Skip to main content
EVOKORE// WORKFLOWS / claude.yml
ag2ai/ag2workflow · 73 lines

workflows/claude.yml

CI / automation

View on GitHub →
# REFERENCE-ONLY: GitHub Actions secrets referenced below are illustrative.
# Do not inject real credentials. See your CI/CD provider for proper secret management.
name: Claude Code

on:
  issue_comment:
    types: [created]
  pull_request_review_comment:
    types: [created]
  issues:
    types: [opened, assigned]
  pull_request_review:
    types: [submitted]

jobs:
  claude:
    if: |
      (github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
      (github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
      (github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
      (github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
    runs-on: ubuntu-latest
    permissions:
      contents: read
      pull-requests: read
      issues: read
      id-token: write
      actions: read # Required for Claude to read CI results on PRs
    steps:
      - name: Checkout repository
        uses: actions/checkout@v4
        with:
          fetch-depth: 1

      - name: Checkout PR branch (if comment is on a PR)
        if: github.event.issue.pull_request || github.event.pull_request
        env:
          GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
        run: |
          if [ -n "${{ github.event.issue.number }}" ]; then
            PR_NUMBER="${{ github.event.issue.number }}"
          elif [ -n "${{ github.event.pull_request.number }}" ]; then
            PR_NUMBER="${{ github.event.pull_request.number }}"
          fi

          if [ -n "$PR_NUMBER" ]; then
            echo "Detected comment on PR #$PR_NUMBER"

            # Check if it's a forked PR
            PR_INFO=$(gh pr view $PR_NUMBER --json isCrossRepository,headRepositoryOwner 2>/dev/null || echo '{}')
            IS_FORK=$(echo "$PR_INFO" | jq -r '.isCrossRepository // false')

            if [ "$IS_FORK" = "true" ]; then
              echo "⚠️  Forked PR detected - running in secure mode"
              FORK_OWNER=$(echo "$PR_INFO" | jq -r '.headRepositoryOwner.login')
              echo "PR from: $FORK_OWNER"
            fi

            echo "Checking out PR #$PR_NUMBER"
            gh pr checkout $PR_NUMBER
            echo "✅ PR branch checked out successfully"
          fi

      - name: Run Claude Code
        id: claude
        uses: anthropics/claude-code-action@v1
        with:
          claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}

          # This is an optional setting that allows Claude to read CI results on PRs
          additional_permissions: |
            actions: read