mirror of
https://github.com/anthropics/claude-code-action.git
synced 2026-01-24 07:24:12 +08:00
Compare commits
9 Commits
v1.0.23
...
inigo/add-
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
84265a4271 | ||
|
|
9d3bab5bc7 | ||
|
|
bf8f85ca9d | ||
|
|
f551cdf070 | ||
|
|
ec3a934da7 | ||
|
|
8cd2cc1236 | ||
|
|
dcee434ef2 | ||
|
|
e93583852d | ||
|
|
e600a516c7 |
2
.github/workflows/claude-review.yml
vendored
2
.github/workflows/claude-review.yml
vendored
@@ -2,7 +2,7 @@ name: PR Review
|
|||||||
|
|
||||||
on:
|
on:
|
||||||
pull_request:
|
pull_request:
|
||||||
types: [opened]
|
types: [opened, synchronize, ready_for_review, reopened]
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
review:
|
review:
|
||||||
|
|||||||
4
.github/workflows/sync-base-action.yml
vendored
4
.github/workflows/sync-base-action.yml
vendored
@@ -94,5 +94,5 @@ jobs:
|
|||||||
echo "✅ Successfully synced \`base-action\` directory to [anthropics/claude-code-base-action](https://github.com/anthropics/claude-code-base-action)" >> $GITHUB_STEP_SUMMARY
|
echo "✅ Successfully synced \`base-action\` directory to [anthropics/claude-code-base-action](https://github.com/anthropics/claude-code-base-action)" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "" >> $GITHUB_STEP_SUMMARY
|
echo "" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "- **Source commit**: [\`${GITHUB_SHA:0:7}\`](https://github.com/anthropics/claude-code-action/commit/${GITHUB_SHA})" >> $GITHUB_STEP_SUMMARY
|
echo "- **Source commit**: [\`${GITHUB_SHA:0:7}\`](https://github.com/anthropics/claude-code-action/commit/${GITHUB_SHA})" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "- **Triggered by**: $GITHUB_EVENT_NAME" >> $GITHUB_STEP_SUMMARY
|
echo "- **Triggered by**: ${{ github.event_name }}" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "- **Actor**: @$GITHUB_ACTOR" >> $GITHUB_STEP_SUMMARY
|
echo "- **Actor**: @${{ github.actor }}" >> $GITHUB_STEP_SUMMARY
|
||||||
|
|||||||
58
.github/workflows/test-base-action.yml
vendored
58
.github/workflows/test-base-action.yml
vendored
@@ -118,61 +118,3 @@ jobs:
|
|||||||
echo "❌ Execution log file not found"
|
echo "❌ Execution log file not found"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
test-agent-sdk:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
|
|
||||||
|
|
||||||
- name: Test with Agent SDK
|
|
||||||
id: sdk-test
|
|
||||||
uses: ./base-action
|
|
||||||
env:
|
|
||||||
USE_AGENT_SDK: "true"
|
|
||||||
with:
|
|
||||||
prompt: ${{ github.event.inputs.test_prompt || 'List the files in the current directory starting with "package"' }}
|
|
||||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
|
||||||
allowed_tools: "LS,Read"
|
|
||||||
|
|
||||||
- name: Verify SDK output
|
|
||||||
run: |
|
|
||||||
OUTPUT_FILE="${{ steps.sdk-test.outputs.execution_file }}"
|
|
||||||
CONCLUSION="${{ steps.sdk-test.outputs.conclusion }}"
|
|
||||||
|
|
||||||
echo "Conclusion: $CONCLUSION"
|
|
||||||
echo "Output file: $OUTPUT_FILE"
|
|
||||||
|
|
||||||
if [ "$CONCLUSION" = "success" ]; then
|
|
||||||
echo "✅ Action completed successfully with Agent SDK"
|
|
||||||
else
|
|
||||||
echo "❌ Action failed with Agent SDK"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ -f "$OUTPUT_FILE" ]; then
|
|
||||||
if [ -s "$OUTPUT_FILE" ]; then
|
|
||||||
echo "✅ Execution log file created successfully with content"
|
|
||||||
echo "Validating JSON format:"
|
|
||||||
if jq . "$OUTPUT_FILE" > /dev/null 2>&1; then
|
|
||||||
echo "✅ Output is valid JSON"
|
|
||||||
# Verify SDK output contains total_cost_usd (SDK field name)
|
|
||||||
if jq -e '.[] | select(.type == "result") | .total_cost_usd' "$OUTPUT_FILE" > /dev/null 2>&1; then
|
|
||||||
echo "✅ SDK output contains total_cost_usd field"
|
|
||||||
else
|
|
||||||
echo "❌ SDK output missing total_cost_usd field"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
echo "Content preview:"
|
|
||||||
head -c 500 "$OUTPUT_FILE"
|
|
||||||
else
|
|
||||||
echo "❌ Output is not valid JSON"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
else
|
|
||||||
echo "❌ Execution log file is empty"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
else
|
|
||||||
echo "❌ Execution log file not found"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|||||||
72
.github/workflows/test-structured-output.yml
vendored
72
.github/workflows/test-structured-output.yml
vendored
@@ -30,10 +30,19 @@ jobs:
|
|||||||
- number_field: 42
|
- number_field: 42
|
||||||
- boolean_true: true
|
- boolean_true: true
|
||||||
- boolean_false: false
|
- boolean_false: false
|
||||||
|
json_schema: |
|
||||||
|
{
|
||||||
|
"type": "object",
|
||||||
|
"properties": {
|
||||||
|
"text_field": {"type": "string"},
|
||||||
|
"number_field": {"type": "number"},
|
||||||
|
"boolean_true": {"type": "boolean"},
|
||||||
|
"boolean_false": {"type": "boolean"}
|
||||||
|
},
|
||||||
|
"required": ["text_field", "number_field", "boolean_true", "boolean_false"]
|
||||||
|
}
|
||||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
claude_args: |
|
allowed_tools: "Bash"
|
||||||
--allowedTools Bash
|
|
||||||
--json-schema '{"type":"object","properties":{"text_field":{"type":"string"},"number_field":{"type":"number"},"boolean_true":{"type":"boolean"},"boolean_false":{"type":"boolean"}},"required":["text_field","number_field","boolean_true","boolean_false"]}'
|
|
||||||
|
|
||||||
- name: Verify outputs
|
- name: Verify outputs
|
||||||
run: |
|
run: |
|
||||||
@@ -88,10 +97,21 @@ jobs:
|
|||||||
- items: ["apple", "banana", "cherry"]
|
- items: ["apple", "banana", "cherry"]
|
||||||
- config: {"key": "value", "count": 3}
|
- config: {"key": "value", "count": 3}
|
||||||
- empty_array: []
|
- empty_array: []
|
||||||
|
json_schema: |
|
||||||
|
{
|
||||||
|
"type": "object",
|
||||||
|
"properties": {
|
||||||
|
"items": {
|
||||||
|
"type": "array",
|
||||||
|
"items": {"type": "string"}
|
||||||
|
},
|
||||||
|
"config": {"type": "object"},
|
||||||
|
"empty_array": {"type": "array"}
|
||||||
|
},
|
||||||
|
"required": ["items", "config", "empty_array"]
|
||||||
|
}
|
||||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
claude_args: |
|
allowed_tools: "Bash"
|
||||||
--allowedTools Bash
|
|
||||||
--json-schema '{"type":"object","properties":{"items":{"type":"array","items":{"type":"string"}},"config":{"type":"object"},"empty_array":{"type":"array"}},"required":["items","config","empty_array"]}'
|
|
||||||
|
|
||||||
- name: Verify JSON stringification
|
- name: Verify JSON stringification
|
||||||
run: |
|
run: |
|
||||||
@@ -140,10 +160,19 @@ jobs:
|
|||||||
- empty_string: ""
|
- empty_string: ""
|
||||||
- negative: -5
|
- negative: -5
|
||||||
- decimal: 3.14
|
- decimal: 3.14
|
||||||
|
json_schema: |
|
||||||
|
{
|
||||||
|
"type": "object",
|
||||||
|
"properties": {
|
||||||
|
"zero": {"type": "number"},
|
||||||
|
"empty_string": {"type": "string"},
|
||||||
|
"negative": {"type": "number"},
|
||||||
|
"decimal": {"type": "number"}
|
||||||
|
},
|
||||||
|
"required": ["zero", "empty_string", "negative", "decimal"]
|
||||||
|
}
|
||||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
claude_args: |
|
allowed_tools: "Bash"
|
||||||
--allowedTools Bash
|
|
||||||
--json-schema '{"type":"object","properties":{"zero":{"type":"number"},"empty_string":{"type":"string"},"negative":{"type":"number"},"decimal":{"type":"number"}},"required":["zero","empty_string","negative","decimal"]}'
|
|
||||||
|
|
||||||
- name: Verify edge cases
|
- name: Verify edge cases
|
||||||
run: |
|
run: |
|
||||||
@@ -194,10 +223,17 @@ jobs:
|
|||||||
prompt: |
|
prompt: |
|
||||||
Run: echo "test"
|
Run: echo "test"
|
||||||
Return EXACTLY: {test-result: "passed", item_count: 10}
|
Return EXACTLY: {test-result: "passed", item_count: 10}
|
||||||
|
json_schema: |
|
||||||
|
{
|
||||||
|
"type": "object",
|
||||||
|
"properties": {
|
||||||
|
"test-result": {"type": "string"},
|
||||||
|
"item_count": {"type": "number"}
|
||||||
|
},
|
||||||
|
"required": ["test-result", "item_count"]
|
||||||
|
}
|
||||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
claude_args: |
|
allowed_tools: "Bash"
|
||||||
--allowedTools Bash
|
|
||||||
--json-schema '{"type":"object","properties":{"test-result":{"type":"string"},"item_count":{"type":"number"}},"required":["test-result","item_count"]}'
|
|
||||||
|
|
||||||
- name: Verify sanitized names work
|
- name: Verify sanitized names work
|
||||||
run: |
|
run: |
|
||||||
@@ -232,10 +268,16 @@ jobs:
|
|||||||
uses: ./base-action
|
uses: ./base-action
|
||||||
with:
|
with:
|
||||||
prompt: "Run: echo 'complete'. Return: {done: true}"
|
prompt: "Run: echo 'complete'. Return: {done: true}"
|
||||||
|
json_schema: |
|
||||||
|
{
|
||||||
|
"type": "object",
|
||||||
|
"properties": {
|
||||||
|
"done": {"type": "boolean"}
|
||||||
|
},
|
||||||
|
"required": ["done"]
|
||||||
|
}
|
||||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
claude_args: |
|
allowed_tools: "Bash"
|
||||||
--allowedTools Bash
|
|
||||||
--json-schema '{"type":"object","properties":{"done":{"type":"boolean"}},"required":["done"]}'
|
|
||||||
|
|
||||||
- name: Verify execution file contains structured_output
|
- name: Verify execution file contains structured_output
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
@@ -2,7 +2,7 @@
|
|||||||
|
|
||||||
# Claude Code Action
|
# Claude Code Action
|
||||||
|
|
||||||
A general-purpose [Claude Code](https://claude.ai/code) action for GitHub PRs and issues that can answer questions and implement code changes. This action intelligently detects when to activate based on your workflow context—whether responding to @claude mentions, issue assignments, or executing automation tasks with explicit prompts. It supports multiple authentication methods including Anthropic direct API, Amazon Bedrock, Google Vertex AI, and Microsoft Foundry.
|
A general-purpose [Claude Code](https://claude.ai/code) action for GitHub PRs and issues that can answer questions and implement code changes. This action intelligently detects when to activate based on your workflow context—whether responding to @claude mentions, issue assignments, or executing automation tasks with explicit prompts. It supports multiple authentication methods including Anthropic direct API, Amazon Bedrock, and Google Vertex AI.
|
||||||
|
|
||||||
## Features
|
## Features
|
||||||
|
|
||||||
@@ -30,7 +30,7 @@ This command will guide you through setting up the GitHub app and required secre
|
|||||||
**Note**:
|
**Note**:
|
||||||
|
|
||||||
- You must be a repository admin to install the GitHub app and add secrets
|
- You must be a repository admin to install the GitHub app and add secrets
|
||||||
- This quickstart method is only available for direct Anthropic API users. For AWS Bedrock, Google Vertex AI, or Microsoft Foundry setup, see [docs/cloud-providers.md](./docs/cloud-providers.md).
