mirror of
https://github.com/GoodOlClint/PSProxmoxVE.git
synced 2026-07-26 07:58:14 +00:00
6e2f25a083
Previous approach (/code-review:code-review --comment) was based on incorrect documentation research. Reviewing the actual official examples at anthropics/claude-code-action/examples/pr-review-*.yml reveals the correct pattern: 1. Use a custom prompt with explicit review instructions (not a plugin slash command) 2. Use claude_args with --allowedTools to enable the MCP inline comment tool and gh pr CLI commands — this is what lets Claude actually post to the PR 3. Enable track_progress: true for visual progress tracking Without --allowedTools, Claude has no way to post anything because the tools for PR commenting aren't allowed by default. Also removed the plugins and plugin_marketplaces inputs since they're not needed — the review runs via prompt instructions and the allowed tools alone. The custom prompt is tailored to PSProxmoxVE with focus areas specific to the module: DECISIONS.md compliance, cmdlet conventions, API correctness against the PVE OpenAPI spec, test coverage, and security. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
57 lines
2.2 KiB
YAML
57 lines
2.2 KiB
YAML
name: Claude Code Review
|
|
|
|
on:
|
|
pull_request:
|
|
types: [opened, synchronize, ready_for_review, reopened]
|
|
|
|
jobs:
|
|
claude-review:
|
|
if: ${{ !github.event.pull_request.draft }}
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
pull-requests: write
|
|
issues: write
|
|
id-token: write
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v6
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Run Claude Code Review
|
|
id: claude-review
|
|
uses: anthropics/claude-code-action@v1
|
|
with:
|
|
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
|
|
allowed_bots: 'dependabot[bot]'
|
|
track_progress: true
|
|
prompt: |
|
|
REPO: ${{ github.repository }}
|
|
PR NUMBER: ${{ github.event.pull_request.number }}
|
|
|
|
Review this pull request for the PSProxmoxVE PowerShell module.
|
|
|
|
Focus areas:
|
|
1. **DECISIONS.md compliance** — Check against the 13 architectural
|
|
decisions (D001-D013). Any violation is a regression.
|
|
2. **Code quality** — Cmdlet conventions (sealed, OutputType,
|
|
ConfirmImpact.High for destructive, VmId ValidateRange),
|
|
SecureString for passwords, Uri.EscapeDataString on path params,
|
|
no bare catch blocks, Newtonsoft-only JSON.
|
|
3. **API correctness** — Parameter names and enum values must match
|
|
the PVE OpenAPI spec (see tests/PSProxmoxVE.Core.Tests/Fixtures/
|
|
pve-api-enums.pve*.json for valid values per PVE version).
|
|
4. **Tests** — New cmdlets should have xUnit service tests and
|
|
Pester parameter-validation tests.
|
|
5. **Security** — No hardcoded credentials, no secrets in logs,
|
|
TLS verification on by default.
|
|
|
|
Provide inline comments for specific issues and a summary comment
|
|
for general observations. Skip nitpicks unless they indicate a
|
|
real problem.
|
|
|
|
claude_args: |
|
|
--allowedTools "mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*)"
|