Skip to content

Iteration 2026-01-23-005: Revise stable zone regularity target #33

Iteration 2026-01-23-005: Revise stable zone regularity target

Iteration 2026-01-23-005: Revise stable zone regularity target #33

Workflow file for this run

name: Claude Code
on:
issue_comment:
types: [created]
pull_request_review_comment:
types: [created]
issues:
types: [opened, assigned]
pull_request_review:
types: [submitted]
jobs:
claude:
# Security: Only allow OWNER, MEMBER, or COLLABORATOR to trigger Claude
# This prevents unauthorized users from burning API credits or making changes
if: |
(
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
) && (
github.event.comment.author_association == 'OWNER' ||
github.event.comment.author_association == 'MEMBER' ||
github.event.comment.author_association == 'COLLABORATOR' ||
github.event.issue.author_association == 'OWNER' ||
github.event.issue.author_association == 'MEMBER' ||
github.event.issue.author_association == 'COLLABORATOR' ||
github.event.review.author_association == 'OWNER' ||
github.event.review.author_association == 'MEMBER' ||
github.event.review.author_association == 'COLLABORATOR'
)
runs-on: ubuntu-latest
# Permissions rationale (updated 2026-01-18 for /iterate command support):
# - contents: write - Required for Claude to push code changes and create branches
# - pull-requests: write - Required for Claude to create and update PRs
# - issues: write - Required for Claude to update issue comments and labels
# - id-token: write - Required for OIDC authentication
# - actions: read - Required for Claude to read CI results on PRs
#
# Security model:
# - Only OWNER/MEMBER/COLLABORATOR can trigger (see `if` condition above)
# - Claude creates PRs for review, does not merge directly
# - No force push capability
# - Repository-scoped permissions only
#
# See: docs/tasks/completed/64-claude-permissions.md for full rationale
permissions:
contents: write
pull-requests: write
issues: write
id-token: write
actions: read
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 1
- name: Run Claude Code
id: claude
uses: anthropics/claude-code-action@v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# This is an optional setting that allows Claude to read CI results on PRs
additional_permissions: |
actions: read
# Optional: Give a custom prompt to Claude. If this is not specified, Claude will perform the instructions specified in the comment that tagged it.
# prompt: 'Update the pull request description to include a summary of changes.'
# Optional: Add claude_args to customize behavior and configuration
# See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md
# or https://code.claude.com/docs/en/cli-reference for available options
# claude_args: '--allowed-tools Bash(gh pr:*)'