|
- This quickstart method is only available for direct Anthropic API users. For AWS Bedrock or Google Vertex AI setup, see [docs/cloud-providers.md](./docs/cloud-providers.md).
|
||||||
|
|
||||||
## 📚 Solutions & Use Cases
|
## 📚 Solutions & Use Cases
|
||||||
|
|
||||||
@@ -57,7 +57,7 @@ Each solution includes complete working examples, configuration details, and exp
|
|||||||
- [Custom Automations](./docs/custom-automations.md) - Examples of automated workflows and custom prompts
|
- [Custom Automations](./docs/custom-automations.md) - Examples of automated workflows and custom prompts
|
||||||
- [Configuration](./docs/configuration.md) - MCP servers, permissions, environment variables, and advanced settings
|
- [Configuration](./docs/configuration.md) - MCP servers, permissions, environment variables, and advanced settings
|
||||||
- [Experimental Features](./docs/experimental.md) - Execution modes and network restrictions
|
- [Experimental Features](./docs/experimental.md) - Execution modes and network restrictions
|
||||||
- [Cloud Providers](./docs/cloud-providers.md) - AWS Bedrock, Google Vertex AI, and Microsoft Foundry setup
|
- [Cloud Providers](./docs/cloud-providers.md) - AWS Bedrock and Google Vertex AI setup
|
||||||
- [Capabilities & Limitations](./docs/capabilities-and-limitations.md) - What Claude can and cannot do
|
- [Capabilities & Limitations](./docs/capabilities-and-limitations.md) - What Claude can and cannot do
|
||||||
- [Security](./docs/security.md) - Access control, permissions, and commit signing
|
- [Security](./docs/security.md) - Access control, permissions, and commit signing
|
||||||
- [FAQ](./docs/faq.md) - Common questions and troubleshooting
|
- [FAQ](./docs/faq.md) - Common questions and troubleshooting
|
||||||
|
|||||||
70
action.yml
70
action.yml
@@ -44,7 +44,7 @@ inputs:
|
|||||||
|
|
||||||
# Auth configuration
|
# Auth configuration
|
||||||
anthropic_api_key:
|
anthropic_api_key:
|
||||||
description: "Anthropic API key (required for direct API, not needed for Bedrock/Vertex/Foundry)"
|
description: "Anthropic API key (required for direct API, not needed for Bedrock/Vertex)"
|
||||||
required: false
|
required: false
|
||||||
claude_code_oauth_token:
|
claude_code_oauth_token:
|
||||||
description: "Claude Code OAuth token (alternative to anthropic_api_key)"
|
description: "Claude Code OAuth token (alternative to anthropic_api_key)"
|
||||||
@@ -60,10 +60,6 @@ inputs:
|
|||||||
description: "Use Google Vertex AI with OIDC authentication instead of direct Anthropic API"
|
description: "Use Google Vertex AI with OIDC authentication instead of direct Anthropic API"
|
||||||
required: false
|
required: false
|
||||||
default: "false"
|
default: "false"
|
||||||
use_foundry:
|
|
||||||
description: "Use Microsoft Foundry with OIDC authentication instead of direct Anthropic API"
|
|
||||||
required: false
|
|
||||||
default: "false"
|
|
||||||
|
|
||||||
claude_args:
|
claude_args:
|
||||||
description: "Additional arguments to pass directly to Claude CLI"
|
description: "Additional arguments to pass directly to Claude CLI"
|
||||||
@@ -93,6 +89,10 @@ inputs:
|
|||||||
description: "Force tag mode with tracking comments for pull_request and issue events. Only applicable to pull_request (opened, synchronize, ready_for_review, reopened) and issue (opened, edited, labeled, assigned) events."
|
description: "Force tag mode with tracking comments for pull_request and issue events. Only applicable to pull_request (opened, synchronize, ready_for_review, reopened) and issue (opened, edited, labeled, assigned) events."
|
||||||
required: false
|
required: false
|
||||||
default: "false"
|
default: "false"
|
||||||
|
experimental_allowed_domains:
|
||||||
|
description: "Restrict network access to these domains only (newline-separated). If not set, no restrictions are applied. Provider domains are auto-detected."
|
||||||
|
required: false
|
||||||
|
default: ""
|
||||||
path_to_claude_code_executable:
|
path_to_claude_code_executable:
|
||||||
description: "Optional path to a custom Claude Code executable. If provided, skips automatic installation and uses this executable instead. WARNING: Using an older version may cause problems if the action begins taking advantage of new Claude Code features. This input is typically not needed unless you're debugging something specific or have unique needs in your environment."
|
description: "Optional path to a custom Claude Code executable. If provided, skips automatic installation and uses this executable instead. WARNING: Using an older version may cause problems if the action begins taking advantage of new Claude Code features. This input is typically not needed unless you're debugging something specific or have unique needs in your environment."
|
||||||
required: false
|
required: false
|
||||||
@@ -113,6 +113,10 @@ inputs:
|
|||||||
description: "Newline-separated list of Claude Code plugin marketplace Git URLs to install from (e.g., 'https://github.com/user/marketplace1.git\nhttps://github.com/user/marketplace2.git')"
|
description: "Newline-separated list of Claude Code plugin marketplace Git URLs to install from (e.g., 'https://github.com/user/marketplace1.git\nhttps://github.com/user/marketplace2.git')"
|
||||||
required: false
|
required: false
|
||||||
default: ""
|
default: ""
|
||||||
|
json_schema:
|
||||||
|
description: "JSON schema for structured output validation. When provided, Claude will return validated JSON matching this schema. All fields are available in the structured_output output as a JSON string (use fromJSON() or jq to access fields)."
|
||||||
|
required: false
|
||||||
|
default: ""
|
||||||
|
|
||||||
outputs:
|
outputs:
|
||||||
execution_file:
|
execution_file:
|
||||||
@@ -124,9 +128,6 @@ outputs:
|
|||||||
github_token:
|
github_token:
|
||||||
description: "The GitHub token used by the action (Claude App token if available)"
|
description: "The GitHub token used by the action (Claude App token if available)"
|
||||||
value: ${{ steps.prepare.outputs.github_token }}
|
value: ${{ steps.prepare.outputs.github_token }}
|
||||||
structured_output:
|
|
||||||
description: "JSON string containing all structured output fields when --json-schema is provided in claude_args. Use fromJSON() to parse: fromJSON(steps.id.outputs.structured_output).field_name"
|
|
||||||
value: ${{ steps.claude-code.outputs.structured_output }}
|
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: "composite"
|
using: "composite"
|
||||||
@@ -140,12 +141,10 @@ runs:
|
|||||||
- name: Setup Custom Bun Path
|
- name: Setup Custom Bun Path
|
||||||
if: inputs.path_to_bun_executable != ''
|
if: inputs.path_to_bun_executable != ''
|
||||||
shell: bash
|
shell: bash
|
||||||
env:
|
|
||||||
PATH_TO_BUN_EXECUTABLE: ${{ inputs.path_to_bun_executable }}
|
|
||||||
run: |
|
run: |
|
||||||
echo "Using custom Bun executable: $PATH_TO_BUN_EXECUTABLE"
|
echo "Using custom Bun executable: ${{ inputs.path_to_bun_executable }}"
|
||||||
# Add the directory containing the custom executable to PATH
|
# Add the directory containing the custom executable to PATH
|
||||||
BUN_DIR=$(dirname "$PATH_TO_BUN_EXECUTABLE")
|
BUN_DIR=$(dirname "${{ inputs.path_to_bun_executable }}")
|
||||||
echo "$BUN_DIR" >> "$GITHUB_PATH"
|
echo "$BUN_DIR" >> "$GITHUB_PATH"
|
||||||
|
|
||||||
- name: Install Dependencies
|
- name: Install Dependencies
|
||||||
@@ -179,13 +178,12 @@ runs:
|
|||||||
TRACK_PROGRESS: ${{ inputs.track_progress }}
|
TRACK_PROGRESS: ${{ inputs.track_progress }}
|
||||||
ADDITIONAL_PERMISSIONS: ${{ inputs.additional_permissions }}
|
ADDITIONAL_PERMISSIONS: ${{ inputs.additional_permissions }}
|
||||||
CLAUDE_ARGS: ${{ inputs.claude_args }}
|
CLAUDE_ARGS: ${{ inputs.claude_args }}
|
||||||
|
JSON_SCHEMA: ${{ inputs.json_schema }}
|
||||||
ALL_INPUTS: ${{ toJson(inputs) }}
|
ALL_INPUTS: ${{ toJson(inputs) }}
|
||||||
|
|
||||||
- name: Install Base Action Dependencies
|
- name: Install Base Action Dependencies
|
||||||
if: steps.prepare.outputs.contains_trigger == 'true'
|
if: steps.prepare.outputs.contains_trigger == 'true'
|
||||||
shell: bash
|
shell: bash
|
||||||
env:
|
|
||||||
PATH_TO_CLAUDE_CODE_EXECUTABLE: ${{ inputs.path_to_claude_code_executable }}
|
|
||||||
run: |
|
run: |
|
||||||
echo "Installing base-action dependencies..."
|
echo "Installing base-action dependencies..."
|
||||||
cd ${GITHUB_ACTION_PATH}/base-action
|
cd ${GITHUB_ACTION_PATH}/base-action
|
||||||
@@ -194,32 +192,26 @@ runs:
|
|||||||
cd -
|
cd -
|
||||||
|
|
||||||
# Install Claude Code if no custom executable is provided
|
# Install Claude Code if no custom executable is provided
|
||||||
if [ -z "$PATH_TO_CLAUDE_CODE_EXECUTABLE" ]; then
|
if [ -z "${{ inputs.path_to_claude_code_executable }}" ]; then
|
||||||
CLAUDE_CODE_VERSION="2.0.62"
|
echo "Installing Claude Code..."
|
||||||
echo "Installing Claude Code v${CLAUDE_CODE_VERSION}..."
|
curl -fsSL https://claude.ai/install.sh | bash -s 2.0.42
|
||||||
for attempt in 1 2 3; do
|
|
||||||
echo "Installation attempt $attempt..."
|
|
||||||
if command -v timeout &> /dev/null; then
|
|
||||||
timeout 120 bash -c "curl -fsSL https://claude.ai/install.sh | bash -s -- $CLAUDE_CODE_VERSION" && break
|
|
||||||
else
|
|
||||||
curl -fsSL https://claude.ai/install.sh | bash -s -- "$CLAUDE_CODE_VERSION" && break
|
|
||||||
fi
|
|
||||||
if [ $attempt -eq 3 ]; then
|
|
||||||
echo "Failed to install Claude Code after 3 attempts"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
echo "Installation failed, retrying..."
