name: Claude Code on: issue_comment: types: [created] pull_request_review_comment: types: [created] issues: types: [opened, assigned] pull_request_review: types: [submitted] jobs: check-permissions: if: | (github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) || (github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) || (github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) || (github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude'))) runs-on: ubuntu-latest outputs: has-permission: ${{ steps.check-org.outputs.result }} steps: - name: Check organization membership id: check-org uses: actions/github-script@v7 with: script: | let username; if (context.eventName === 'issue_comment' || context.eventName === 'pull_request_review_comment') { username = context.payload.comment.user.login; } else if (context.eventName === 'pull_request_review') { username = context.payload.review.user.login; } else if (context.eventName === 'issues') { username = context.payload.issue.user.login; } try { const { data: perm } = await github.rest.repos.getCollaboratorPermissionLevel({ owner: context.repo.owner, repo: context.repo.repo, username: username }); const hasAccess = ['admin', 'write'].includes(perm.permission); console.log(`User ${username} has ${perm.permission} access`); return hasAccess; } catch(error) { console.log(`User ${username} has no repository access`); return false; } claude: needs: [check-permissions] if: needs.check-permissions.outputs.has-permission == 'true' runs-on: ubuntu-latest permissions: contents: read pull-requests: read issues: read id-token: write actions: read # Required for Claude to read CI results on PRs steps: - name: Checkout repository uses: actions/checkout@v4 with: fetch-depth: 1 - name: Run Claude Code id: claude uses: anthropics/claude-code-action@v1 with: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} # This is an optional setting that allows Claude to read CI results on PRs additional_permissions: | actions: read # Optional: Give a custom prompt to Claude. If this is not specified, Claude will perform the instructions specified in the comment that tagged it. # prompt: 'Update the pull request description to include a summary of changes.' # Optional: Add claude_args to customize behavior and configuration # See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md # or https://code.claude.com/docs/en/cli-reference for available options # claude_args: '--allowed-tools Bash(gh pr:*)' # NOTE(sfn): we can add a custom system prompt here claude_args: | --model claude-opus-4-5-20251101