Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/workflows/claude-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,11 @@ on:
issue_comment:
types: [created]

# A new push to a PR supersedes any review still running on the old head.
concurrency:
group: claude-review-${{ github.event.pull_request.number || github.event.issue.number }}
cancel-in-progress: true

jobs:
claude-review:
name: Review
Expand All @@ -30,6 +35,9 @@ jobs:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
github_token: ${{ secrets.GITHUB_TOKEN }}
trigger_phrase: "@claude"
# Read-only git access. Every recent run logged 3-6 denied tool
# calls, each a wasted turn; a reviewer needs the diff and history.
claude_args: "--allowedTools Bash(git diff:*),Bash(git log:*),Bash(git show:*),Bash(git blame:*)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

issue (bug_risk): The new --allowedTools argument replaces the action's existing default allowlist, so Claude is left with only the four git command patterns and loses Glob, Grep, LS, and Read; the reviewer cannot use the normal source-inspection tools it previously relied on.

Triggers: On any review run where the action treats the CLI allowlist as an override rather than a merge.

Suggested fix: Include the existing inspection tools in the allowlist, for example Read,Glob,Grep,LS alongside the four Bash(git ...) patterns, or use the action's documented additive mechanism.

Suggested change
claude_args: "--allowedTools Bash(git diff:*),Bash(git log:*),Bash(git show:*),Bash(git blame:*)"
claude_args: "--allowedTools Read,Glob,Grep,LS,Bash(git diff:*),Bash(git log:*),Bash(git show:*),Bash(git blame:*)"

prompt: |
REPO: ${{ github.repository }}
PR NUMBER: ${{ github.event.pull_request.number }}
Expand Down
Loading