|
|
||||||
sleep 5
|
|
||||||
done
|
|
||||||
echo "Claude Code installed successfully"
|
|
||||||
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
||||||
else
|
else
|
||||||
echo "Using custom Claude Code executable: $PATH_TO_CLAUDE_CODE_EXECUTABLE"
|
echo "Using custom Claude Code executable: ${{ inputs.path_to_claude_code_executable }}"
|
||||||
# Add the directory containing the custom executable to PATH
|
# Add the directory containing the custom executable to PATH
|
||||||
CLAUDE_DIR=$(dirname "$PATH_TO_CLAUDE_CODE_EXECUTABLE")
|
CLAUDE_DIR=$(dirname "${{ inputs.path_to_claude_code_executable }}")
|
||||||
echo "$CLAUDE_DIR" >> "$GITHUB_PATH"
|
echo "$CLAUDE_DIR" >> "$GITHUB_PATH"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
- name: Setup Network Restrictions
|
||||||
|
if: steps.prepare.outputs.contains_trigger == 'true' && inputs.experimental_allowed_domains != ''
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
chmod +x ${GITHUB_ACTION_PATH}/scripts/setup-network-restrictions.sh
|
||||||
|
${GITHUB_ACTION_PATH}/scripts/setup-network-restrictions.sh
|
||||||
|
env:
|
||||||
|
EXPERIMENTAL_ALLOWED_DOMAINS: ${{ inputs.experimental_allowed_domains }}
|
||||||
|
|
||||||
- name: Run Claude Code
|
- name: Run Claude Code
|
||||||
id: claude-code
|
id: claude-code
|
||||||
if: steps.prepare.outputs.contains_trigger == 'true'
|
if: steps.prepare.outputs.contains_trigger == 'true'
|
||||||
@@ -241,6 +233,7 @@ runs:
|
|||||||
INPUT_SHOW_FULL_OUTPUT: ${{ inputs.show_full_output }}
|
INPUT_SHOW_FULL_OUTPUT: ${{ inputs.show_full_output }}
|
||||||
INPUT_PLUGINS: ${{ inputs.plugins }}
|
INPUT_PLUGINS: ${{ inputs.plugins }}
|
||||||
INPUT_PLUGIN_MARKETPLACES: ${{ inputs.plugin_marketplaces }}
|
INPUT_PLUGIN_MARKETPLACES: ${{ inputs.plugin_marketplaces }}
|
||||||
|
JSON_SCHEMA: ${{ inputs.json_schema }}
|
||||||
|
|
||||||
# Model configuration
|
# Model configuration
|
||||||
GITHUB_TOKEN: ${{ steps.prepare.outputs.GITHUB_TOKEN }}
|
GITHUB_TOKEN: ${{ steps.prepare.outputs.GITHUB_TOKEN }}
|
||||||
@@ -254,14 +247,12 @@ runs:
|
|||||||
ANTHROPIC_CUSTOM_HEADERS: ${{ env.ANTHROPIC_CUSTOM_HEADERS }}
|
ANTHROPIC_CUSTOM_HEADERS: ${{ env.ANTHROPIC_CUSTOM_HEADERS }}
|
||||||
CLAUDE_CODE_USE_BEDROCK: ${{ inputs.use_bedrock == 'true' && '1' || '' }}
|
CLAUDE_CODE_USE_BEDROCK: ${{ inputs.use_bedrock == 'true' && '1' || '' }}
|
||||||
CLAUDE_CODE_USE_VERTEX: ${{ inputs.use_vertex == 'true' && '1' || '' }}
|
CLAUDE_CODE_USE_VERTEX: ${{ inputs.use_vertex == 'true' && '1' || '' }}
|
||||||
CLAUDE_CODE_USE_FOUNDRY: ${{ inputs.use_foundry == 'true' && '1' || '' }}
|
|
||||||
|
|
||||||
# AWS configuration
|
# AWS configuration
|
||||||
AWS_REGION: ${{ env.AWS_REGION }}
|
AWS_REGION: ${{ env.AWS_REGION }}
|
||||||
AWS_ACCESS_KEY_ID: ${{ env.AWS_ACCESS_KEY_ID }}
|
AWS_ACCESS_KEY_ID: ${{ env.AWS_ACCESS_KEY_ID }}
|
||||||
AWS_SECRET_ACCESS_KEY: ${{ env.AWS_SECRET_ACCESS_KEY }}
|
AWS_SECRET_ACCESS_KEY: ${{ env.AWS_SECRET_ACCESS_KEY }}
|
||||||
AWS_SESSION_TOKEN: ${{ env.AWS_SESSION_TOKEN }}
|
AWS_SESSION_TOKEN: ${{ env.AWS_SESSION_TOKEN }}
|
||||||
AWS_BEARER_TOKEN_BEDROCK: ${{ env.AWS_BEARER_TOKEN_BEDROCK }}
|
|
||||||
ANTHROPIC_BEDROCK_BASE_URL: ${{ env.ANTHROPIC_BEDROCK_BASE_URL || (env.AWS_REGION && format('https://bedrock-runtime.{0}.amazonaws.com', env.AWS_REGION)) }}
|
ANTHROPIC_BEDROCK_BASE_URL: ${{ env.ANTHROPIC_BEDROCK_BASE_URL || (env.AWS_REGION && format('https://bedrock-runtime.{0}.amazonaws.com', env.AWS_REGION)) }}
|
||||||
|
|
||||||
# GCP configuration
|
# GCP configuration
|
||||||
@@ -275,13 +266,6 @@ runs:
|
|||||||
VERTEX_REGION_CLAUDE_3_5_SONNET: ${{ env.VERTEX_REGION_CLAUDE_3_5_SONNET }}
|
VERTEX_REGION_CLAUDE_3_5_SONNET: ${{ env.VERTEX_REGION_CLAUDE_3_5_SONNET }}
|
||||||
VERTEX_REGION_CLAUDE_3_7_SONNET: ${{ env.VERTEX_REGION_CLAUDE_3_7_SONNET }}
|
VERTEX_REGION_CLAUDE_3_7_SONNET: ${{ env.VERTEX_REGION_CLAUDE_3_7_SONNET }}
|
||||||
|
|
||||||
# Microsoft Foundry configuration
|
|
||||||
ANTHROPIC_FOUNDRY_RESOURCE: ${{ env.ANTHROPIC_FOUNDRY_RESOURCE }}
|
|
||||||
ANTHROPIC_FOUNDRY_BASE_URL: ${{ env.ANTHROPIC_FOUNDRY_BASE_URL }}
|
|
||||||
ANTHROPIC_DEFAULT_SONNET_MODEL: ${{ env.ANTHROPIC_DEFAULT_SONNET_MODEL }}
|
|
||||||
ANTHROPIC_DEFAULT_HAIKU_MODEL: ${{ env.ANTHROPIC_DEFAULT_HAIKU_MODEL }}
|
|
||||||
ANTHROPIC_DEFAULT_OPUS_MODEL: ${{ env.ANTHROPIC_DEFAULT_OPUS_MODEL }}
|
|
||||||
|
|
||||||
- name: Update comment with job link
|
- name: Update comment with job link
|
||||||
if: steps.prepare.outputs.contains_trigger == 'true' && steps.prepare.outputs.claude_comment_id && always()
|
if: steps.prepare.outputs.contains_trigger == 'true' && steps.prepare.outputs.claude_comment_id && always()
|
||||||
shell: bash
|
shell: bash
|
||||||
|
|||||||
@@ -24,6 +24,10 @@ inputs:
|
|||||||
description: "Additional arguments to pass directly to Claude CLI (e.g., '--max-turns 3 --mcp-config /path/to/config.json')"
|
description: "Additional arguments to pass directly to Claude CLI (e.g., '--max-turns 3 --mcp-config /path/to/config.json')"
|
||||||
required: false
|
required: false
|
||||||
default: ""
|
default: ""
|
||||||
|
allowed_tools:
|
||||||
|
description: "Comma-separated list of allowed tools (e.g., 'Read,Write,Bash'). Passed as --allowedTools to Claude CLI"
|
||||||
|
required: false
|
||||||
|
default: ""
|
||||||
|
|
||||||
# Authentication settings
|
# Authentication settings
|
||||||
anthropic_api_key:
|
anthropic_api_key:
|
||||||
@@ -42,10 +46,6 @@ inputs:
|
|||||||
description: "Use Google Vertex AI with OIDC authentication instead of direct Anthropic API"
|
description: "Use Google Vertex AI with OIDC authentication instead of direct Anthropic API"
|
||||||
required: false
|
required: false
|
||||||
default: "false"
|
default: "false"
|
||||||
use_foundry:
|
|
||||||
description: "Use Microsoft Foundry with OIDC authentication instead of direct Anthropic API"
|
|
||||||
required: false
|
|
||||||
default: "false"
|
|
||||||
|
|
||||||
use_node_cache:
|
use_node_cache:
|
||||||
description: "Whether to use Node.js dependency caching (set to true only for Node.js projects with lock files)"
|
description: "Whether to use Node.js dependency caching (set to true only for Node.js projects with lock files)"
|
||||||
@@ -71,6 +71,14 @@ inputs:
|
|||||||
description: "Newline-separated list of Claude Code plugin marketplace Git URLs to install from (e.g., 'https://github.com/user/marketplace1.git\nhttps://github.com/user/marketplace2.git')"
|
description: "Newline-separated list of Claude Code plugin marketplace Git URLs to install from (e.g., 'https://github.com/user/marketplace1.git\nhttps://github.com/user/marketplace2.git')"
|
||||||
required: false
|
required: false
|
||||||
default: ""
|
default: ""
|
||||||
|
json_schema:
|
||||||
|
description: |
|
||||||
|
JSON schema for structured output validation. Claude must return JSON matching this schema
|
||||||
|
or the action will fail. All fields are returned in a single structured_output JSON string.
|
||||||
|
|
||||||
|
Access outputs via: fromJSON(steps.<step-id>.outputs.structured_output).<field_name>
|
||||||
|
required: false
|
||||||
|
default: ""
|
||||||
|
|
||||||
outputs:
|
outputs:
|
||||||
conclusion:
|
conclusion:
|
||||||
@@ -80,7 +88,7 @@ outputs:
|
|||||||
description: "Path to the JSON file containing Claude Code execution log"
|
description: "Path to the JSON file containing Claude Code execution log"
|
||||||
value: ${{ steps.run_claude.outputs.execution_file }}
|
value: ${{ steps.run_claude.outputs.execution_file }}
|
||||||
structured_output:
|
structured_output:
|
||||||
description: "JSON string containing all structured output fields when --json-schema is provided in claude_args (use fromJSON() or jq to parse)"
|
description: "JSON string containing all structured output fields (use fromJSON() or jq to parse)"
|
||||||
value: ${{ steps.run_claude.outputs.structured_output }}
|
value: ${{ steps.run_claude.outputs.structured_output }}
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
@@ -101,12 +109,10 @@ runs:
|
|||||||
- name: Setup Custom Bun Path
|
- name: Setup Custom Bun Path
|
||||||
if: inputs.path_to_bun_executable != ''
|
if: inputs.path_to_bun_executable != ''
|
||||||
shell: bash
|
shell: bash
|
||||||
env:
|
|
||||||
PATH_TO_BUN_EXECUTABLE: ${{ inputs.path_to_bun_executable }}
|
|
||||||
run: |
|
run: |
|
||||||
echo "Using custom Bun executable: $PATH_TO_BUN_EXECUTABLE"
|
echo "Using custom Bun executable: ${{ inputs.path_to_bun_executable }}"
|
||||||
# Add the directory containing the custom executable to PATH
|
# Add the directory containing the custom executable to PATH
|
||||||
BUN_DIR=$(dirname "$PATH_TO_BUN_EXECUTABLE")
|
BUN_DIR=$(dirname "${{ inputs.path_to_bun_executable }}")
|
||||||
echo "$BUN_DIR" >> "$GITHUB_PATH"
|
echo "$BUN_DIR" >> "$GITHUB_PATH"
|
||||||
|
|
||||||
- name: Install Dependencies
|
- name: Install Dependencies
|
||||||
@@ -117,31 +123,14 @@ runs:
|
|||||||
|
|
||||||
- name: Install Claude Code
|
- name: Install Claude Code
|
||||||
shell: bash
|
shell: bash
|
||||||
env:
|
|
||||||
PATH_TO_CLAUDE_CODE_EXECUTABLE: ${{ inputs.path_to_claude_code_executable }}
|
|
||||||
run: |
|
run: |
|
||||||
if [ -z "$PATH_TO_CLAUDE_CODE_EXECUTABLE" ]; then
|
if [ -z "${{ inputs.path_to_claude_code_executable }}" ]; then
|
||||||
CLAUDE_CODE_VERSION="2.0.62"
|
echo "Installing Claude Code..."
|
||||||
echo "Installing Claude Code v${CLAUDE_CODE_VERSION}..."
|
curl -fsSL https://claude.ai/install.sh | bash -s 2.0.45
|
||||||
for attempt in 1 2 3; do
|
|
||||||
echo "Installation attempt $attempt..."
|
|
||||||
if command -v timeout &> /dev/null; then
|
|
||||||
timeout 120 bash -c "curl -fsSL https://claude.ai/install.sh | bash -s -- $CLAUDE_CODE_VERSION" && break
|
|
||||||
else
|
|
||||||
curl -fsSL https://claude.ai/install.sh | bash -s -- "$CLAUDE_CODE_VERSION" && break
|
|
||||||
fi
|
|
||||||
if [ $attempt -eq 3 ]; then
|
|
||||||
echo "Failed to install Claude Code after 3 attempts"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
echo "Installation failed, retrying..."
