Skip to content

ci: Claude workflows (@claude + on-request review) and CodeQL - #56

Merged
skoonin merged 4 commits into
devfrom
claude-ci
Jul 6, 2026
Merged

skoonin merged 4 commits into
devfrom
claude-ci

Conversation

@skoonin

@skoonin skoonin commented Jul 6, 2026 •

Copy link
Copy Markdown
Owner

Rewires the auto-review workflow (added in #172) to run a committed, CI-adapted version of the local sk-review orchestration instead of a single-pass prompt, and points both Claude workflows at the dev environment's CC_API_KEY.

Review workflow — trimmed sk-review roster

.claude/commands/sk-review-ci.md drives the run:

  1. Context — orchestrator gets the PR diff/base via gh, reads CLAUDE.md conventions.
  2. Parallel review — code-reviewer (bugs/security/convention/data-loss) and code-quality-pragmatist (over-engineering/YAGNI) run concurrently.
  3. Reality check — reality-check-manager verifies each finding against the actual code; rejected findings are dropped.
  4. Post — inline comments for verified findings + one summary comment.

This keeps sk-review's multi-perspective + anti-hallucination structure at ~3 agents instead of the full 8, to bound per-PR cost.

Vendored agents (.claude/agents/)

/sk-review and its agents live in personal ~/.claude/ and plugins — absent from a CI checkout. The three needed agents are vendored into the repo, CI-adapted:

  • code-reviewer — from the feature-dev plugin, already read-only.
  • code-quality-pragmatist — trimmed to Read/Grep/Glob.
  • reality-check-manager — Edit/Write removed so it verifies, not fixes.

Plugin namespaces (@agent-feature-dev:...) are rewritten to the repo-local names. Files are git add -f'd because .gitignore ignores .claude/ — same precedent as the #172 workflow files.

Auth / environment

Both workflows now read anthropic_api_key: ${{ secrets.CC_API_KEY }} and declare environment: dev.

  • Env secrets are only readable by a job that declares the environment — hence the environment: dev line.
  • Caveat: if the dev environment has required-reviewer or wait-timer protection rules, both jobs (including the interactive @claude responder) will wait on those rules before running. Noted in an in-file comment. If that's undesirable for @claude, a plain repo secret avoids it.

Still gated behind CLAUDE_REVIEW_ENABLED (off by default), opened/ready_for_review only, same-repo guard, non-draft. --max-turns 40, tools restricted to read + gh pr + inline-comment (no Edit/Write/push).

Not yet verified live

Headless subagent fan-out (the Task tool in the action runner) isn't documented; the first live run should be watched to confirm the parallel agents actually spawn. Safe to merge while gated off.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@skoonin

skoonin commented Jul 6, 2026

Copy link
Copy Markdown
Owner Author

@claude review this PR

@skoonin
skoonin merged commit 225047c into dev Jul 6, 2026
18 checks passed
@skoonin
skoonin deleted the claude-ci branch July 6, 2026 18:55
skoonin added a commit that referenced this pull request Jul 6, 2026
Adds the Claude CI system and CodeQL to `main` as repository
infrastructure. Branched off `main` and adds only workflow and
`.claude/` files — no product code.

The Claude review and `@claude` responder must live on the default
branch to run: mention-triggered runs use the default branch's
workflows, and claude-code-action validates that a review workflow
matches the default-branch copy before executing (a guard against a PR
editing the review workflow to exfiltrate the API key). Hosting these
only on `dev` leaves them inert.

Contents (identical to the versions on the `dev`-targeted PR #56, so the
validation passes for `dev` PRs):

- `claude.yaml` — `@claude` responder, author-gated to
OWNER/MEMBER/COLLABORATOR, reads `CC_API_KEY` from the `dev`
environment.
- `claude-review.yaml` — review on the `pr-review` label only; posts
inline + summary comments itself (no `track_progress`, which the action
rejects for the `labeled` event).
- `codeql.yml` — CodeQL advanced setup (python + actions) on push/PR to
`main` and `dev`.
- `.claude/commands/sk-review-ci.md` + three vendored review agents.

Both `main` and `dev` need identical copies of these files for the
review to run on `dev`-targeted PRs; keep them in sync.
@skoonin skoonin mentioned this pull request Jul 6, 2026
skoonin added a commit that referenced this pull request Jul 6, 2026
Release v1.1.1. Finalizes `__version__` `1.1.1-dev` → `1.1.1` and dates
the CHANGELOG section.

Since 1.1.0 the changes are repository/CI hardening rather than CLI
behavior:
- GitHub Actions pinned to commit SHAs + Dependabot for actions (#41)
- CodeQL code scanning (Python + workflows) on push/PR to `main` and
`dev` (#56)
- Claude Code CI: `@claude` responder on PRs, and a
`pr-review`-label-triggered automated review (#56)

Per the release process, a merge into `main` is expected to conflict on
the version/changelog lines; resolve by taking the release branch's
versions. After merge, dispatch `cd-release.yaml` from `main` to tag
`v1.1.1` and publish the Release, then bump `dev` to `1.1.2-dev`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants