diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml index cf9fc07..5da1f17 100644 --- a/.github/workflows/claude-code-review.yml +++ b/.github/workflows/claude-code-review.yml @@ -26,6 +26,31 @@ jobs: with: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} allowed_bots: 'dependabot[bot]' - plugin_marketplaces: 'https://github.com/anthropics/claude-code.git' - plugins: 'code-review@claude-code-plugins' - prompt: '/code-review:code-review ${{ github.repository }}/pull/${{ github.event.pull_request.number }}' + track_progress: true + prompt: | + REPO: ${{ github.repository }} + PR NUMBER: ${{ github.event.pull_request.number }} + + Review this pull request for the PSProxmoxVE PowerShell module. + + Focus areas: + 1. **DECISIONS.md compliance** — Check against the 13 architectural + decisions (D001-D013). Any violation is a regression. + 2. **Code quality** — Cmdlet conventions (sealed, OutputType, + ConfirmImpact.High for destructive, VmId ValidateRange), + SecureString for passwords, Uri.EscapeDataString on path params, + no bare catch blocks, Newtonsoft-only JSON. + 3. **API correctness** — Parameter names and enum values must match + the PVE OpenAPI spec (see tests/PSProxmoxVE.Core.Tests/Fixtures/ + pve-api-enums.pve*.json for valid values per PVE version). + 4. **Tests** — New cmdlets should have xUnit service tests and + Pester parameter-validation tests. + 5. **Security** — No hardcoded credentials, no secrets in logs, + TLS verification on by default. + + Provide inline comments for specific issues and a summary comment + for general observations. Skip nitpicks unless they indicate a + real problem. + + claude_args: | + --allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)"