feat: configure Claude GitHub Action with permissions and restrictions
- Add write permissions for contents, pull-requests, and issues - Configure allowed tools for pnpm, git, gh CLI, and file operations - Restrict Claude activation to repository owner (heyitsnoah) only - Update init-bootstrap to ask about development work - Personal vault users: Remove .github folder and disconnect from origin - Contributors: Keep GitHub workflows and origin for development - Prevents personal vault users from seeing confusing GitHub Actions failures
This commit is contained in:
@@ -32,7 +32,9 @@ Then generate a customized CLAUDE.md file tailored to their needs.
|
||||
- Verify core dependencies are installed
|
||||
- Check git status:
|
||||
- If no .git folder: Initialize git repository
|
||||
- If has remote origin: Remove it to disconnect from claudesidian
|
||||
- If has remote origin: Ask about development work
|
||||
- Personal vault: Remove origin and .github folder
|
||||
- Contributing: Keep origin and workflows intact
|
||||
- If clean local repo: Ready to go
|
||||
- Don't create folders yet - wait until after asking about organization method
|
||||
|
||||
@@ -330,9 +332,24 @@ Now setting up your environment...
|
||||
[Installs dependencies with pnpm/npm]
|
||||
*Why: These tools enable Claude Code to work with your vault effectively*
|
||||
|
||||
🔓 **Disconnecting from Original Repository**
|
||||
[Removes git remote to disconnect from original]
|
||||
*Why: This ensures you won't accidentally push your personal notes to the public repo*
|
||||
🔓 **Repository Setup**
|
||||
|
||||
**Will you be contributing to claudesidian development?**
|
||||
- **No** (Personal vault only) → I'll remove GitHub workflows and disconnect from the repo
|
||||
- **Yes** (I want to contribute) → I'll keep the development setup intact
|
||||
|
||||
[Implementation:]
|
||||
```bash
|
||||
# If user says "No" (personal vault):
|
||||
rm -rf .github # Remove GitHub workflows
|
||||
git remote remove origin # Disconnect from claudesidian repo
|
||||
|
||||
# If user says "Yes" (contributing):
|
||||
# Keep .github folder and origin remote
|
||||
echo "Development setup preserved for contributing"
|
||||
```
|
||||
|
||||
*Why: Personal vaults don't need GitHub Actions, but contributors benefit from the automation*
|
||||
|
||||
📂 **Creating Folder Structure**
|
||||
[Creates folders based on your chosen organization method]
|
||||
|
||||
@@ -13,17 +13,20 @@ on:
|
||||
jobs:
|
||||
claude:
|
||||
if: |
|
||||
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
|
||||
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
|
||||
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
|
||||
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
|
||||
(github.actor == 'heyitsnoah' || github.actor == 'dependabot[bot]') &&
|
||||
(
|
||||
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
|
||||
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
|
||||
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
|
||||
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
|
||||
)
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: read
|
||||
pull-requests: read
|
||||
issues: read
|
||||
contents: write # Allow Claude to push changes
|
||||
pull-requests: write # Allow Claude to create/modify PRs
|
||||
issues: write # Allow Claude to create/update issues
|
||||
id-token: write
|
||||
actions: read # Required for Claude to read CI results on PRs
|
||||
actions: read # Required for Claude to read CI results on PRs
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@v4
|
||||
@@ -40,11 +43,39 @@ jobs:
|
||||
additional_permissions: |
|
||||
actions: read
|
||||
|
||||
# Allow Claude to run specific tools and commands
|
||||
allowed_tools: |
|
||||
Bash(pnpm install)
|
||||
Bash(pnpm setup)
|
||||
Bash(pnpm attachments:*)
|
||||
Bash(pnpm vault:stats)
|
||||
Bash(pnpm check-updates)
|
||||
Bash(npm run *)
|
||||
Bash(git status)
|
||||
Bash(git diff *)
|
||||
Bash(git log *)
|
||||
Bash(git add *)
|
||||
Bash(git commit *)
|
||||
Bash(git push)
|
||||
Bash(gh pr *)
|
||||
Bash(gh issue *)
|
||||
Bash(ls *)
|
||||
Bash(cat *)
|
||||
Bash(grep *)
|
||||
Bash(find *)
|
||||
View
|
||||
GlobTool
|
||||
GrepTool
|
||||
BatchTool
|
||||
Read
|
||||
Write
|
||||
Edit
|
||||
|
||||
# Optional: Give a custom prompt to Claude. If this is not specified, Claude will perform the instructions specified in the comment that tagged it.
|
||||
# prompt: 'Update the pull request description to include a summary of changes.'
|
||||
|
||||
# Optional: Add claude_args to customize behavior and configuration
|
||||
# See https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md
|
||||
# or https://docs.anthropic.com/en/docs/claude-code/sdk#command-line for available options
|
||||
# claude_args: '--model claude-opus-4-1-20250805 --allowed-tools Bash(gh pr:*)'
|
||||
# claude_args: '--model claude-opus-4-1-20250805'
|
||||
|
||||
|
||||
Reference in New Issue
Block a user