diff --git a/.github/workflows/claude-code-review.yml b/.github/workflows/claude-code-review.yml deleted file mode 100644 index b29f060..0000000 --- a/.github/workflows/claude-code-review.yml +++ /dev/null @@ -1,157 +0,0 @@ -name: Claude Code Review - -# Posts an automated review on every pull request. Reads only -- it never -# builds, tests, or pushes. `ci.yml` and `e2e.yml` own the gates. -on: - pull_request: - types: [opened, synchronize, ready_for_review, reopened] - # Deliberately no `branches:` filter, unlike ci.yml: a PR stacked onto another - # feature branch deserves a review too. - # - # Only what can carry a defect. Docs-only changes (README.md, CHANGELOG.md, - # docs/**) are skipped. CLAUDE.md is kept because it is the rulebook the - # review enforces. For pull_request events GitHub matches these against the - # whole PR diff, not just the latest push. - paths: - - "src/**" - - "tests/**" - - "Cargo.toml" - - "Cargo.lock" - - "rust-toolchain.toml" - - "scripts/**" - - "npm/**" - - "installer/**" - - ".github/**" - - "CLAUDE.md" - -jobs: - claude-review: - # Two kinds of PR cannot run this job, so skip them instead of failing red: - # - Forks. This repository is public, and a fork's pull_request run gets no - # secrets and a read-only token, so the review could neither authenticate - # nor post. - # - Dependabot. Its runs read Dependabot secrets, not Actions secrets, and - # the action refuses a bot actor unless `allowed_bots` names it. - if: | - github.event.pull_request.head.repo.full_name == github.repository && - github.actor != 'dependabot[bot]' - runs-on: ubuntu-latest - permissions: - contents: read - # write, not read: the review posts inline comments back onto the PR. - pull-requests: write - issues: write - # gh pr view reads statusCheckRollup, which 403s without this. - checks: read - id-token: write - - steps: - - name: Checkout repository - uses: actions/checkout@v4 - with: - fetch-depth: 1 - - - name: Run Claude Code Review - id: claude-review - uses: anthropics/claude-code-action@v1 - with: - claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }} - # Deliberately not the code-review plugin. It delegates each step to sub-agents, and - # the Agent tool here is async: it yields for a notification that a single-shot CI run - # never delivers. Denied that, it burns turns shelling out instead. A direct prompt is - # single-shot by construction. - prompt: | - Review pull request ${{ github.event.pull_request.number }} in ${{ github.repository }}. - - This is `bugsee-cli`: a single cross-platform Rust binary (macOS, Linux, Windows) that - uploads debug symbols and build metadata to Bugsee. External integrators (the Android - Gradle plugin, the iOS SDK and fastlane agents, the worker and appserver) shell to it - and parse what it prints, so its observable behaviour is a public contract. - - Read the diff with `gh pr diff ${{ github.event.pull_request.number }}`. Read - `CLAUDE.md` at the repository root, which is binding for every file here, and read the - surrounding code where you need context. Do not build, run cargo or - scripts/e2e_flows.py, lint, or modify the checkout — CI covers that separately. - - Report only what you are confident is a real problem in the lines this PR changed: - - - `--help` drift: a command, subcommand, positional, option/flag or value-enum variant - added or changed without its `///` clap doc comment updated in the same change, an - empty description, or environment-variable behaviour missing from the command's - `after_help` / `after_long_help`. - - stdout purity: anything written to stdout outside a command's defined - machine-readable output (a `println!`/`print!`, or logging not routed through - `tracing` to stderr). The integrators parse stdout with `json.loads`. - - Exit codes (`src/exit_code.rs`): a code whose meaning changes or is repurposed, or an - error that should map to a specific code but is a bare `anyhow::anyhow!