Skip to content

Add Claude Code GitHub Workflow #453

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
37 changes: 37 additions & 0 deletions .github/workflows/claude.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
name: Claude Code

on:
issue_comment:
types: [created]
pull_request_review_comment:
types: [created]
issues:
types: [opened, assigned]
pull_request_review:
types: [submitted]

jobs:
claude:
if: |
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
issues: read
id-token: write
Comment on lines +21 to +25
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The action that powers Claude will need to write to the repository (e.g. opening PRs, committing changes, or posting comments). Granting only read permissions to contents and pull-requests is likely to cause authorization failures at runtime and defeats the purpose of the integration. Granting the minimal required write scopes keeps the principle of least privilege while still allowing Claude to function.

Suggestion

Update the permission block:

permissions:
  contents: write         # allow committing / pushing branches
  pull-requests: write    # allow creating / updating PRs
  issues: write           # allow commenting on issues/PRs
  id-token: write         # required for OIDC

Reply with "@CharlieHelps yes please" if you'd like me to add a commit with this suggestion.

steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 1

- name: Run Claude Code
id: claude
uses: anthropics/claude-code-action@beta
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pinning an action to a floating tag (@beta) introduces supply-chain risk because the referenced code can change unexpectedly. GitHub’s security guidance recommends pinning to a commit SHA or at least a versioned tag to guarantee immutability.

Suggestion

Replace anthropics/claude-code-action@beta with a specific version or SHA, e.g.:

uses: anthropics/claude-code-action@<commit-sha>

Reply with "@CharlieHelps yes please" if you'd like me to add a commit with this suggestion.

with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}

Loading