|
|
||||||
sleep 5
|
|
||||||
done
|
|
||||||
echo "Claude Code installed successfully"
|
|
||||||
else
|
else
|
||||||
echo "Using custom Claude Code executable: $PATH_TO_CLAUDE_CODE_EXECUTABLE"
|
echo "Using custom Claude Code executable: ${{ inputs.path_to_claude_code_executable }}"
|
||||||
# Add the directory containing the custom executable to PATH
|
# Add the directory containing the custom executable to PATH
|
||||||
CLAUDE_DIR=$(dirname "$PATH_TO_CLAUDE_CODE_EXECUTABLE")
|
CLAUDE_DIR=$(dirname "${{ inputs.path_to_claude_code_executable }}")
|
||||||
echo "$CLAUDE_DIR" >> "$GITHUB_PATH"
|
echo "$CLAUDE_DIR" >> "$GITHUB_PATH"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -167,6 +156,8 @@ runs:
|
|||||||
INPUT_SHOW_FULL_OUTPUT: ${{ inputs.show_full_output }}
|
INPUT_SHOW_FULL_OUTPUT: ${{ inputs.show_full_output }}
|
||||||
INPUT_PLUGINS: ${{ inputs.plugins }}
|
INPUT_PLUGINS: ${{ inputs.plugins }}
|
||||||
INPUT_PLUGIN_MARKETPLACES: ${{ inputs.plugin_marketplaces }}
|
INPUT_PLUGIN_MARKETPLACES: ${{ inputs.plugin_marketplaces }}
|
||||||
|
INPUT_ALLOWED_TOOLS: ${{ inputs.allowed_tools }}
|
||||||
|
JSON_SCHEMA: ${{ inputs.json_schema }}
|
||||||
|
|
||||||
# Provider configuration
|
# Provider configuration
|
||||||
ANTHROPIC_API_KEY: ${{ inputs.anthropic_api_key }}
|
ANTHROPIC_API_KEY: ${{ inputs.anthropic_api_key }}
|
||||||
@@ -176,14 +167,12 @@ runs:
|
|||||||
# Only set provider flags if explicitly true, since any value (including "false") is truthy
|
# Only set provider flags if explicitly true, since any value (including "false") is truthy
|
||||||
CLAUDE_CODE_USE_BEDROCK: ${{ inputs.use_bedrock == 'true' && '1' || '' }}
|
CLAUDE_CODE_USE_BEDROCK: ${{ inputs.use_bedrock == 'true' && '1' || '' }}
|
||||||
CLAUDE_CODE_USE_VERTEX: ${{ inputs.use_vertex == 'true' && '1' || '' }}
|
CLAUDE_CODE_USE_VERTEX: ${{ inputs.use_vertex == 'true' && '1' || '' }}
|
||||||
CLAUDE_CODE_USE_FOUNDRY: ${{ inputs.use_foundry == 'true' && '1' || '' }}
|
|
||||||
|
|
||||||
# AWS configuration
|
# AWS configuration
|
||||||
AWS_REGION: ${{ env.AWS_REGION }}
|
AWS_REGION: ${{ env.AWS_REGION }}
|
||||||
AWS_ACCESS_KEY_ID: ${{ env.AWS_ACCESS_KEY_ID }}
|
AWS_ACCESS_KEY_ID: ${{ env.AWS_ACCESS_KEY_ID }}
|
||||||
AWS_SECRET_ACCESS_KEY: ${{ env.AWS_SECRET_ACCESS_KEY }}
|
AWS_SECRET_ACCESS_KEY: ${{ env.AWS_SECRET_ACCESS_KEY }}
|
||||||
AWS_SESSION_TOKEN: ${{ env.AWS_SESSION_TOKEN }}
|
AWS_SESSION_TOKEN: ${{ env.AWS_SESSION_TOKEN }}
|
||||||
AWS_BEARER_TOKEN_BEDROCK: ${{ env.AWS_BEARER_TOKEN_BEDROCK }}
|
|
||||||
ANTHROPIC_BEDROCK_BASE_URL: ${{ env.ANTHROPIC_BEDROCK_BASE_URL || (env.AWS_REGION && format('https://bedrock-runtime.{0}.amazonaws.com', env.AWS_REGION)) }}
|
ANTHROPIC_BEDROCK_BASE_URL: ${{ env.ANTHROPIC_BEDROCK_BASE_URL || (env.AWS_REGION && format('https://bedrock-runtime.{0}.amazonaws.com', env.AWS_REGION)) }}
|
||||||
|
|
||||||
# GCP configuration
|
# GCP configuration
|
||||||
@@ -191,10 +180,3 @@ runs:
|
|||||||
CLOUD_ML_REGION: ${{ env.CLOUD_ML_REGION }}
|
CLOUD_ML_REGION: ${{ env.CLOUD_ML_REGION }}
|
||||||
GOOGLE_APPLICATION_CREDENTIALS: ${{ env.GOOGLE_APPLICATION_CREDENTIALS }}
|
GOOGLE_APPLICATION_CREDENTIALS: ${{ env.GOOGLE_APPLICATION_CREDENTIALS }}
|
||||||
ANTHROPIC_VERTEX_BASE_URL: ${{ env.ANTHROPIC_VERTEX_BASE_URL }}
|
ANTHROPIC_VERTEX_BASE_URL: ${{ env.ANTHROPIC_VERTEX_BASE_URL }}
|
||||||
|
|
||||||
# Microsoft Foundry configuration
|
|
||||||
ANTHROPIC_FOUNDRY_RESOURCE: ${{ env.ANTHROPIC_FOUNDRY_RESOURCE }}
|
|
||||||
ANTHROPIC_FOUNDRY_BASE_URL: ${{ env.ANTHROPIC_FOUNDRY_BASE_URL }}
|
|
||||||
ANTHROPIC_DEFAULT_SONNET_MODEL: ${{ env.ANTHROPIC_DEFAULT_SONNET_MODEL }}
|
|
||||||
ANTHROPIC_DEFAULT_HAIKU_MODEL: ${{ env.ANTHROPIC_DEFAULT_HAIKU_MODEL }}
|
|
||||||
ANTHROPIC_DEFAULT_OPUS_MODEL: ${{ env.ANTHROPIC_DEFAULT_OPUS_MODEL }}
|
|
||||||
|
|||||||
@@ -5,7 +5,6 @@
|
|||||||
"name": "@anthropic-ai/claude-code-base-action",
|
"name": "@anthropic-ai/claude-code-base-action",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": "^1.10.1",
|
"@actions/core": "^1.10.1",
|
||||||
"@anthropic-ai/claude-agent-sdk": "^0.1.52",
|
|
||||||
"shell-quote": "^1.8.3",
|
"shell-quote": "^1.8.3",
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
@@ -26,40 +25,8 @@
|
|||||||
|
|
||||||
"@actions/io": ["@actions/io@1.1.3", "", {}, "sha512-wi9JjgKLYS7U/z8PPbco+PvTb/nRWjeoFlJ1Qer83k/3C5PHQi28hiVdeE2kHXmIL99mQFawx8qt/JPjZilJ8Q=="],
|
"@actions/io": ["@actions/io@1.1.3", "", {}, "sha512-wi9JjgKLYS7U/z8PPbco+PvTb/nRWjeoFlJ1Qer83k/3C5PHQi28hiVdeE2kHXmIL99mQFawx8qt/JPjZilJ8Q=="],
|
||||||
|
|
||||||
"@anthropic-ai/claude-agent-sdk": ["@anthropic-ai/claude-agent-sdk@0.1.52", "", { "optionalDependencies": { "@img/sharp-darwin-arm64": "^0.33.5", "@img/sharp-darwin-x64": "^0.33.5", "@img/sharp-linux-arm": "^0.33.5", "@img/sharp-linux-arm64": "^0.33.5", "@img/sharp-linux-x64": "^0.33.5", "@img/sharp-linuxmusl-arm64": "^0.33.5", "@img/sharp-linuxmusl-x64": "^0.33.5", "@img/sharp-win32-x64": "^0.33.5" }, "peerDependencies": { "zod": "^3.24.1" } }, "sha512-yF8N05+9NRbqYA/h39jQ726HTQFrdXXp7pEfDNKIJ2c4FdWvEjxBA/8ciZIebN6/PyvGDcbEp3yq2Co4rNpg6A=="],
|
|
||||||
|
|
||||||
"@fastify/busboy": ["@fastify/busboy@2.1.1", "", {}, "sha512-vBZP4NlzfOlerQTnba4aqZoMhE/a9HY7HRqoOPaETQcSQuWEIyZMHGfVu6w9wGtGK5fED5qRs2DteVCjOH60sA=="],
|
"@fastify/busboy": ["@fastify/busboy@2.1.1", "", {}, "sha512-vBZP4NlzfOlerQTnba4aqZoMhE/a9HY7HRqoOPaETQcSQuWEIyZMHGfVu6w9wGtGK5fED5qRs2DteVCjOH60sA=="],
|
||||||
|
|
||||||
"@img/sharp-darwin-arm64": ["@img/sharp-darwin-arm64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-darwin-arm64": "1.0.4" }, "os": "darwin", "cpu": "arm64" }, "sha512-UT4p+iz/2H4twwAoLCqfA9UH5pI6DggwKEGuaPy7nCVQ8ZsiY5PIcrRvD1DzuY3qYL07NtIQcWnBSY/heikIFQ=="],
|
|
||||||
|
|
||||||
"@img/sharp-darwin-x64": ["@img/sharp-darwin-x64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-darwin-x64": "1.0.4" }, "os": "darwin", "cpu": "x64" }, "sha512-fyHac4jIc1ANYGRDxtiqelIbdWkIuQaI84Mv45KvGRRxSAa7o7d1ZKAOBaYbnepLC1WqxfpimdeWfvqqSGwR2Q=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-darwin-arm64": ["@img/sharp-libvips-darwin-arm64@1.0.4", "", { "os": "darwin", "cpu": "arm64" }, "sha512-XblONe153h0O2zuFfTAbQYAX2JhYmDHeWikp1LM9Hul9gVPjFY427k6dFEcOL72O01QxQsWi761svJ/ev9xEDg=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-darwin-x64": ["@img/sharp-libvips-darwin-x64@1.0.4", "", { "os": "darwin", "cpu": "x64" }, "sha512-xnGR8YuZYfJGmWPvmlunFaWJsb9T/AO2ykoP3Fz/0X5XV2aoYBPkX6xqCQvUTKKiLddarLaxpzNe+b1hjeWHAQ=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-linux-arm": ["@img/sharp-libvips-linux-arm@1.0.5", "", { "os": "linux", "cpu": "arm" }, "sha512-gvcC4ACAOPRNATg/ov8/MnbxFDJqf/pDePbBnuBDcjsI8PssmjoKMAz4LtLaVi+OnSb5FK/yIOamqDwGmXW32g=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-linux-arm64": ["@img/sharp-libvips-linux-arm64@1.0.4", "", { "os": "linux", "cpu": "arm64" }, "sha512-9B+taZ8DlyyqzZQnoeIvDVR/2F4EbMepXMc/NdVbkzsJbzkUjhXv/70GQJ7tdLA4YJgNP25zukcxpX2/SueNrA=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-linux-x64": ["@img/sharp-libvips-linux-x64@1.0.4", "", { "os": "linux", "cpu": "x64" }, "sha512-MmWmQ3iPFZr0Iev+BAgVMb3ZyC4KeFc3jFxnNbEPas60e1cIfevbtuyf9nDGIzOaW9PdnDciJm+wFFaTlj5xYw=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-linuxmusl-arm64": ["@img/sharp-libvips-linuxmusl-arm64@1.0.4", "", { "os": "linux", "cpu": "arm64" }, "sha512-9Ti+BbTYDcsbp4wfYib8Ctm1ilkugkA/uscUn6UXK1ldpC1JjiXbLfFZtRlBhjPZ5o1NCLiDbg8fhUPKStHoTA=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-linuxmusl-x64": ["@img/sharp-libvips-linuxmusl-x64@1.0.4", "", { "os": "linux", "cpu": "x64" }, "sha512-viYN1KX9m+/hGkJtvYYp+CCLgnJXwiQB39damAO7WMdKWlIhmYTfHjwSbQeUK/20vY154mwezd9HflVFM1wVSw=="],
|
|
||||||
|
|
||||||
"@img/sharp-linux-arm": ["@img/sharp-linux-arm@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-linux-arm": "1.0.5" }, "os": "linux", "cpu": "arm" }, "sha512-JTS1eldqZbJxjvKaAkxhZmBqPRGmxgu+qFKSInv8moZ2AmT5Yib3EQ1c6gp493HvrvV8QgdOXdyaIBrhvFhBMQ=="],
|
|
||||||
|
|
||||||
"@img/sharp-linux-arm64": ["@img/sharp-linux-arm64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-linux-arm64": "1.0.4" }, "os": "linux", "cpu": "arm64" }, "sha512-JMVv+AMRyGOHtO1RFBiJy/MBsgz0x4AWrT6QoEVVTyh1E39TrCUpTRI7mx9VksGX4awWASxqCYLCV4wBZHAYxA=="],
|
|
||||||
|
|
||||||
"@img/sharp-linux-x64": ["@img/sharp-linux-x64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-linux-x64": "1.0.4" }, "os": "linux", "cpu": "x64" }, "sha512-opC+Ok5pRNAzuvq1AG0ar+1owsu842/Ab+4qvU879ippJBHvyY5n2mxF1izXqkPYlGuP/M556uh53jRLJmzTWA=="],
|
|
||||||
|
|
||||||
"@img/sharp-linuxmusl-arm64": ["@img/sharp-linuxmusl-arm64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-linuxmusl-arm64": "1.0.4" }, "os": "linux", "cpu": "arm64" }, "sha512-XrHMZwGQGvJg2V/oRSUfSAfjfPxO+4DkiRh6p2AFjLQztWUuY/o8Mq0eMQVIY7HJ1CDQUJlxGGZRw1a5bqmd1g=="],
|
|
||||||
|
|
||||||
"@img/sharp-linuxmusl-x64": ["@img/sharp-linuxmusl-x64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-linuxmusl-x64": "1.0.4" }, "os": "linux", "cpu": "x64" }, "sha512-WT+d/cgqKkkKySYmqoZ8y3pxx7lx9vVejxW/W4DOFMYVSkErR+w7mf2u8m/y4+xHe7yY9DAXQMWQhpnMuFfScw=="],
|
|
||||||
|
|
||||||
"@img/sharp-win32-x64": ["@img/sharp-win32-x64@0.33.5", "", { "os": "win32", "cpu": "x64" }, "sha512-MpY/o8/8kj+EcnxwvrP4aTJSWw/aZ7JIGR4aBeZkZw5B7/Jn+tY9/VNwtcoGmdT7GfggGIU4kygOMSbYnOrAbg=="],
