diff --git a/.github/workflows/claude-review.yml b/.github/workflows/claude-review.yml index 43f34e001e..062e8cb83f 100644 --- a/.github/workflows/claude-review.yml +++ b/.github/workflows/claude-review.yml @@ -7,6 +7,11 @@ on: issue_comment: types: [created] +# A new push to a PR supersedes any review still running on the old head. +concurrency: + group: claude-review-${{ github.event.pull_request.number || github.event.issue.number }} + cancel-in-progress: true + jobs: claude-review: name: Review @@ -30,6 +35,9 @@ jobs: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} github_token: ${{ secrets.GITHUB_TOKEN }} trigger_phrase: "@claude" + # Read-only git access. Every recent run logged 3-6 denied tool + # calls, each a wasted turn; a reviewer needs the diff and history. + claude_args: "--allowedTools Bash(git diff:*),Bash(git log:*),Bash(git show:*),Bash(git blame:*)" prompt: | REPO: ${{ github.repository }} PR NUMBER: ${{ github.event.pull_request.number }}