Configure the @claude summon workflow so it can actually produce a
verified fix when asked in an issue/PR comment:
- use_commit_signing: bot commits show as Verified
- --allowedTools Bash: lets Claude build/test to verify the fix before
committing (default allowlist blocks Bash). Safe because the job `if`
gate restricts this to OWNER/MEMBER/COLLABORATOR.
- --max-turns 30: enough turns to investigate -> fix -> verify
Auto-commit/PR is already built into claude-code-action and the
required write permissions were already present, so no permission
changes are needed.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- claude.yml: drop the issues "assigned" trigger; its author_association
gate keys on the issue author, not the assigner, so a maintainer
assigning an outside contributor's issue would be wrongly skipped.
- claude-code-review.yml: issues: read -> write so use_sticky_comment can
create/update its PR comment via the issues API.
- hil SKILL.md: make local/remote command blocks copy-pasteable (drop
[-b BOARD_NAME] notation for concrete examples) and fix timeout
(600000 ms is 10 min; use 1200000 ms for the stated 20 min).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- claude.yml: gate @claude on author_association (OWNER/MEMBER/COLLABORATOR)
so the write-scoped token and OAuth secret are never issued for an
untrusted commenter on this public repo (defense-in-depth).
- claude-code-review.yml: skip fork PRs in the job condition
(head.repo.full_name == github.repository) since forks get no secrets
and would only fail noisily; fix the misleading token comment; pass
additional_permissions: actions: read so actions: read is effective.
- hil SKILL.md: reword hostname guidance, use full test/hil/* paths, and
show an explicit CONFIG= assignment so the local command is runnable.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- claude-code-review.yml: re-enable (drop `if: false`); switch from
pull_request_target to pull_request so fork PRs never receive the
OAuth token (avoids prompt-injection token leak). Auto-review on
open/synchronize/reopen/ready_for_review, skip drafts, sticky comment.
- claude.yml: grant contents/pull-requests/issues write so @claude can
reply and push fixes; @claude is the on-demand path for fork PRs.
Switch pull_request to pull_request_target so secrets and OIDC tokens
are available when reviewing PRs from forks. Also add pull-requests: write
permission so the action can post review comments.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The stm32h7 and samd5x_e5x targets were configured with boards that
aren't built by CI (which uses --one-first flag). This caused the
membrowse workflow to run in identical mode and fail on upload.
- stm32h7: daisyseed → stm32h743eval
- samd5x_e5x: d5035_01 → metro_m4_express