|
|
||||||
|
|
||||||
"@types/bun": ["@types/bun@1.2.19", "", { "dependencies": { "bun-types": "1.2.19" } }, "sha512-d9ZCmrH3CJ2uYKXQIUuZ/pUnTqIvLDS0SK7pFmbx8ma+ziH/FRMoAq5bYpRG7y+w1gl+HgyNZbtqgMq4W4e2Lg=="],
|
"@types/bun": ["@types/bun@1.2.19", "", { "dependencies": { "bun-types": "1.2.19" } }, "sha512-d9ZCmrH3CJ2uYKXQIUuZ/pUnTqIvLDS0SK7pFmbx8ma+ziH/FRMoAq5bYpRG7y+w1gl+HgyNZbtqgMq4W4e2Lg=="],
|
||||||
|
|
||||||
"@types/node": ["@types/node@20.19.9", "", { "dependencies": { "undici-types": "~6.21.0" } }, "sha512-cuVNgarYWZqxRJDQHEB58GEONhOK79QVR/qYx4S7kcUObQvUwvFnYxJuuHUKm2aieN9X3yZB4LZsuYNU1Qphsw=="],
|
"@types/node": ["@types/node@20.19.9", "", { "dependencies": { "undici-types": "~6.21.0" } }, "sha512-cuVNgarYWZqxRJDQHEB58GEONhOK79QVR/qYx4S7kcUObQvUwvFnYxJuuHUKm2aieN9X3yZB4LZsuYNU1Qphsw=="],
|
||||||
@@ -83,7 +50,5 @@
|
|||||||
"undici": ["undici@5.29.0", "", { "dependencies": { "@fastify/busboy": "^2.0.0" } }, "sha512-raqeBD6NQK4SkWhQzeYKd1KmIG6dllBOTt55Rmkt4HtI9mwdWtJljnrXjAFUBLTSN67HWrOIZ3EPF4kjUw80Bg=="],
|
"undici": ["undici@5.29.0", "", { "dependencies": { "@fastify/busboy": "^2.0.0" } }, "sha512-raqeBD6NQK4SkWhQzeYKd1KmIG6dllBOTt55Rmkt4HtI9mwdWtJljnrXjAFUBLTSN67HWrOIZ3EPF4kjUw80Bg=="],
|
||||||
|
|
||||||
"undici-types": ["undici-types@6.21.0", "", {}, "sha512-iwDZqg0QAGrg9Rav5H4n0M64c3mkR59cJ6wQp+7C4nI0gsmExaedaYLNO44eT4AtBBwjbTiGPMlt2Md0T9H9JQ=="],
|
"undici-types": ["undici-types@6.21.0", "", {}, "sha512-iwDZqg0QAGrg9Rav5H4n0M64c3mkR59cJ6wQp+7C4nI0gsmExaedaYLNO44eT4AtBBwjbTiGPMlt2Md0T9H9JQ=="],
|
||||||
|
|
||||||
"zod": ["zod@3.25.76", "", {}, "sha512-gzUt/qt81nXsFGKIFcC3YnfEAx5NkunCfnDlvuBSSFS02bcXu4Lmea0AFIUwbLWxWPx3d9p8S5QoaujKcNQxcQ=="],
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -11,7 +11,6 @@
|
|||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": "^1.10.1",
|
"@actions/core": "^1.10.1",
|
||||||
"@anthropic-ai/claude-agent-sdk": "^0.1.52",
|
|
||||||
"shell-quote": "^1.8.3"
|
"shell-quote": "^1.8.3"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
|
|||||||
@@ -28,8 +28,22 @@ async function run() {
|
|||||||
promptFile: process.env.INPUT_PROMPT_FILE || "",
|
promptFile: process.env.INPUT_PROMPT_FILE || "",
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Build claudeArgs with JSON schema if provided
|
||||||
|
let claudeArgs = process.env.INPUT_CLAUDE_ARGS || "";
|
||||||
|
|
||||||
|
// Add allowed tools if specified
|
||||||
|
if (process.env.INPUT_ALLOWED_TOOLS) {
|
||||||
|
claudeArgs += ` --allowedTools "${process.env.INPUT_ALLOWED_TOOLS}"`;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Add JSON schema if specified (no escaping - parseShellArgs handles it)
|
||||||
|
if (process.env.JSON_SCHEMA) {
|
||||||
|
// Wrap in single quotes for parseShellArgs
|
||||||
|
claudeArgs += ` --json-schema '${process.env.JSON_SCHEMA}'`;
|
||||||
|
}
|
||||||
|
|
||||||
await runClaude(promptConfig.path, {
|
await runClaude(promptConfig.path, {
|
||||||
claudeArgs: process.env.INPUT_CLAUDE_ARGS,
|
claudeArgs: claudeArgs.trim(),
|
||||||
allowedTools: process.env.INPUT_ALLOWED_TOOLS,
|
allowedTools: process.env.INPUT_ALLOWED_TOOLS,
|
||||||
disallowedTools: process.env.INPUT_DISALLOWED_TOOLS,
|
disallowedTools: process.env.INPUT_DISALLOWED_TOOLS,
|
||||||
maxTurns: process.env.INPUT_MAX_TURNS,
|
maxTurns: process.env.INPUT_MAX_TURNS,
|
||||||
|
|||||||
@@ -1,149 +0,0 @@
|
|||||||
import { parse as parseShellArgs } from "shell-quote";
|
|
||||||
import type { ClaudeOptions } from "./run-claude";
|
|
||||||
import type { Options as SdkOptions } from "@anthropic-ai/claude-agent-sdk";
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Result of parsing ClaudeOptions for SDK usage
|
|
||||||
*/
|
|
||||||
export type ParsedSdkOptions = {
|
|
||||||
sdkOptions: SdkOptions;
|
|
||||||
showFullOutput: boolean;
|
|
||||||
hasJsonSchema: boolean;
|
|
||||||
};
|
|
||||||
|
|
||||||
// Flags that should accumulate multiple values instead of overwriting
|
|
||||||
const ACCUMULATING_FLAGS = new Set(["allowedTools", "disallowedTools"]);
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Parse claudeArgs string into extraArgs record for SDK pass-through
|
|
||||||
* The SDK/CLI will handle --mcp-config, --json-schema, etc.
|
|
||||||
* For allowedTools and disallowedTools, multiple occurrences are accumulated (comma-joined).
|
|
||||||
*/
|
|
||||||
function parseClaudeArgsToExtraArgs(
|
|
||||||
claudeArgs?: string,
|
|
||||||
): Record<string, string | null> {
|
|
||||||
if (!claudeArgs?.trim()) return {};
|
|
||||||
|
|
||||||
const result: Record<string, string | null> = {};
|
|
||||||
const args = parseShellArgs(claudeArgs).filter(
|
|
||||||
(arg): arg is string => typeof arg === "string",
|
|
||||||
);
|
|
||||||
|
|
||||||
for (let i = 0; i < args.length; i++) {
|
|
||||||
const arg = args[i];
|
|
||||||
if (arg?.startsWith("--")) {
|
|
||||||
const flag = arg.slice(2);
|
|
||||||
const nextArg = args[i + 1];
|
|
||||||
|
|
||||||
// Check if next arg is a value (not another flag)
|
|
||||||
if (nextArg && !nextArg.startsWith("--")) {
|
|
||||||
// For accumulating flags, join multiple values with commas
|
|
||||||
if (ACCUMULATING_FLAGS.has(flag) && result[flag]) {
|
|
||||||
result[flag] = `${result[flag]},${nextArg}`;
|
|
||||||
} else {
|
|
||||||
result[flag] = nextArg;
|
|
||||||
}
|
|
||||||
i++; // Skip the value
|
|
||||||
} else {
|
|
||||||
result[flag] = null; // Boolean flag
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Parse ClaudeOptions into SDK-compatible options
|
|
||||||
* Uses extraArgs for CLI pass-through instead of duplicating option parsing
|
|
||||||
*/
|
|
||||||
export function parseSdkOptions(options: ClaudeOptions): ParsedSdkOptions {
|
|
||||||
// Determine output verbosity
|
|
||||||
const isDebugMode = process.env.ACTIONS_STEP_DEBUG === "true";
|
|
||||||
const showFullOutput = options.showFullOutput === "true" || isDebugMode;
|
|
||||||
|
|
||||||
// Parse claudeArgs into extraArgs for CLI pass-through
|
|
||||||
const extraArgs = parseClaudeArgsToExtraArgs(options.claudeArgs);
|
|
||||||
|
|
||||||
// Detect if --json-schema is present (for hasJsonSchema flag)
|
|
||||||
const hasJsonSchema = "json-schema" in extraArgs;
|
|
||||||
|
|
||||||
// Extract and merge allowedTools from both sources:
|
|
||||||
// 1. From extraArgs (parsed from claudeArgs - contains tag mode's tools)
|
|
||||||
// 2. From options.allowedTools (direct input - may be undefined)
|
|
||||||
// This prevents duplicate flags being overwritten when claudeArgs contains --allowedTools
|
|
||||||
const extraArgsAllowedTools = extraArgs["allowedTools"]
|
|
||||||
? extraArgs["allowedTools"].split(",").map((t) => t.trim())
|
|
||||||
: [];
|
|
||||||
const directAllowedTools = options.allowedTools
|
|
||||||
? options.allowedTools.split(",").map((t) => t.trim())
|
|
||||||
: [];
|
|
||||||
const mergedAllowedTools = [
|
|
||||||
...new Set([...extraArgsAllowedTools, ...directAllowedTools]),
|
|
||||||
];
|
|
||||||
delete extraArgs["allowedTools"];
|
|
||||||
|
|
||||||
// Same for disallowedTools
|
|
||||||
const extraArgsDisallowedTools = extraArgs["disallowedTools"]
|
|
||||||
? extraArgs["disallowedTools"].split(",").map((t) => t.trim())
|
|
||||||
: [];
|
|
||||||
const directDisallowedTools = options.disallowedTools
|
|
||||||
? options.disallowedTools.split(",").map((t) => t.trim())
|
|
||||||
: [];
|
|
||||||
const mergedDisallowedTools = [
|
|
||||||
...new Set([...extraArgsDisallowedTools, ...directDisallowedTools]),
|
|
||||||
];
|
|
||||||
delete extraArgs["disallowedTools"];
|
|
||||||
|
|
||||||
// Build custom environment
|
|
||||||
const env: Record<string, string | undefined> = { ...process.env };
|
|
||||||
if (process.env.INPUT_ACTION_INPUTS_PRESENT) {
|
|
||||||
env.GITHUB_ACTION_INPUTS = process.env.INPUT_ACTION_INPUTS_PRESENT;
|
|
||||||
}
|
|
||||||
|
|
||||||
// Build system prompt option - default to claude_code preset
|
|
||||||
let systemPrompt: SdkOptions["systemPrompt"];
|
|
||||||
if (options.systemPrompt) {
|
|
||||||
systemPrompt = options.systemPrompt;
|
|
||||||
} else if (options.appendSystemPrompt) {
|
|
||||||
systemPrompt = {
|
|
||||||
type: "preset",
|
|
||||||
preset: "claude_code",
|
|
||||||
append: options.appendSystemPrompt,
|
|
||||||
};
|
|
||||||
} else {
|
|
||||||
// Default to claude_code preset when no custom prompt is specified
|
|
||||||
systemPrompt = {
|
|
||||||
type: "preset",
|
|
||||||
preset: "claude_code",
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
// Build SDK options - use merged tools from both direct options and claudeArgs
|
|
||||||
const sdkOptions: SdkOptions = {
|
|
||||||
// Direct options from ClaudeOptions inputs
|
|
||||||
model: options.model,
|
|
||||||
maxTurns: options.maxTurns ? parseInt(options.maxTurns, 10) : undefined,
|
|
||||||
allowedTools:
|
|
||||||
mergedAllowedTools.length > 0 ? mergedAllowedTools : undefined,
|
|
||||||
disallowedTools:
|
|
||||||
mergedDisallowedTools.length > 0 ? mergedDisallowedTools : undefined,
|
|
||||||
systemPrompt,
|
|
||||||
fallbackModel: options.fallbackModel,
|
|
||||||
pathToClaudeCodeExecutable: options.pathToClaudeCodeExecutable,
|
|
||||||
|
|
||||||
// Pass through claudeArgs as extraArgs - CLI handles --mcp-config, --json-schema, etc.
