Skip to content

Add Claude Code GitHub Workflow - #1

Merged
megabyte0x merged 2 commits into
masterfrom
add-claude-github-actions-1767717439637
Jan 6, 2026
Merged

megabyte0x merged 2 commits into
masterfrom
add-claude-github-actions-1767717439637

Conversation

@megabyte0x

@megabyte0x megabyte0x commented Jan 6, 2026 •

Copy link
Copy Markdown
Owner

🤖 Installing Claude Code GitHub App

This PR adds a GitHub Actions workflow that enables Claude Code integration in our repository.

What is Claude Code?

Claude Code is an AI coding agent that can help with:

  • Bug fixes and improvements
  • Documentation updates
  • Implementing new features
  • Code reviews and suggestions
  • Writing tests
  • And more!

How it works

Once this PR is merged, we'll be able to interact with Claude by mentioning @claude in a pull request or issue comment.
Once the workflow is triggered, Claude will analyze the comment and surrounding context, and execute on the request in a GitHub action.

Important Notes

  • This workflow won't take effect until this PR is merged
  • @claude mentions won't work until after the merge is complete
  • The workflow runs automatically whenever Claude is mentioned in PR or issue comments
  • Claude gets access to the entire PR or issue context including files, diffs, and previous comments

Security

  • Our Anthropic API key is securely stored as a GitHub Actions secret
  • Only users with write access to the repository can trigger the workflow
  • All Claude runs are stored in the GitHub Actions run history
  • Claude's default tools are limited to reading/writing files and interacting with our repo by creating comments, branches, and commits.
  • We can add more allowed tools by adding them to the workflow file like:
allowed_tools: Bash(npm install),Bash(npm run build),Bash(npm run lint),Bash(npm run test)

There's more information in the Claude Code action repo.

After merging this PR, let's try mentioning @claude in a comment on any PR to get started!


Open with Devin

@megabyte0x
megabyte0x merged commit 801a4a7 into master Jan 6, 2026
1 of 2 checks passed
@megabyte0x
megabyte0x deleted the add-claude-github-actions-1767717439637 branch January 6, 2026 16:45

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

View issue and 2 additional flags in Devin Review.

Open in Devin Review

runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 Missing pull-requests: write permission prevents Claude from commenting on PRs

The workflow instructs Claude to leave review comments using gh pr comment (line 52) and includes Bash(gh pr comment:*) in the allowed tools (line 56), but the workflow only has pull-requests: read permission (line 24).

Click to expand

How the bug is triggered

  1. A pull request is opened or synchronized
  2. The workflow runs and Claude performs the code review
  3. Claude attempts to execute gh pr comment to post the review
  4. The GitHub API rejects the request because the workflow token only has read permission on pull requests

Actual vs Expected

Actual: The gh pr comment command fails with a permission error, and the review is never posted to the PR.

Expected: Claude successfully posts the code review as a comment on the PR.

Impact

The workflow's primary purpose (posting code reviews as PR comments) will fail every time. The code review analysis may complete successfully, but the results will never be visible to users.

Fix

Change line 24 from:

pull-requests: read

to:

pull-requests: write
Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant