, mcp__web_search
37+
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
38+
39+
# This is an optional setting that allows Claude to read CI results on PRs
40+
additional_permissions: |
41+
actions: read
42+
43+
# Optional: Give a custom prompt to Claude. If this is not specified, Claude will perform the instructions specified in the comment that tagged it.
44+
# prompt: 'Update the pull request description to include a summary of changes.'
45+
46+
# Optional: Add claude_args to customize behavior and configuration
47+
# See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md
48+
# or https://docs.claude.com/en/docs/claude-code/sdk#command-line for available options
49+
# claude_args: '--model claude-opus-4-1-20250805 --allowed-tools Bash(gh pr:*)'
50+

0 commit comments

Comments
 (0)