Let Claude compose and send readable Feishu CI cards - #361
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CI notices currently flatten a long report into a fixed card and obscure the PR, actual changes, compliance conclusion and failed nodes. Replace that design with natural-language instructions for Claude to generate a readable Feishu Card 2.0 and POST it itself through Bash/Node.
The prompt prioritizes the PR link, 1–3 behavior-change bullets, evidence-backed compliance findings and failed job/step links. It omits routine skips and successful-job inventories, requires short mobile-readable content, and treats missing context as uncertainty rather than a violation. Collection now supplies associated PR metadata and bounded source context at the recorded revision.
The workflow has no independent sender or scripted fallback. Claude reads the webhook/signing secret from its step environment, signs if configured, sends the card, and confirms the response. A small final check fails the workflow unless Claude returns sent=true. The prompt prohibits retrying ambiguous requests. Existing bot and non-write actor allowances are preserved so completed external-contributor CI still receives a notification. Source remains untrusted data in the prompt, the checkout is trusted, the GitHub token remains read-only, and the only enabled tool is Bash with Node permission for delivery. All implementation remains in
ci-review.yml.Validation:
make check-ci check-docs check-names, actionlint 1.7.12 and whitespace checks passed. Inline checks covered PR association, immutable comparison, source context, failure filtering and delivery-result validation. Tool arguments were verified with the pinned Action's actual parser. Live model generation and Feishu posting remain unverified and require a configured workflow run.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.