` (which - falls through to exit 1) instead of a typed `error::Error`. - - Wire shapes: a changed field name, casing, type, or null-vs-omit rule in a command's - stdout JSON, the upload ZIP layout or compression, the registration POST body, or a - bundle entry name — each a breaking change needing a major version bump. - - Cargo.toml table ordering: a `[target.'cfg(unix)'.dependencies]` (or any `[table]` - header) placed where TOML silently absorbs the keys after it — e.g. mid- - `[dependencies]`, which moves every later dependency under `cfg(unix)` so it vanishes - on Windows while the native build stays green. The same hazard applies inside - `[workspace.metadata.dist]`. - - MSRV drift: `rust-version` in Cargo.toml is the floor, but the toolchain and CI both - build `stable`, so nothing else catches it. Flag a std/language feature or a - dependency bump that needs a newer Rust than the declared `rust-version` without - raising it in the same change. Check the real stabilization or MSRV rather than - trusting memory. - - Daemonizing (`src/daemon.rs`, `main`): the double-fork must happen before ANY thread - or the tokio runtime exists — forking a live multi-threaded runtime is undefined - behaviour. `should_daemonize` must copy EVERY environment variable that - `resolve_upload_dsyms_mode` reads. - - Cross-platform: Unix-only APIs or path assumptions without a `cfg` guard, which break - the Windows build or Windows behaviour. - - Network I/O that bypasses `upload::http` (its one client, retry/backoff, and the - `X-Bugsee-Uploader` header). - - `.github/workflows/release.yml` is generated by cargo-dist: flag a hand edit beyond - the action pins dependabot manages, or a dist-config change in Cargo.toml that - assumes the file regenerates itself. - - Async and concurrency errors: blocking I/O on a runtime thread, a lock held across - `.await`, races on shared state, and panics (`unwrap`, indexing) on input from - disk, the environment, or the network. - - Broken contracts and violations of a CLAUDE.md rule you can quote. - - Skip nitpicks, formatting and style, missing tests, and anything rustc, clippy - (run with `-D warnings`) or rustfmt catches. Pre-existing issues are out of scope. - - Post the review in two parts. - - 1. One INLINE comment per finding, on the line it is about, using the - mcp__github_inline_comment__create_inline_comment tool. Each one says what is wrong - and why it matters, and proposes the concrete change. Keep it to a few sentences — - the reasoning that does not fit belongs in the summary. Only comment on lines this - PR actually changed; GitHub rejects the rest. - - 2. Then exactly ONE summary comment on the conversation, with - `gh pr comment ${{ github.event.pull_request.number }} --body "..."`. This is the - part a reviewer reads first: what the change does, whether it is sound, what the - findings add up to, and what you recommend. Do not repeat the inline comments — - reference them. - - ALWAYS post the summary, even with nothing to report — a silent run is - indistinguishable from a broken one. Use this shape: - - ### Code review - - - - **Findings:** N inline (M blocking) — or "None." - - - - claude_args: >- - --allowedTools - "Read,Grep,Glob,Bash,mcp__github_inline_comment__create_inline_comment" - # --allowedTools REPLACES the default tool list rather than adding to it, so every - # tool the prompt needs has to be named here. - - # No `show_full_output: true`, unlike bugsee-cocoa. It prints the full agent transcript - # into the job log, which cocoa accepts only because its Actions logs are - # collaborator-only and says to drop if the repository goes public. This repository IS - # public, so its logs are world-readable. To debug a silent run, enable it on a - # short-lived branch and remove it again. - # See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md - # or https://code.claude.com/docs/en/cli-reference for available options diff --git a/.github/workflows/claude.yml b/.github/workflows/claude.yml index 32dbaf3..cf28236 100644 --- a/.github/workflows/claude.yml +++ b/.github/workflows/claude.yml @@ -1,7 +1,6 @@ name: Claude Code # Answers an `@claude` mention on an issue, a PR, a PR review, or a review -# comment. The automatic per-PR review lives in claude-code-review.yml. on: issue_comment: types: [created]