diff --git a/.github/workflows/claude-review.yml b/.github/workflows/claude-review.yml index 61cf6a9..17de613 100644 --- a/.github/workflows/claude-review.yml +++ b/.github/workflows/claude-review.yml @@ -94,8 +94,11 @@ jobs: EXCEPTIONS — never delete: - the tracking comment for THIS run (the one you update via update_claude_comment) - any comment containing "claude-pr-feedback-round" (round-limit markers used by the feedback workflow) - 4. Dismiss any previous formal review from github-actions[bot] on this PR. - 5. Resolve any outdated inline review comment threads from previous reviews. + 4. Dismiss any previous formal review from github-actions[bot] on this PR. List them with: + gh api repos/${{ github.repository }}/pulls/${{ github.event.pull_request.number }}/reviews --jq '.[] | select(.user.login == "github-actions[bot]" and (.state == "APPROVED" or .state == "CHANGES_REQUESTED")) | .id' + and dismiss each with: + gh api repos/${{ github.repository }}/pulls/${{ github.event.pull_request.number }}/reviews//dismissals -X PUT -f message="Superseded by a newer automated review" + 5. Best effort only: try to resolve outdated inline review comment threads from previous reviews with `gh api graphql` (resolveReviewThread mutation). The workflow token is often refused on that mutation; if it fails, move on without reporting it as a problem. **Now review the pull request:** @@ -110,13 +113,23 @@ jobs: Leave inline comments on specific lines and a top-level summary. Skip nitpicks; prioritize substantive feedback. - **When you are done, submit a GitHub review using one of:** - - `gh pr review ${{ github.event.pull_request.number }} --approve --body "..."` — if no substantive issues found - - `gh pr review ${{ github.event.pull_request.number }} --request-changes --body "..."` — if there are blocking problems + **When you are done, submit a formal GitHub review.** Prefer the MCP tool + `mcp__github__create_and_submit_pull_request_review` (owner/repo/pullNumber from + the header above) with event `APPROVE` if no substantive issues were found, or + `REQUEST_CHANGES` if there are blocking problems. `gh pr review ${{ github.event.pull_request.number }} --approve|--request-changes --body "..."` + is the fallback if the MCP tool is unavailable. Do not leave a PR without a formal APPROVE or REQUEST_CHANGES state. + # Bash rule shapes matter here. Claude Code only treats `:*` as a + # wildcard on an otherwise-literal prefix: a `*` earlier in the rule + # combined with a `:*` suffix never matches anything (verified on + # 2.1.258/2.1.261 — every `gh api repos/...` call was denied with "This + # command requires approval" while `gh pr view:*` worked). Rules with a + # mid-pattern `*` must use the trailing-space form (`... *`) instead. + # The `gh api` rules stay scoped to issues/pulls endpoints so the + # token's `actions: write` scope is still unreachable from the agent. claude_args: | - --model sonnet --allowedTools "mcp__github__pull_request_review_write,mcp__github__add_comment_to_pending_review,mcp__github__add_issue_comment,mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*),Bash(gh pr review:*),Bash(gh api repos/*/issues/*/comments:*),Bash(gh api repos/*/issues/comments/*:*),Bash(gh api repos/*/pulls/*/reviews:*),Bash(gh api repos/*/pulls/*/comments:*)" + --model sonnet --allowedTools "mcp__github__get_issue_comments,mcp__github__get_pull_request_reviews,mcp__github__get_pull_request_diff,mcp__github__create_and_submit_pull_request_review,mcp__github__create_pending_pull_request_review,mcp__github__add_comment_to_pending_review,mcp__github__submit_pending_pull_request_review,mcp__github__add_issue_comment,mcp__github_inline_comment__create_inline_comment,Bash(gh pr comment:*),Bash(gh pr diff:*),Bash(gh pr view:*),Bash(gh pr review:*),Bash(gh api graphql *),Bash(gh api repos/*/issues/*/comments *),Bash(gh api repos/*/issues/comments/* *),Bash(gh api repos/*/pulls/*/reviews *),Bash(gh api repos/*/pulls/*/reviews/*/dismissals *),Bash(gh api repos/*/pulls/*/comments *)" # Reviews from the default GITHUB_TOKEN raise no workflow events, so the # feedback loop must be kicked explicitly (see header). Deterministic step