Support templates and note creation across the roots of a multi-root workspace #38
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Review | |
| # Every push of code gets reviewed, not just the first: the PR leaving draft | |
| # says the implementation is done, and each push after that — a fix round, a | |
| # follow-up — is code nobody has read yet. Drafts carry specs and plans and | |
| # are deliberately left alone. | |
| # | |
| # Scope: PRs opened by the flow (claude[bot]) or by the maintainer, from a | |
| # branch in this repo. A contributor's PR gets a review by asking for one in | |
| # a comment, which claude.yml handles. | |
| # | |
| # Only PRs from this flow (opened by the Claude app, branch in this repo) are | |
| # reviewed automatically. To review anyone else's PR, ask in a comment and | |
| # claude.yml handles it. | |
| on: | |
| pull_request: | |
| types: [opened, ready_for_review, synchronize] | |
| # A newer push makes an in-flight review of the older code pointless. | |
| concurrency: | |
| group: review-${{ github.event.pull_request.number }} | |
| cancel-in-progress: true | |
| jobs: | |
| review: | |
| # Draft is the line between work in progress and code to review: specs and | |
| # plans land while the PR is a draft, so only pushes after it leaves draft | |
| # get reviewed — including the fix rounds, which is the point. | |
| if: >- | |
| github.event.pull_request.draft == false && | |
| (github.event.pull_request.user.login == 'claude[bot]' || | |
| github.event.pull_request.user.login == 'riccardoferretti') && | |
| github.event.pull_request.head.repo.full_name == github.repository | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| permissions: | |
| contents: read | |
| pull-requests: write | |
| issues: read | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@v6 | |
| with: | |
| fetch-depth: 0 | |
| - uses: anthropics/claude-code-action@v1 | |
| with: | |
| claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} | |
| plugin_marketplaces: "https://github.com/anthropics/claude-code.git" | |
| plugins: "code-review@claude-code-plugins" | |
| prompt: | | |
| /code-review:code-review --comment ${{ github.repository }}/pull/${{ github.event.pull_request.number }} | |
| Proceed with the review even though this pull request was opened | |
| by the Claude app and already carries comments from it. Those are | |
| stage reports from this repo's spec, plan and implement stages — | |
| not a code review. Treat a review as already done only if you | |
| posted findings against the current head commit. This PR being | |
| agent-authored is the normal case here, not a reason to skip. | |
| If you find nothing worth reporting, say so in one summary | |
| comment. Silence is indistinguishable from not having run. | |
| This PR implements the spec committed in the same branch under | |
| specs/<slug>/spec.md, where <slug> is the branch name minus its | |
| type prefix. Read that spec first and review the diff against its | |
| acceptance criteria as well as for correctness: a criterion with | |
| no test that proves it is a finding, and so is a test that asserts | |
| something weaker than its criterion. | |
| Read the diff with: | |
| git diff origin/main...HEAD -- . ':!specs/**/plan.md' | |
| rather than `gh pr diff`, which would include specs/**/plan.md. | |
| Do not read that file by any route. Knowing the intended approach | |
| makes you check whether the code matches the plan, when the job is | |
| to check whether the code is right. | |
| A user-visible feature or behaviour change with nothing added | |
| under docs/user/ is a finding, and so is documentation that | |
| explains the implementation rather than showing someone how to | |
| use the feature — AGENTS.md sets the standard those pages are | |
| held to. | |
| Report findings only. Do not push commits, and do not approve or | |
| request changes — the maintainer decides. | |
| settings: '{"permissions":{"deny":["Read(./specs/**/plan.md)","Bash(git push:*)","Bash(git remote:*)","Bash(gh api:*)","Bash(gh pr merge:*)","Bash(gh pr close:*)","Bash(gh workflow:*)","Bash(gh secret:*)","Bash(gh release:*)"]}}' | |
| claude_args: | | |
| --model claude-fable-5-1 | |
| --allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(git diff:*),Bash(git log:*),Bash(git show:*),Bash(gh pr view:*),Bash(gh pr diff:*),Read,Grep,Glob" |