|
|
||||||
// Note: allowedTools and disallowedTools have been removed from extraArgs to prevent duplicates
|
|
||||||
extraArgs,
|
|
||||||
env,
|
|
||||||
|
|
||||||
// Load settings from all sources to pick up CLI-installed plugins, CLAUDE.md, etc.
|
|
||||||
settingSources: ["user", "project", "local"],
|
|
||||||
};
|
|
||||||
|
|
||||||
return {
|
|
||||||
sdkOptions,
|
|
||||||
showFullOutput,
|
|
||||||
hasJsonSchema,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,151 +0,0 @@
|
|||||||
import * as core from "@actions/core";
|
|
||||||
import { readFile, writeFile } from "fs/promises";
|
|
||||||
import { query } from "@anthropic-ai/claude-agent-sdk";
|
|
||||||
import type {
|
|
||||||
SDKMessage,
|
|
||||||
SDKResultMessage,
|
|
||||||
} from "@anthropic-ai/claude-agent-sdk";
|
|
||||||
import type { ParsedSdkOptions } from "./parse-sdk-options";
|
|
||||||
|
|
||||||
const EXECUTION_FILE = `${process.env.RUNNER_TEMP}/claude-execution-output.json`;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Sanitizes SDK output to match CLI sanitization behavior
|
|
||||||
*/
|
|
||||||
function sanitizeSdkOutput(
|
|
||||||
message: SDKMessage,
|
|
||||||
showFullOutput: boolean,
|
|
||||||
): string | null {
|
|
||||||
if (showFullOutput) {
|
|
||||||
return JSON.stringify(message, null, 2);
|
|
||||||
}
|
|
||||||
|
|
||||||
// System initialization - safe to show
|
|
||||||
if (message.type === "system" && message.subtype === "init") {
|
|
||||||
return JSON.stringify(
|
|
||||||
{
|
|
||||||
type: "system",
|
|
||||||
subtype: "init",
|
|
||||||
message: "Claude Code initialized",
|
|
||||||
model: "model" in message ? message.model : "unknown",
|
|
||||||
},
|
|
||||||
null,
|
|
||||||
2,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Result messages - show sanitized summary
|
|
||||||
if (message.type === "result") {
|
|
||||||
const resultMsg = message as SDKResultMessage;
|
|
||||||
return JSON.stringify(
|
|
||||||
{
|
|
||||||
type: "result",
|
|
||||||
subtype: resultMsg.subtype,
|
|
||||||
is_error: resultMsg.is_error,
|
|
||||||
duration_ms: resultMsg.duration_ms,
|
|
||||||
num_turns: resultMsg.num_turns,
|
|
||||||
total_cost_usd: resultMsg.total_cost_usd,
|
|
||||||
permission_denials: resultMsg.permission_denials,
|
|
||||||
},
|
|
||||||
null,
|
|
||||||
2,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Suppress other message types in non-full-output mode
|
|
||||||
return null;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Run Claude using the Agent SDK
|
|
||||||
*/
|
|
||||||
export async function runClaudeWithSdk(
|
|
||||||
promptPath: string,
|
|
||||||
{ sdkOptions, showFullOutput, hasJsonSchema }: ParsedSdkOptions,
|
|
||||||
): Promise<void> {
|
|
||||||
const prompt = await readFile(promptPath, "utf-8");
|
|
||||||
|
|
||||||
if (!showFullOutput) {
|
|
||||||
console.log(
|
|
||||||
"Running Claude Code via SDK (full output hidden for security)...",
|
|
||||||
);
|
|
||||||
console.log(
|
|
||||||
"Rerun in debug mode or enable `show_full_output: true` in your workflow file for full output.",
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
console.log(`Running Claude with prompt from file: ${promptPath}`);
|
|
||||||
// Log SDK options without env (which could contain sensitive data)
|
|
||||||
const { env, ...optionsToLog } = sdkOptions;
|
|
||||||
console.log("SDK options:", JSON.stringify(optionsToLog, null, 2));
|
|
||||||
|
|
||||||
const messages: SDKMessage[] = [];
|
|
||||||
let resultMessage: SDKResultMessage | undefined;
|
|
||||||
|
|
||||||
try {
|
|
||||||
for await (const message of query({ prompt, options: sdkOptions })) {
|
|
||||||
messages.push(message);
|
|
||||||
|
|
||||||
const sanitized = sanitizeSdkOutput(message, showFullOutput);
|
|
||||||
if (sanitized) {
|
|
||||||
console.log(sanitized);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (message.type === "result") {
|
|
||||||
resultMessage = message as SDKResultMessage;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
} catch (error) {
|
|
||||||
console.error("SDK execution error:", error);
|
|
||||||
core.setOutput("conclusion", "failure");
|
|
||||||
process.exit(1);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Write execution file
|
|
||||||
try {
|
|
||||||
await writeFile(EXECUTION_FILE, JSON.stringify(messages, null, 2));
|
|
||||||
console.log(`Log saved to ${EXECUTION_FILE}`);
|
|
||||||
core.setOutput("execution_file", EXECUTION_FILE);
|
|
||||||
} catch (error) {
|
|
||||||
core.warning(`Failed to write execution file: ${error}`);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!resultMessage) {
|
|
||||||
core.setOutput("conclusion", "failure");
|
|
||||||
core.error("No result message received from Claude");
|
|
||||||
process.exit(1);
|
|
||||||
}
|
|
||||||
|
|
||||||
const isSuccess = resultMessage.subtype === "success";
|
|
||||||
core.setOutput("conclusion", isSuccess ? "success" : "failure");
|
|
||||||
|
|
||||||
// Handle structured output
|
|
||||||
if (hasJsonSchema) {
|
|
||||||
if (
|
|
||||||
isSuccess &&
|
|
||||||
"structured_output" in resultMessage &&
|
|
||||||
resultMessage.structured_output
|
|
||||||
) {
|
|
||||||
const structuredOutputJson = JSON.stringify(
|
|
||||||
resultMessage.structured_output,
|
|
||||||
);
|
|
||||||
core.setOutput("structured_output", structuredOutputJson);
|
|
||||||
core.info(
|
|
||||||
`Set structured_output with ${Object.keys(resultMessage.structured_output as object).length} field(s)`,
|
|
||||||
);
|
|
||||||
} else {
|
|
||||||
core.setFailed(
|
|
||||||
`--json-schema was provided but Claude did not return structured_output. Result subtype: ${resultMessage.subtype}`,
|
|
||||||
);
|
|
||||||
core.setOutput("conclusion", "failure");
|
|
||||||
process.exit(1);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!isSuccess) {
|
|
||||||
if ("errors" in resultMessage && resultMessage.errors) {
|
|
||||||
core.error(`Execution failed: ${resultMessage.errors.join(", ")}`);
|
|
||||||
}
|
|
||||||
process.exit(1);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -5,8 +5,6 @@ import { unlink, writeFile, stat, readFile } from "fs/promises";
|
|||||||
import { createWriteStream } from "fs";
|
import { createWriteStream } from "fs";
|
||||||
import { spawn } from "child_process";
|
import { spawn } from "child_process";
|
||||||
import { parse as parseShellArgs } from "shell-quote";
|
import { parse as parseShellArgs } from "shell-quote";
|
||||||
import { runClaudeWithSdk } from "./run-claude-sdk";
|
|
||||||
import { parseSdkOptions } from "./parse-sdk-options";
|
|
||||||
|
|
||||||
const execAsync = promisify(exec);
|
const execAsync = promisify(exec);
|
||||||
|
|
||||||
@@ -126,7 +124,7 @@ export function prepareRunConfig(
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Parses structured_output from execution file and sets GitHub Action outputs
|
* Parses structured_output from execution file and sets GitHub Action outputs
|
||||||
* Only runs if --json-schema was explicitly provided in claude_args
|
* Only runs if json_schema was explicitly provided by the user
|
||||||
* Exported for testing
|
* Exported for testing
|
||||||
*/
|
*/
|
||||||
export async function parseAndSetStructuredOutputs(
|
export async function parseAndSetStructuredOutputs(
|
||||||
@@ -146,7 +144,7 @@ export async function parseAndSetStructuredOutputs(
|
|||||||
|
|
||||||
if (!result?.structured_output) {
|
if (!result?.structured_output) {
|
||||||
throw new Error(
|
throw new Error(
|
||||||
`--json-schema was provided but Claude did not return structured_output.\n` +
|
`json_schema was provided but Claude did not return structured_output.\n` +
|
||||||
`Found ${messages.length} messages. Result exists: ${!!result}\n`,
|
`Found ${messages.length} messages. Result exists: ${!!result}\n`,
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
@@ -167,22 +165,8 @@ export async function parseAndSetStructuredOutputs(
|
|||||||
}
|
}
|
||||||
|
|
||||||
export async function runClaude(promptPath: string, options: ClaudeOptions) {
|
export async function runClaude(promptPath: string, options: ClaudeOptions) {
|
||||||
// Feature flag: use SDK path when USE_AGENT_SDK=true
|
|
||||||
const useAgentSdk = process.env.USE_AGENT_SDK === "true";
|
|
||||||
console.log(
|
|
||||||
`Using ${useAgentSdk ? "Agent SDK" : "CLI"} path (USE_AGENT_SDK=${process.env.USE_AGENT_SDK ?? "unset"})`,
|
|
||||||
);
|
|
||||||
|
|
||||||
if (useAgentSdk) {
|
|
||||||
const parsedOptions = parseSdkOptions(options);
|
|
||||||
return runClaudeWithSdk(promptPath, parsedOptions);
|
|
||||||
}
|
|
||||||
|
|
||||||
const config = prepareRunConfig(promptPath, options);
|
const config = prepareRunConfig(promptPath, options);
|
||||||
|
|
||||||
// Detect if --json-schema is present in claude args
|
|
||||||
const hasJsonSchema = options.claudeArgs?.includes("--json-schema") ?? false;
|
|
||||||
|
|
||||||
// Create a named pipe
|
// Create a named pipe
|
||||||
try {
|
try {
|
||||||
await unlink(PIPE_PATH);
|
await unlink(PIPE_PATH);
|
||||||
@@ -368,8 +352,8 @@ export async function runClaude(promptPath: string, options: ClaudeOptions) {
|
|||||||
|
|
||||||
core.setOutput("execution_file", EXECUTION_FILE);
|
core.setOutput("execution_file", EXECUTION_FILE);
|
||||||
|
|
||||||
// Parse and set structured outputs only if user provided --json-schema in claude_args
|
// Parse and set structured outputs only if user provided json_schema
|
||||||
if (hasJsonSchema) {
|
if (process.env.JSON_SCHEMA) {
|
||||||
try {
|
try {
|
||||||
await parseAndSetStructuredOutputs(EXECUTION_FILE);
|
await parseAndSetStructuredOutputs(EXECUTION_FILE);
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
|||||||
@@ -1,50 +1,39 @@
|
|||||||
/**
|
/**
|
||||||
* Validates the environment variables required for running Claude Code
|
* Validates the environment variables required for running Claude Code
|
||||||
* based on the selected provider (Anthropic API, AWS Bedrock, Google Vertex AI, or Microsoft Foundry)
|
* based on the selected provider (Anthropic API, AWS Bedrock, or Google Vertex AI)
|
||||||
*/
|
*/
|
||||||
export function validateEnvironmentVariables() {
|
export function validateEnvironmentVariables() {
|
||||||
const useBedrock = process.env.CLAUDE_CODE_USE_BEDROCK === "1";
|
const useBedrock = process.env.CLAUDE_CODE_USE_BEDROCK === "1";
|
||||||
const useVertex = process.env.CLAUDE_CODE_USE_VERTEX === "1";
|
const useVertex = process.env.CLAUDE_CODE_USE_VERTEX === "1";
|
||||||
const useFoundry = process.env.CLAUDE_CODE_USE_FOUNDRY === "1";
|
|
||||||
