ci: address codex/copilot review on claude workflows

- claude.yml: gate @claude on author_association (OWNER/MEMBER/COLLABORATOR)
  so the write-scoped token and OAuth secret are never issued for an
  untrusted commenter on this public repo (defense-in-depth).
- claude-code-review.yml: skip fork PRs in the job condition
  (head.repo.full_name == github.repository) since forks get no secrets
  and would only fail noisily; fix the misleading token comment; pass
  additional_permissions: actions: read so actions: read is effective.
- hil SKILL.md: reword hostname guidance, use full test/hil/* paths, and
  show an explicit CONFIG= assignment so the local command is runnable.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
hathach
2026-06-02 00:16:54 +07:00
parent 87f9cc01cf
commit 1ea04f7fe6
3 changed files with 30 additions and 16 deletions

View File

@ -5,16 +5,18 @@ on:
# opened/reopened/ready_for_review -> first auto review
# synchronize -> auto re-review on new pushes
#
# NOTE: pull_request (not _target) means fork PRs from non-write-access
# contributors get NO token, so they are not auto-reviewed -> use @claude
# on those. Same-repo branches (yours or write-access contributors) get
# full auto-review safely.
# NOTE: pull_request (not _target) means fork PRs get a read-only GITHUB_TOKEN
# and NO repository secrets (CLAUDE_CODE_OAUTH_TOKEN), so they cannot be
# auto-reviewed. The job condition below skips them cleanly -> use @claude on
# those. Same-repo branches (yours or write-access contributors) auto-review.
types: [opened, synchronize, reopened, ready_for_review]
jobs:
claude-review:
# Skip drafts; review real PRs only
if: github.event.pull_request.draft == false
# Skip drafts, and skip fork PRs (no secrets -> would only fail noisily)
if: >
github.event.pull_request.draft == false &&
github.event.pull_request.head.repo.full_name == github.repository
runs-on: ubuntu-latest
permissions:
contents: read
@ -34,6 +36,9 @@ jobs:
uses: anthropics/claude-code-action@v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# Pairs with the actions: read permission so Claude can read CI results
additional_permissions: |
actions: read
plugin_marketplaces: 'https://github.com/anthropics/claude-code.git'
plugins: 'code-review@claude-code-plugins'
prompt: '/code-review:code-review ${{ github.repository }}/pull/${{ github.event.pull_request.number }}'

View File

@ -12,11 +12,18 @@ on:
jobs:
claude:
# Only trusted actors (repo owner/member/collaborator) may summon @claude, so the
# write-scoped token and OAuth secret are never issued for an outside contributor's
# comment on this public repo. Defense-in-depth on top of the action's own check.
if: |
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude') &&
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.comment.author_association)) ||
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude') &&
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.comment.author_association)) ||
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude') &&
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.review.author_association)) ||
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')) &&
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR"]'), github.event.issue.author_association))
runs-on: ubuntu-latest
permissions:
contents: write # allow Claude to push commits/branches when asked