Skip to content

Set the pending-wrap flag only at the phantom column #98

Set the pending-wrap flag only at the phantom column

Set the pending-wrap flag only at the phantom column #98

name: Claude Code Review
on:
pull_request:
types: [opened, ready_for_review, reopened]
# Optional: Only run on specific file changes
# paths:
# - "src/**/*.ts"
# - "src/**/*.tsx"
# - "src/**/*.js"
# - "src/**/*.jsx"
jobs:
claude-review:
# Optional: Filter by PR author
# if: |
# github.event.pull_request.user.login == 'external-contributor' ||
# github.event.pull_request.user.login == 'new-developer' ||
# github.event.pull_request.author_association == 'FIRST_TIME_CONTRIBUTOR'
# Reviewable pull requests only. Three cases this cannot or should not review:
# head.repo.fork -- a FORK pull request. GitHub gives these a read-only token, no
# id-token: write and NO SECRETS, so ANTHROPIC_API_KEY arrives
# empty and the action dies on OIDC. Not fixable by permissions;
# pull_request_target would fix it by running fork code WITH the
# secrets, which is worse than no review.
# user.type -- the PR was OPENED by a bot (Copilot and friends).
# github.actor -- a human's PR that Claude then PUSHED to. The push fires
# `synchronize`, and Claude would review its own commit.
# All three are still reviewable on demand: comment @claude on the PR. That runs on
# issue_comment, which is a base-repo event and does get the secrets.
if: github.event.pull_request.head.repo.fork == false && github.event.pull_request.user.type != 'Bot' && github.actor != 'claude[bot]'
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
issues: read
id-token: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 1
- name: Run Claude Code Review
id: claude-review
uses: anthropics/claude-code-action@v1
with:
show_full_output: true
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
plugin_marketplaces: 'https://github.com/anthropics/claude-code.git'
plugins: 'code-review@claude-code-plugins'
prompt: '/code-review:code-review ${{ github.repository }}/pull/${{ github.event.pull_request.number }}'
# Same gating as claude.yml: .claude/settings.json does not reach the Action, so a
# reviewer without this cannot build or run the suite, and every finding it reports
# is unverified reasoning about code it never executed.
# See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md
# or https://code.claude.com/docs/en/cli-reference for available options
# --model pinned EXPLICITLY. Left to default, the CLI resolved to claude-opus-5[1m]
# -- the 1M-context variant, which this key cannot use -- and the first API call died
# in under half a second: is_error, zero cost, empty modelUsage, and the real error
# hidden by the default output redaction. show_full_output is on for the same reason:
# a failure that cannot be read from the log gets diagnosed by archaeology instead.
claude_args: '--model claude-opus-5 --allowedTools "Bash(dotnet:*),Bash(gh pr edit:*),Bash(gh pr ready:*),Bash(gh pr view:*)"'