From b0e66c2e64635cbfe26e8841f416c8725b0d2ef2 Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 1 Oct 2026 05:33:01 +0000 Subject: [PATCH] Run Claude Code Review only on PRs labelled claude-review The CLAUDE_CODE_OAUTH_TOKEN secret is revoked, so the job fails on every pull request. Make it opt-in: adding the claude-review label starts a review and later pushes re-run it; unlabelled PRs show it as skipped. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01TMXYMqgLAykqRApmbRfpTA --- .github/workflows/claude-code-review.yml | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml index b5e8cfd..c4ca087 100644 --- a/.github/workflows/claude-code-review.yml +++ b/.github/workflows/claude-code-review.yml @@ -1,8 +1,11 @@ name: Claude Code Review +# Opt-in: runs only on pull requests labelled "claude-review", so a missing +# or expired CLAUDE_CODE_OAUTH_TOKEN doesn't put a red check on every PR. +# Adding the label starts a review; later pushes to the PR re-run it. on: pull_request: - types: [opened, synchronize, ready_for_review, reopened] + types: [opened, synchronize, ready_for_review, reopened, labeled] # Optional: Only run on specific file changes # paths: # - "src/**/*.ts" @@ -12,8 +15,12 @@ on: jobs: claude-review: - # Optional: Filter by PR author - # if: | + if: >- + (github.event.action == 'labeled' + && github.event.label.name == 'claude-review') + || (github.event.action != 'labeled' + && contains(github.event.pull_request.labels.*.name, 'claude-review')) + # Optional: also filter by PR author by adding to the condition above, e.g. # github.event.pull_request.user.login == 'external-contributor' || # github.event.pull_request.user.login == 'new-developer' || # github.event.pull_request.author_association == 'FIRST_TIME_CONTRIBUTOR'