const anthropicApiKey = process.env.ANTHROPIC_API_KEY;
|
const anthropicApiKey = process.env.ANTHROPIC_API_KEY;
|
||||||
const claudeCodeOAuthToken = process.env.CLAUDE_CODE_OAUTH_TOKEN;
|
const claudeCodeOAuthToken = process.env.CLAUDE_CODE_OAUTH_TOKEN;
|
||||||
|
|
||||||
const errors: string[] = [];
|
const errors: string[] = [];
|
||||||
|
|
||||||
// Check for mutual exclusivity between providers
|
if (useBedrock && useVertex) {
|
||||||
const activeProviders = [useBedrock, useVertex, useFoundry].filter(Boolean);
|
|
||||||
if (activeProviders.length > 1) {
|
|
||||||
errors.push(
|
errors.push(
|
||||||
"Cannot use multiple providers simultaneously. Please set only one of: CLAUDE_CODE_USE_BEDROCK, CLAUDE_CODE_USE_VERTEX, or CLAUDE_CODE_USE_FOUNDRY.",
|
"Cannot use both Bedrock and Vertex AI simultaneously. Please set only one provider.",
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!useBedrock && !useVertex && !useFoundry) {
|
if (!useBedrock && !useVertex) {
|
||||||
if (!anthropicApiKey && !claudeCodeOAuthToken) {
|
if (!anthropicApiKey && !claudeCodeOAuthToken) {
|
||||||
errors.push(
|
errors.push(
|
||||||
"Either ANTHROPIC_API_KEY or CLAUDE_CODE_OAUTH_TOKEN is required when using direct Anthropic API.",
|
"Either ANTHROPIC_API_KEY or CLAUDE_CODE_OAUTH_TOKEN is required when using direct Anthropic API.",
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
} else if (useBedrock) {
|
} else if (useBedrock) {
|
||||||
const awsRegion = process.env.AWS_REGION;
|
const requiredBedrockVars = {
|
||||||
const awsAccessKeyId = process.env.AWS_ACCESS_KEY_ID;
|
AWS_REGION: process.env.AWS_REGION,
|
||||||
const awsSecretAccessKey = process.env.AWS_SECRET_ACCESS_KEY;
|
AWS_ACCESS_KEY_ID: process.env.AWS_ACCESS_KEY_ID,
|
||||||
const awsBearerToken = process.env.AWS_BEARER_TOKEN_BEDROCK;
|
AWS_SECRET_ACCESS_KEY: process.env.AWS_SECRET_ACCESS_KEY,
|
||||||
|
};
|
||||||
|
|
||||||
// AWS_REGION is always required for Bedrock
|
Object.entries(requiredBedrockVars).forEach(([key, value]) => {
|
||||||
if (!awsRegion) {
|
if (!value) {
|
||||||
errors.push("AWS_REGION is required when using AWS Bedrock.");
|
errors.push(`${key} is required when using AWS Bedrock.`);
|
||||||
}
|
}
|
||||||
|
});
|
||||||
// Either bearer token OR access key credentials must be provided
|
|
||||||
const hasAccessKeyCredentials = awsAccessKeyId && awsSecretAccessKey;
|
|
||||||
const hasBearerToken = awsBearerToken;
|
|
||||||
|
|
||||||
if (!hasAccessKeyCredentials && !hasBearerToken) {
|
|
||||||
errors.push(
|
|
||||||
"Either AWS_BEARER_TOKEN_BEDROCK or both AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY are required when using AWS Bedrock.",
|
|
||||||
);
|
|
||||||
}
|
|
||||||
} else if (useVertex) {
|
} else if (useVertex) {
|
||||||
const requiredVertexVars = {
|
const requiredVertexVars = {
|
||||||
ANTHROPIC_VERTEX_PROJECT_ID: process.env.ANTHROPIC_VERTEX_PROJECT_ID,
|
ANTHROPIC_VERTEX_PROJECT_ID: process.env.ANTHROPIC_VERTEX_PROJECT_ID,
|
||||||
@@ -56,16 +45,6 @@ export function validateEnvironmentVariables() {
|
|||||||
errors.push(`${key} is required when using Google Vertex AI.`);
|
errors.push(`${key} is required when using Google Vertex AI.`);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
} else if (useFoundry) {
|
|
||||||
const foundryResource = process.env.ANTHROPIC_FOUNDRY_RESOURCE;
|
|
||||||
const foundryBaseUrl = process.env.ANTHROPIC_FOUNDRY_BASE_URL;
|
|
||||||
|
|
||||||
// Either resource name or base URL is required
|
|
||||||
if (!foundryResource && !foundryBaseUrl) {
|
|
||||||
errors.push(
|
|
||||||
"Either ANTHROPIC_FOUNDRY_RESOURCE or ANTHROPIC_FOUNDRY_BASE_URL is required when using Microsoft Foundry.",
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (errors.length > 0) {
|
if (errors.length > 0) {
|
||||||
|
|||||||
@@ -1,163 +0,0 @@
|
|||||||
#!/usr/bin/env bun
|
|
||||||
|
|
||||||
import { describe, test, expect } from "bun:test";
|
|
||||||
import { parseSdkOptions } from "../src/parse-sdk-options";
|
|
||||||
import type { ClaudeOptions } from "../src/run-claude";
|
|
||||||
|
|
||||||
describe("parseSdkOptions", () => {
|
|
||||||
describe("allowedTools merging", () => {
|
|
||||||
test("should extract allowedTools from claudeArgs", () => {
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs: '--allowedTools "Edit,Read,Write"',
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.allowedTools).toEqual(["Edit", "Read", "Write"]);
|
|
||||||
expect(result.sdkOptions.extraArgs?.["allowedTools"]).toBeUndefined();
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should extract allowedTools from claudeArgs with MCP tools", () => {
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs:
|
|
||||||
'--allowedTools "Edit,Read,mcp__github_comment__update_claude_comment"',
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.allowedTools).toEqual([
|
|
||||||
"Edit",
|
|
||||||
"Read",
|
|
||||||
"mcp__github_comment__update_claude_comment",
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should accumulate multiple --allowedTools flags from claudeArgs", () => {
|
|
||||||
// This simulates tag mode adding its tools, then user adding their own
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs:
|
|
||||||
'--allowedTools "Edit,Read,mcp__github_comment__update_claude_comment" --model "claude-3" --allowedTools "Bash(npm install),mcp__github__get_issue"',
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.allowedTools).toEqual([
|
|
||||||
"Edit",
|
|
||||||
"Read",
|
|
||||||
"mcp__github_comment__update_claude_comment",
|
|
||||||
"Bash(npm install)",
|
|
||||||
"mcp__github__get_issue",
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should merge allowedTools from both claudeArgs and direct options", () => {
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs: '--allowedTools "Edit,Read"',
|
|
||||||
allowedTools: "Write,Glob",
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.allowedTools).toEqual([
|
|
||||||
"Edit",
|
|
||||||
"Read",
|
|
||||||
"Write",
|
|
||||||
"Glob",
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should deduplicate allowedTools when merging", () => {
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs: '--allowedTools "Edit,Read"',
|
|
||||||
allowedTools: "Edit,Write",
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.allowedTools).toEqual(["Edit", "Read", "Write"]);
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should use only direct options when claudeArgs has no allowedTools", () => {
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs: '--model "claude-3-5-sonnet"',
|
|
||||||
allowedTools: "Edit,Read",
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.allowedTools).toEqual(["Edit", "Read"]);
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should return undefined allowedTools when neither source has it", () => {
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs: '--model "claude-3-5-sonnet"',
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.allowedTools).toBeUndefined();
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should remove allowedTools from extraArgs after extraction", () => {
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs: '--allowedTools "Edit,Read" --model "claude-3-5-sonnet"',
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.extraArgs?.["allowedTools"]).toBeUndefined();
|
|
||||||
expect(result.sdkOptions.extraArgs?.["model"]).toBe("claude-3-5-sonnet");
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe("disallowedTools merging", () => {
|
|
||||||
test("should extract disallowedTools from claudeArgs", () => {
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs: '--disallowedTools "Bash,Write"',
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.disallowedTools).toEqual(["Bash", "Write"]);
|
|
||||||
expect(result.sdkOptions.extraArgs?.["disallowedTools"]).toBeUndefined();
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should merge disallowedTools from both sources", () => {
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs: '--disallowedTools "Bash"',
|
|
||||||
disallowedTools: "Write",
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.disallowedTools).toEqual(["Bash", "Write"]);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe("other extraArgs passthrough", () => {
|
|
||||||
test("should pass through mcp-config in extraArgs", () => {
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs: `--mcp-config '{"mcpServers":{}}' --allowedTools "Edit"`,
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.extraArgs?.["mcp-config"]).toBe(
|
|
||||||
'{"mcpServers":{}}',
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should pass through json-schema in extraArgs", () => {
|
|
||||||
const options: ClaudeOptions = {
|
|
||||||
claudeArgs: `--json-schema '{"type":"object"}'`,
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = parseSdkOptions(options);
|
|
||||||
|
|
||||||
expect(result.sdkOptions.extraArgs?.["json-schema"]).toBe(
|
|
||||||
'{"type":"object"}',
|
|
||||||
);
|
|
||||||
expect(result.hasJsonSchema).toBe(true);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -113,7 +113,7 @@ describe("parseAndSetStructuredOutputs", () => {
|
|||||||
await expect(
|
await expect(
|
||||||
parseAndSetStructuredOutputs(TEST_EXECUTION_FILE),
|
parseAndSetStructuredOutputs(TEST_EXECUTION_FILE),
|
||||||
).rejects.toThrow(
|
).rejects.toThrow(
|
||||||
"--json-schema was provided but Claude did not return structured_output",
|
"json_schema was provided but Claude did not return structured_output",
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -127,7 +127,7 @@ describe("parseAndSetStructuredOutputs", () => {
|
|||||||
await expect(
|
await expect(
|
||||||
parseAndSetStructuredOutputs(TEST_EXECUTION_FILE),
|
parseAndSetStructuredOutputs(TEST_EXECUTION_FILE),
|
||||||
).rejects.toThrow(
|
).rejects.toThrow(
|
||||||
"--json-schema was provided but Claude did not return structured_output",
|
"json_schema was provided but Claude did not return structured_output",
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -13,19 +13,15 @@ describe("validateEnvironmentVariables", () => {
|
|||||||
delete process.env.ANTHROPIC_API_KEY;
|
delete process.env.ANTHROPIC_API_KEY;
|
||||||
delete process.env.CLAUDE_CODE_USE_BEDROCK;
|
delete process.env.CLAUDE_CODE_USE_BEDROCK;
|
||||||
delete process.env.CLAUDE_CODE_USE_VERTEX;
|
delete process.env.CLAUDE_CODE_USE_VERTEX;
|
||||||
delete process.env.CLAUDE_CODE_USE_FOUNDRY;
|
|
||||||
delete process.env.AWS_REGION;
|
delete process.env.AWS_REGION;
|
||||||
delete process.env.AWS_ACCESS_KEY_ID;
|
delete process.env.AWS_ACCESS_KEY_ID;
