feat(ci): comment-triggered PR fix-ups via @claude
PR Checks / Frontend Typecheck + Tests (pull_request) Successful in 9m41s
PR Checks / Backend Smoke (pull_request) Successful in 5s
PR Checks / Build Backend (no push) (pull_request) Successful in 16s
PR Checks / Build Frontend (no push) (pull_request) Successful in 47s
PR Checks / Build Pipeline (no push) (pull_request) Successful in 10s
PR Checks / AI Code Review (Claude) (pull_request) Failing after 2m30s
PR Checks / Frontend Typecheck + Tests (pull_request) Successful in 9m41s
PR Checks / Backend Smoke (pull_request) Successful in 5s
PR Checks / Build Backend (no push) (pull_request) Successful in 16s
PR Checks / Build Frontend (no push) (pull_request) Successful in 47s
PR Checks / Build Pipeline (no push) (pull_request) Successful in 10s
PR Checks / AI Code Review (Claude) (pull_request) Failing after 2m30s
Commenting '@claude <instruction>' on a PR runs headless Claude Code on the PR branch (subscription auth), pushes the resulting commit — re-running the PR checks — and replies with a summary. Owner-only trigger; runs unsandboxed inside the ephemeral runner container per explicit maintainer sign-off. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PqGhF93UrpDNvXBLMjJENL
This commit is contained in:
@@ -130,3 +130,21 @@ token Gitea Actions provides automatically (`secrets.GITEA_TOKEN` — no setup
|
||||
needed), and fails the check only when a finding is rated
|
||||
**severe** (would break prod, leak data, or corrupt data). Minor findings are
|
||||
informational and never block a merge.
|
||||
|
||||
## Comment-triggered fix-ups (@claude)
|
||||
|
||||
Comment `@claude <instruction>` on any PR and `.gitea/workflows/pr-comment.yml`
|
||||
runs `scripts/ci/ai_fixup.py`: it checks out the PR branch, hands the
|
||||
instruction to headless Claude Code (same subscription auth as the reviewer),
|
||||
commits and pushes whatever changed, and replies on the PR with a summary.
|
||||
The push re-runs the PR checks automatically.
|
||||
|
||||
Guard rails:
|
||||
- Only comments from the **repo owner** trigger it (the job pushes code).
|
||||
- Only comments starting with `@claude` — the bot's own replies never re-trigger.
|
||||
- Each comment is one full agentic session on the Claude subscription; batch
|
||||
related asks into one comment rather than several small ones.
|
||||
|
||||
Caveat: if the checks don't re-run after the bot's push, Gitea is suppressing
|
||||
workflows for pushes made with the run token — create a personal access token
|
||||
secret and swap it in for the push, or re-run the checks manually.
|
||||
|
||||
Reference in New Issue
Block a user