feat: configure Claude GitHub Action with permissions and restrictions

- Add write permissions for contents, pull-requests, and issues
- Configure allowed tools for pnpm, git, gh CLI, and file operations
- Restrict Claude activation to repository owner (heyitsnoah) only
- Update init-bootstrap to ask about development work
  - Personal vault users: Remove .github folder and disconnect from origin
  - Contributors: Keep GitHub workflows and origin for development
- Prevents personal vault users from seeing confusing GitHub Actions failures
This commit is contained in:
Noah Brier
2025-09-14 16:06:49 -04:00
parent 537b699498
commit 94869b6b04
2 changed files with 61 additions and 13 deletions
+21 -4
View File
@@ -32,7 +32,9 @@ Then generate a customized CLAUDE.md file tailored to their needs.
- Verify core dependencies are installed
- Check git status:
- If no .git folder: Initialize git repository
- If has remote origin: Remove it to disconnect from claudesidian
- If has remote origin: Ask about development work
- Personal vault: Remove origin and .github folder
- Contributing: Keep origin and workflows intact
- If clean local repo: Ready to go
- Don't create folders yet - wait until after asking about organization method
@@ -330,9 +332,24 @@ Now setting up your environment...
[Installs dependencies with pnpm/npm]
*Why: These tools enable Claude Code to work with your vault effectively*
🔓 **Disconnecting from Original Repository**
[Removes git remote to disconnect from original]
*Why: This ensures you won't accidentally push your personal notes to the public repo*
🔓 **Repository Setup**
**Will you be contributing to claudesidian development?**
- **No** (Personal vault only) → I'll remove GitHub workflows and disconnect from the repo
- **Yes** (I want to contribute) → I'll keep the development setup intact
[Implementation:]
```bash
# If user says "No" (personal vault):
rm -rf .github # Remove GitHub workflows
git remote remove origin # Disconnect from claudesidian repo
# If user says "Yes" (contributing):
# Keep .github folder and origin remote
echo "Development setup preserved for contributing"
```
*Why: Personal vaults don't need GitHub Actions, but contributors benefit from the automation*
📂 **Creating Folder Structure**
[Creates folders based on your chosen organization method]
+40 -9
View File
@@ -13,17 +13,20 @@ on:
jobs:
claude:
if: |
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
(github.actor == 'heyitsnoah' || github.actor == 'dependabot[bot]') &&
(
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
)
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: read
issues: read
contents: write # Allow Claude to push changes
pull-requests: write # Allow Claude to create/modify PRs
issues: write # Allow Claude to create/update issues
id-token: write
actions: read # Required for Claude to read CI results on PRs
actions: read # Required for Claude to read CI results on PRs
steps:
- name: Checkout repository
uses: actions/checkout@v4
@@ -40,11 +43,39 @@ jobs:
additional_permissions: |
actions: read
# Allow Claude to run specific tools and commands
allowed_tools: |
Bash(pnpm install)
Bash(pnpm setup)
Bash(pnpm attachments:*)
Bash(pnpm vault:stats)
Bash(pnpm check-updates)
Bash(npm run *)
Bash(git status)
Bash(git diff *)
Bash(git log *)
Bash(git add *)
Bash(git commit *)
Bash(git push)
Bash(gh pr *)
Bash(gh issue *)
Bash(ls *)
Bash(cat *)
Bash(grep *)
Bash(find *)
View
GlobTool
GrepTool
BatchTool
Read
Write
Edit
# Optional: Give a custom prompt to Claude. If this is not specified, Claude will perform the instructions specified in the comment that tagged it.
# prompt: 'Update the pull request description to include a summary of changes.'
# Optional: Add claude_args to customize behavior and configuration
# See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md
# or https://docs.anthropic.com/en/docs/claude-code/sdk#command-line for available options
# claude_args: '--model claude-opus-4-1-20250805 --allowed-tools Bash(gh pr:*)'
# claude_args: '--model claude-opus-4-1-20250805'