Skip to content

Let @claude follow up on PRs that Claude opened - #391

Merged
ddaspit merged 1 commit into
mainfrom
ddaspit/claude-follow-up-bot-prs
Oct 1, 2026
Merged

ddaspit merged 1 commit into
mainfrom
ddaspit/claude-follow-up-bot-prs

Conversation

@ddaspit

@ddaspit ddaspit commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Quick summary

A member's @claude comment on a PR that Claude opened now runs the workflow. It used to be skipped. The commenter must still be an owner, member or collaborator.

Where to look

The job checks the author of the issue or PR as well as the commenter. claude[bot] has the association NONE, so the run for my comment on #390 was skipped. The check now also passes when the issue or PR was opened by claude[bot].

The check trusts the claude[bot] login, not where the branch lives. For comment events, GitHub does not include the PR's head repo in the event data, so the condition cannot check it. I do not think an outsider can get the bot to open a PR here from a fork, but I have not confirmed it. The action's own write-access check on the commenter still runs.

Validation

  • Parsed .github/workflows/claude.yml with PyYAML and printed the job's if. It parsed.
  • git diff --check -- clean.
  • I did not run ./local_check.sh. This PR only changes a workflow file.
  • The fix can only be verified by running the workflow. Mentioning @claude on Convert USFM versification before updating from rows #390 again after this is merged will confirm it.

🤖 Generated with Claude Code


This change is Reviewable

@codecov-commenter

codecov-commenter commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.07%. Comparing base (56f5347) to head (8e7926d).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #391   +/-   ##
=======================================
  Coverage   92.07%   92.07%           
=======================================
  Files         394      394           
  Lines       24896    24896           
=======================================
  Hits        22922    22922           
  Misses       1974     1974           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Comment thread .github/workflows/claude.yml
@claude

This comment has been minimized.

The job only ran when the issue or PR author was an owner, member or
collaborator. The bot's association is NONE, so a member's @claude comment on
a PR Claude opened was skipped, as on #390. PRs authored by claude[bot] now
pass that check. The commenter must still be a member.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ddaspit
ddaspit force-pushed the ddaspit/claude-follow-up-bot-prs branch from 4a97632 to 8e7926d Compare October 1, 2026 17:01
Comment thread .github/workflows/claude.yml
Comment thread .github/workflows/claude.yml
@claude

claude Bot commented Oct 1, 2026

Copy link
Copy Markdown
  1. Verdict: approve.
  2. Most important: F2 (Low). The claude[bot] bypass also passes plain issues Claude opened, not just its PRs as the comment says (.github/workflows/claude.yml:28).
  3. Counts: 0 Critical, 0 Important, 2 new Low (F2, F3), 1 earlier Low (F1).
  4. Ran gh api .../compare/4a97632...8e7926d, which printed diverged, so I reviewed the whole PR again. The claude.yml patch at 4a97632 and at head are identical: this was a rebase onto 56f5347. Ran /code-review high 391, which returned 5 candidates. I kept 2. I dropped one that said Claude-authored branches launder injected issue comments, because the first run on the issue already exposes those comments with the same token, so this PR adds no new exposure. I dropped two that were speculative about future config: the hard-coded login if the auth app changes, and the association moving off NONE. I counted the comment block with a script: 297 characters now, 176 before. Read claude-code-review.yml: it runs only on in-repo PRs, which limits who can make claude[bot] author anything.
  5. Not verified: whether claude[bot] has ever filed an issue here (gh issue list --author app/claude needed approval), whether an outsider fork PR can be authored as claude[bot] (F1), and the workflow run itself. I did not run ./local_check.sh because the PR changes only a workflow file.

Public API, optional dependency, wheel surface, sillsdev/machine parity: None verified (CI workflow only).

Findings: F1 open (thread resolved without a reply, code unchanged by the rebase), unverified. F2 new, unverified. F3 new.

Reviewed at 8e7926d

@ddaspit
ddaspit merged commit 785fbcb into main Oct 1, 2026
23 checks passed
@ddaspit
ddaspit deleted the ddaspit/claude-follow-up-bot-prs branch October 1, 2026 17:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants