Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/code-review.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ jobs:
contents: read
pull-requests: write
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
with:
ref: ${{ github.event.pull_request.head.sha || github.sha }}
fetch-depth: 2
Expand Down
8 changes: 5 additions & 3 deletions .github/workflows/test-claudecode.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,17 +18,18 @@ jobs:
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5

- name: Set up Python
uses: actions/setup-python@7f4fc3e22c37d6ff65e88745f38bd3157c663f7c # v4
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
with:
python-version: '3.10'

- name: Set up Node.js
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5
with:
node-version: '20'
package-manager-cache: false

- name: Install Claude CLI
run: |
Expand All @@ -38,6 +39,7 @@ jobs:
run: |
pip install pytest pytest-cov
pip install -r claudecode/requirements.txt
pip install -r claudecode/requirements-dev.txt

- name: Run ClaudeCode unit tests
run: |
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ __pycache__/
# Output files
*.csv
*.json
!scripts/fixtures/*.json
security_report.*

# Virtual environments
Expand Down
8 changes: 6 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,8 +41,12 @@ claudecode/
## Testing

```bash
# Python tests
pytest claudecode -v # Run all tests (177 passing)
# Python tests (PyYAML is a dev-only dependency of the action-runtime guard tests)
python -m pip install -r claudecode/requirements.txt -r claudecode/requirements-dev.txt pytest
pytest claudecode -v # Run all tests (250 tests)
# Action runtime guard (offline) and fixture refresh check (needs network)
python scripts/check-action-runtime-dependencies.py
python scripts/refresh-action-runtime-metadata.py --check
# JavaScript tests
~/.bun/bin/bun test scripts/comment-pr-findings.bun.test.js
```
Expand Down
11 changes: 11 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -95,6 +95,10 @@ jobs:

**Note**: The `app-slug` parameter enables the bot to detect when it's mentioned in PR comments (e.g., `@my-code-review-app`). Requires `actions/create-github-app-token@v1.9.0` or later. `publish-check` additionally requires the GitHub App to have **Checks: read and write**. The action reacts to an accepted `review` command and creates the in-progress Check Run before checking out the repository.

## Runner Requirements

This action's GitHub Action dependencies require a runner that supports the Node 24 action runtime: actions/runner 2.327.1 or newer (GitHub-hosted runners already qualify). This is separate from the reviewer application's Node.js toolchain: the composite action continues to install Node.js 18 for the review and the repository test workflow continues to install Node.js 20 for its tests.

## Security Considerations

This action is not hardened against prompt injection attacks and should only be used to review trusted PRs. We recommend [configuring your repository](https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#controlling-changes-from-forks-to-workflows-in-public-repositories) to use the "Require approval for all external contributors" option to ensure workflows only run after a maintainer has reviewed the PR.
Expand Down Expand Up @@ -520,9 +524,16 @@ Review dismissal works automatically with custom apps since reviews are identifi
Run the test suite to validate functionality:

```bash
# From the repository root, install Python test dependencies
python -m pip install -r claudecode/requirements.txt -r claudecode/requirements-dev.txt pytest

# Python tests
pytest claudecode -v

# Action runtime guard (offline) and fixture refresh check (needs network)
python scripts/check-action-runtime-dependencies.py
python scripts/refresh-action-runtime-metadata.py --check

# JavaScript tests
cd scripts && npm test

Expand Down
13 changes: 7 additions & 6 deletions action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -239,7 +239,7 @@ runs:
- name: Check ClaudeCode run history
id: claudecode-history
if: github.event_name == 'pull_request' || (github.event_name == 'issue_comment' && steps.pr-info.outputs.is_pr == 'true')
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
uses: actions/cache@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: .claudecode-marker
key: claudecode-${{ github.repository_id }}-pr-${{ github.event.pull_request.number || steps.pr-info.outputs.pr_number }}-${{ github.event.pull_request.head.sha || steps.pr-info.outputs.pr_sha }}
Expand Down Expand Up @@ -323,7 +323,7 @@ runs:

- name: Checkout exact PR head
if: inputs.checkout-pr == 'true' && steps.claudecode-check.outputs.enable_claudecode == 'true'
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5
with:
repository: ${{ github.repository }}
ref: ${{ github.event.pull_request.head.sha || steps.pr-info.outputs.pr_sha }}
Expand Down Expand Up @@ -388,15 +388,16 @@ runs:

- name: Set up Python
if: steps.claudecode-check.outputs.enable_claudecode == 'true'
uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
with:
python-version: '3.x'

- name: Set up Node.js
if: steps.claudecode-check.outputs.enable_claudecode == 'true'
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5
with:
node-version: '18'
package-manager-cache: false

- name: Setup git for diffing
if: steps.claudecode-check.outputs.enable_claudecode == 'true'
Expand Down Expand Up @@ -623,15 +624,15 @@ runs:

- name: Save ClaudeCode reservation to cache
if: steps.claudecode-check.outputs.enable_claudecode == 'true' && steps.claudecode-scan.outputs.scan_failed != 'true'
uses: actions/cache/save@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5
with:
path: .claudecode-marker
key: claudecode-${{ github.repository_id }}-pr-${{ github.event.pull_request.number || steps.pr-info.outputs.pr_number }}-${{ github.event.pull_request.head.sha || steps.pr-info.outputs.pr_sha || github.sha }}


- name: Upload scan results
if: always() && inputs.upload-results == 'true'
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6
with:
name: code-review-results
path: |
Expand Down
2 changes: 2 additions & 0 deletions claudecode/requirements-dev.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
# Development and test dependencies for local validation tools
PyYAML>=6.0.2
Loading
Loading