Skip to content

CI review and Feishu notification #27

CI review and Feishu notification

CI review and Feishu notification #27

Workflow file for this run

# Actions secrets: MINIMAX_API_KEY, FEISHU_WEBHOOK_URL; optional FEISHU_WEBHOOK_SECRET.
# workflow_run activates after this file reaches the default branch.
name: CI review and Feishu notification
on:
workflow_run:
workflows: [core-check]
branches: [main]
types: [completed]
permissions:
contents: read
actions: read
pull-requests: read
jobs:
review:
if: github.event.workflow_run.event == 'push' && github.event.workflow_run.head_branch == 'main'
runs-on: ${{ vars.OAC_USE_GITHUB_RUNNERS == 'true' && 'ubuntu-24.04' || 'blacksmith-2vcpu-ubuntu-2404' }}
timeout-minutes: 30
env:
# allowed_non_write_users turns on a subprocess secret scrub; opt out so Claude's
# commands can read GH_TOKEN and the Feishu webhook.
CLAUDE_CODE_SUBPROCESS_ENV_SCRUB: '0'
steps:
# The triggering revision is already on main, so its rules and code are trusted.
- uses: actions/checkout@v7
with:
ref: ${{ github.event.workflow_run.head_sha }}
fetch-depth: 2
persist-credentials: false
- name: Review and send Feishu card with Claude Code
# Notification is best effort: a failed review or delivery never fails the job.
continue-on-error: true
timeout-minutes: 25
uses: anthropics/claude-code-action@12dd8d74c712f5f3669365b2369b558c495b1104 # v1
env:
FEISHU_WEBHOOK_URL: ${{ secrets.FEISHU_WEBHOOK_URL }}
FEISHU_WEBHOOK_SECRET: ${{ secrets.FEISHU_WEBHOOK_SECRET }}
ANTHROPIC_BASE_URL: https://api.minimax.cn/anthropic
ANTHROPIC_AUTH_TOKEN: ${{ secrets.MINIMAX_API_KEY }}
CLAUDE_CODE_AUTO_COMPACT_WINDOW: '524288'
ANTHROPIC_MODEL: MiniMax-M3.1-Flash-Preview[1m]
ANTHROPIC_DEFAULT_SONNET_MODEL: MiniMax-M3.1-Flash-Preview[1m]
ANTHROPIC_DEFAULT_OPUS_MODEL: MiniMax-M3.1-Flash-Preview[1m]
ANTHROPIC_DEFAULT_HAIKU_MODEL: MiniMax-M3.1-Flash-Preview[1m]
with:
anthropic_api_key: ${{ secrets.MINIMAX_API_KEY }}
# The action also exports this token as GH_TOKEN, so gh works inside Claude.
github_token: ${{ github.token }}
display_report: true
show_full_output: true
allowed_bots: '*'
allowed_non_write_users: '*'
prompt: |
你是 CI 的负责人,负责审核 CI 结果并给出结论。
仓库 ${{ github.repository }} 的 main 分支刚跑完一次 core-check CI:
- 运行 ID:${{ github.event.workflow_run.id }}(第 ${{ github.event.workflow_run.run_attempt }} 次尝试)
- 结论:${{ github.event.workflow_run.conclusion }}
- 运行链接:${{ github.event.workflow_run.html_url }}
- commit:${{ github.event.workflow_run.head_sha }}(已 checkout 到当前目录)
任务:给飞书群发一张中文卡片(Card 2.0)总结这次 CI,尽量 10 轮以内给出结论,工具调用尽可能的并行。
环境里有 gh(已登录,GH_TOKEN)、git、node 和完整的仓库代码。
如果这个 commit 不是某个 PR 合入 main 产生的(例如直接 push),不发卡片,直接结束。
卡片要让手机上的读者快速看懂,如果一切正常,表达的尽可能简单:
1. 哪个 PR(github id + PR 标题 + 链接)
2. 改了什么(实际行为变化,1–3 条)
3. 是否符合仓库规则(AGENTS.md、CONTRIBUTING.md 及相关文档):未发现明确违规 / 发现需修复问题 / 信息不足,无法确认
4. CI 哪里失败、可能的原因(可以看日志),全部通过就直接说通过,不要给出细节。如果 CI 失败,则详细说明。
发送:webhook 地址在环境变量 FEISHU_WEBHOOK_URL。
响应 code=0 才算成功,失败就排查并重试,直到发出去。最后用一句中文说明结果。
不要在输出里打印 webhook 地址和密钥。
claude_args: >-
--allowedTools Bash Read Write Edit Glob Grep WebFetch WebSearch
--max-turns 100