From 732cc004341541f8081befa5bea37ea454c00e41 Mon Sep 17 00:00:00 2001 From: Lucas Holt Date: Thu, 24 Sep 2026 14:40:16 -0400 Subject: [PATCH 1/2] claude-review: cancel superseded PR review runs The review workflow fires on every push to a PR and nothing cancelled the run already in progress for the previous head. Several PRs were reviewed two to four times on the same day, each a full run. Add a concurrency group keyed on the PR number so a new push cancels the stale review instead of paying for both. AI-Assisted-by: Claude Fable 5.1 Co-Authored-By: Claude Fable 5.1 Signed-off-by: Lucas Holt --- .github/workflows/claude-review.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/claude-review.yml b/.github/workflows/claude-review.yml index 43f34e001e..cc2a9c076e 100644 --- a/.github/workflows/claude-review.yml +++ b/.github/workflows/claude-review.yml @@ -7,6 +7,11 @@ on: issue_comment: types: [created] +# A new push to a PR supersedes any review still running on the old head. +concurrency: + group: claude-review-${{ github.event.pull_request.number || github.event.issue.number }} + cancel-in-progress: true + jobs: claude-review: name: Review From f13c0297c338fe18728badb3aca48780907ad75b Mon Sep 17 00:00:00 2001 From: Lucas Holt Date: Thu, 24 Sep 2026 14:40:25 -0400 Subject: [PATCH 2/2] claude-review: allow read-only git commands during review Every recent review run recorded three to six permission denials, each a wasted turn. The allowed tool list covered Glob, Grep, LS and Read but no way to see the diff or history, so allow git diff, log, show and blame. Verify by watching permission_denials_count in the next runs' result output; revert if it does not drop. AI-Assisted-by: Claude Fable 5.1 Co-Authored-By: Claude Fable 5.1 Signed-off-by: Lucas Holt --- .github/workflows/claude-review.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/claude-review.yml b/.github/workflows/claude-review.yml index cc2a9c076e..062e8cb83f 100644 --- a/.github/workflows/claude-review.yml +++ b/.github/workflows/claude-review.yml @@ -35,6 +35,9 @@ jobs: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} github_token: ${{ secrets.GITHUB_TOKEN }} trigger_phrase: "@claude" + # Read-only git access. Every recent run logged 3-6 denied tool + # calls, each a wasted turn; a reviewer needs the diff and history. + claude_args: "--allowedTools Bash(git diff:*),Bash(git log:*),Bash(git show:*),Bash(git blame:*)" prompt: | REPO: ${{ github.repository }} PR NUMBER: ${{ github.event.pull_request.number }}