Conversation
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
Owner
Author
|
@claude review this PR |
skoonin
added a commit
that referenced
this pull request
Jul 6, 2026
Adds the Claude CI system and CodeQL to `main` as repository infrastructure. Branched off `main` and adds only workflow and `.claude/` files — no product code. The Claude review and `@claude` responder must live on the default branch to run: mention-triggered runs use the default branch's workflows, and claude-code-action validates that a review workflow matches the default-branch copy before executing (a guard against a PR editing the review workflow to exfiltrate the API key). Hosting these only on `dev` leaves them inert. Contents (identical to the versions on the `dev`-targeted PR #56, so the validation passes for `dev` PRs): - `claude.yaml` — `@claude` responder, author-gated to OWNER/MEMBER/COLLABORATOR, reads `CC_API_KEY` from the `dev` environment. - `claude-review.yaml` — review on the `pr-review` label only; posts inline + summary comments itself (no `track_progress`, which the action rejects for the `labeled` event). - `codeql.yml` — CodeQL advanced setup (python + actions) on push/PR to `main` and `dev`. - `.claude/commands/sk-review-ci.md` + three vendored review agents. Both `main` and `dev` need identical copies of these files for the review to run on `dev`-targeted PRs; keep them in sync.
Merged
skoonin
added a commit
that referenced
this pull request
Jul 6, 2026
Release v1.1.1. Finalizes `__version__` `1.1.1-dev` → `1.1.1` and dates the CHANGELOG section. Since 1.1.0 the changes are repository/CI hardening rather than CLI behavior: - GitHub Actions pinned to commit SHAs + Dependabot for actions (#41) - CodeQL code scanning (Python + workflows) on push/PR to `main` and `dev` (#56) - Claude Code CI: `@claude` responder on PRs, and a `pr-review`-label-triggered automated review (#56) Per the release process, a merge into `main` is expected to conflict on the version/changelog lines; resolve by taking the release branch's versions. After merge, dispatch `cd-release.yaml` from `main` to tag `v1.1.1` and publish the Release, then bump `dev` to `1.1.2-dev`.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rewires the auto-review workflow (added in #172) to run a committed, CI-adapted version of the local
sk-revieworchestration instead of a single-pass prompt, and points both Claude workflows at thedevenvironment'sCC_API_KEY.Review workflow — trimmed sk-review roster
.claude/commands/sk-review-ci.mddrives the run:gh, reads CLAUDE.md conventions.code-reviewer(bugs/security/convention/data-loss) andcode-quality-pragmatist(over-engineering/YAGNI) run concurrently.reality-check-managerverifies each finding against the actual code; rejected findings are dropped.This keeps sk-review's multi-perspective + anti-hallucination structure at ~3 agents instead of the full 8, to bound per-PR cost.
Vendored agents (
.claude/agents/)/sk-reviewand its agents live in personal~/.claude/and plugins — absent from a CI checkout. The three needed agents are vendored into the repo, CI-adapted:code-reviewer— from the feature-dev plugin, already read-only.code-quality-pragmatist— trimmed to Read/Grep/Glob.reality-check-manager—Edit/Writeremoved so it verifies, not fixes.Plugin namespaces (
@agent-feature-dev:...) are rewritten to the repo-local names. Files aregit add -f'd because.gitignoreignores.claude/— same precedent as the #172 workflow files.Auth / environment
Both workflows now read
anthropic_api_key: ${{ secrets.CC_API_KEY }}and declareenvironment: dev.environment: devline.devenvironment has required-reviewer or wait-timer protection rules, both jobs (including the interactive @claude responder) will wait on those rules before running. Noted in an in-file comment. If that's undesirable for @claude, a plain repo secret avoids it.Still gated behind
CLAUDE_REVIEW_ENABLED(off by default),opened/ready_for_reviewonly, same-repo guard, non-draft.--max-turns 40, tools restricted to read +gh pr+ inline-comment (no Edit/Write/push).Not yet verified live
Headless subagent fan-out (the
Tasktool in the action runner) isn't documented; the first live run should be watched to confirm the parallel agents actually spawn. Safe to merge while gated off.