|
||||||
delete process.env.AWS_SECRET_ACCESS_KEY;
|
delete process.env.AWS_SECRET_ACCESS_KEY;
|
||||||
delete process.env.AWS_SESSION_TOKEN;
|
delete process.env.AWS_SESSION_TOKEN;
|
||||||
delete process.env.AWS_BEARER_TOKEN_BEDROCK;
|
|
||||||
delete process.env.ANTHROPIC_BEDROCK_BASE_URL;
|
delete process.env.ANTHROPIC_BEDROCK_BASE_URL;
|
||||||
delete process.env.ANTHROPIC_VERTEX_PROJECT_ID;
|
delete process.env.ANTHROPIC_VERTEX_PROJECT_ID;
|
||||||
delete process.env.CLOUD_ML_REGION;
|
delete process.env.CLOUD_ML_REGION;
|
||||||
delete process.env.GOOGLE_APPLICATION_CREDENTIALS;
|
delete process.env.GOOGLE_APPLICATION_CREDENTIALS;
|
||||||
delete process.env.ANTHROPIC_VERTEX_BASE_URL;
|
delete process.env.ANTHROPIC_VERTEX_BASE_URL;
|
||||||
delete process.env.ANTHROPIC_FOUNDRY_RESOURCE;
|
|
||||||
delete process.env.ANTHROPIC_FOUNDRY_BASE_URL;
|
|
||||||
});
|
});
|
||||||
|
|
||||||
afterEach(() => {
|
afterEach(() => {
|
||||||
@@ -96,58 +92,31 @@ describe("validateEnvironmentVariables", () => {
|
|||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("should fail when only AWS_SECRET_ACCESS_KEY is provided without bearer token", () => {
|
test("should fail when AWS_ACCESS_KEY_ID is missing", () => {
|
||||||
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
||||||
process.env.AWS_REGION = "us-east-1";
|
process.env.AWS_REGION = "us-east-1";
|
||||||
process.env.AWS_SECRET_ACCESS_KEY = "test-secret-key";
|
process.env.AWS_SECRET_ACCESS_KEY = "test-secret-key";
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).toThrow(
|
expect(() => validateEnvironmentVariables()).toThrow(
|
||||||
"Either AWS_BEARER_TOKEN_BEDROCK or both AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY are required when using AWS Bedrock.",
|
"AWS_ACCESS_KEY_ID is required when using AWS Bedrock.",
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("should fail when only AWS_ACCESS_KEY_ID is provided without bearer token", () => {
|
test("should fail when AWS_SECRET_ACCESS_KEY is missing", () => {
|
||||||
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
||||||
process.env.AWS_REGION = "us-east-1";
|
process.env.AWS_REGION = "us-east-1";
|
||||||
process.env.AWS_ACCESS_KEY_ID = "test-access-key";
|
process.env.AWS_ACCESS_KEY_ID = "test-access-key";
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).toThrow(
|
expect(() => validateEnvironmentVariables()).toThrow(
|
||||||
"Either AWS_BEARER_TOKEN_BEDROCK or both AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY are required when using AWS Bedrock.",
|
"AWS_SECRET_ACCESS_KEY is required when using AWS Bedrock.",
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
|
|
||||||
test("should pass when AWS_BEARER_TOKEN_BEDROCK is provided instead of access keys", () => {
|
test("should report all missing Bedrock variables", () => {
|
||||||
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
|
||||||
process.env.AWS_REGION = "us-east-1";
|
|
||||||
process.env.AWS_BEARER_TOKEN_BEDROCK = "test-bearer-token";
|
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).not.toThrow();
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should pass when both bearer token and access keys are provided", () => {
|
|
||||||
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
|
||||||
process.env.AWS_REGION = "us-east-1";
|
|
||||||
process.env.AWS_BEARER_TOKEN_BEDROCK = "test-bearer-token";
|
|
||||||
process.env.AWS_ACCESS_KEY_ID = "test-access-key";
|
|
||||||
process.env.AWS_SECRET_ACCESS_KEY = "test-secret-key";
|
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).not.toThrow();
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should fail when no authentication method is provided", () => {
|
|
||||||
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
|
||||||
process.env.AWS_REGION = "us-east-1";
|
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).toThrow(
|
|
||||||
"Either AWS_BEARER_TOKEN_BEDROCK or both AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY are required when using AWS Bedrock.",
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should report missing region and authentication", () => {
|
|
||||||
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).toThrow(
|
expect(() => validateEnvironmentVariables()).toThrow(
|
||||||
/AWS_REGION is required when using AWS Bedrock.*Either AWS_BEARER_TOKEN_BEDROCK or both AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY are required when using AWS Bedrock/s,
|
/AWS_REGION is required when using AWS Bedrock.*AWS_ACCESS_KEY_ID is required when using AWS Bedrock.*AWS_SECRET_ACCESS_KEY is required when using AWS Bedrock/s,
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
@@ -198,56 +167,6 @@ describe("validateEnvironmentVariables", () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
describe("Microsoft Foundry", () => {
|
|
||||||
test("should pass when ANTHROPIC_FOUNDRY_RESOURCE is provided", () => {
|
|
||||||
process.env.CLAUDE_CODE_USE_FOUNDRY = "1";
|
|
||||||
process.env.ANTHROPIC_FOUNDRY_RESOURCE = "test-resource";
|
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).not.toThrow();
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should pass when ANTHROPIC_FOUNDRY_BASE_URL is provided", () => {
|
|
||||||
process.env.CLAUDE_CODE_USE_FOUNDRY = "1";
|
|
||||||
process.env.ANTHROPIC_FOUNDRY_BASE_URL =
|
|
||||||
"https://test-resource.services.ai.azure.com";
|
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).not.toThrow();
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should pass when both resource and base URL are provided", () => {
|
|
||||||
process.env.CLAUDE_CODE_USE_FOUNDRY = "1";
|
|
||||||
process.env.ANTHROPIC_FOUNDRY_RESOURCE = "test-resource";
|
|
||||||
process.env.ANTHROPIC_FOUNDRY_BASE_URL =
|
|
||||||
"https://custom.services.ai.azure.com";
|
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).not.toThrow();
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should construct Foundry base URL from resource name when ANTHROPIC_FOUNDRY_BASE_URL is not provided", () => {
|
|
||||||
// This test verifies our action.yml change, which constructs:
|
|
||||||
// ANTHROPIC_FOUNDRY_BASE_URL: ${{ env.ANTHROPIC_FOUNDRY_BASE_URL || (env.ANTHROPIC_FOUNDRY_RESOURCE && format('https://{0}.services.ai.azure.com', env.ANTHROPIC_FOUNDRY_RESOURCE)) }}
|
|
||||||
|
|
||||||
process.env.CLAUDE_CODE_USE_FOUNDRY = "1";
|
|
||||||
process.env.ANTHROPIC_FOUNDRY_RESOURCE = "my-foundry-resource";
|
|
||||||
// ANTHROPIC_FOUNDRY_BASE_URL is intentionally not set
|
|
||||||
|
|
||||||
// The actual URL construction happens in the composite action in action.yml
|
|
||||||
// This test is a placeholder to document the behavior
|
|
||||||
expect(() => validateEnvironmentVariables()).not.toThrow();
|
|
||||||
|
|
||||||
// In the actual action, ANTHROPIC_FOUNDRY_BASE_URL would be:
|
|
||||||
// https://my-foundry-resource.services.ai.azure.com
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should fail when neither ANTHROPIC_FOUNDRY_RESOURCE nor ANTHROPIC_FOUNDRY_BASE_URL is provided", () => {
|
|
||||||
process.env.CLAUDE_CODE_USE_FOUNDRY = "1";
|
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).toThrow(
|
|
||||||
"Either ANTHROPIC_FOUNDRY_RESOURCE or ANTHROPIC_FOUNDRY_BASE_URL is required when using Microsoft Foundry.",
|
|
||||||
);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe("Multiple providers", () => {
|
describe("Multiple providers", () => {
|
||||||
test("should fail when both Bedrock and Vertex are enabled", () => {
|
test("should fail when both Bedrock and Vertex are enabled", () => {
|
||||||
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
||||||
@@ -260,51 +179,7 @@ describe("validateEnvironmentVariables", () => {
|
|||||||
process.env.CLOUD_ML_REGION = "us-central1";
|
process.env.CLOUD_ML_REGION = "us-central1";
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).toThrow(
|
expect(() => validateEnvironmentVariables()).toThrow(
|
||||||
"Cannot use multiple providers simultaneously. Please set only one of: CLAUDE_CODE_USE_BEDROCK, CLAUDE_CODE_USE_VERTEX, or CLAUDE_CODE_USE_FOUNDRY.",
|
"Cannot use both Bedrock and Vertex AI simultaneously. Please set only one provider.",
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should fail when both Bedrock and Foundry are enabled", () => {
|
|
||||||
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
|
||||||
process.env.CLAUDE_CODE_USE_FOUNDRY = "1";
|
|
||||||
// Provide all required vars to isolate the mutual exclusion error
|
|
||||||
process.env.AWS_REGION = "us-east-1";
|
|
||||||
process.env.AWS_ACCESS_KEY_ID = "test-access-key";
|
|
||||||
process.env.AWS_SECRET_ACCESS_KEY = "test-secret-key";
|
|
||||||
process.env.ANTHROPIC_FOUNDRY_RESOURCE = "test-resource";
|
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).toThrow(
|
|
||||||
"Cannot use multiple providers simultaneously. Please set only one of: CLAUDE_CODE_USE_BEDROCK, CLAUDE_CODE_USE_VERTEX, or CLAUDE_CODE_USE_FOUNDRY.",
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should fail when both Vertex and Foundry are enabled", () => {
|
|
||||||
process.env.CLAUDE_CODE_USE_VERTEX = "1";
|
|
||||||
process.env.CLAUDE_CODE_USE_FOUNDRY = "1";
|
|
||||||
// Provide all required vars to isolate the mutual exclusion error
|
|
||||||
process.env.ANTHROPIC_VERTEX_PROJECT_ID = "test-project";
|
|
||||||
process.env.CLOUD_ML_REGION = "us-central1";
|
|
||||||
process.env.ANTHROPIC_FOUNDRY_RESOURCE = "test-resource";
|
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).toThrow(
|
|
||||||
"Cannot use multiple providers simultaneously. Please set only one of: CLAUDE_CODE_USE_BEDROCK, CLAUDE_CODE_USE_VERTEX, or CLAUDE_CODE_USE_FOUNDRY.",
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
test("should fail when all three providers are enabled", () => {
|
|
||||||
process.env.CLAUDE_CODE_USE_BEDROCK = "1";
|
|
||||||
process.env.CLAUDE_CODE_USE_VERTEX = "1";
|
|
||||||
process.env.CLAUDE_CODE_USE_FOUNDRY = "1";
|
|
||||||
// Provide all required vars to isolate the mutual exclusion error
|
|
||||||
process.env.AWS_REGION = "us-east-1";
|
|
||||||
process.env.AWS_ACCESS_KEY_ID = "test-access-key";
|
|
||||||
process.env.AWS_SECRET_ACCESS_KEY = "test-secret-key";
|
|
||||||
process.env.ANTHROPIC_VERTEX_PROJECT_ID = "test-project";
|
|
||||||
process.env.CLOUD_ML_REGION = "us-central1";
|
|
||||||
process.env.ANTHROPIC_FOUNDRY_RESOURCE = "test-resource";
|
|
||||||
|
|
||||||
expect(() => validateEnvironmentVariables()).toThrow(
|
|
||||||
"Cannot use multiple providers simultaneously. Please set only one of: CLAUDE_CODE_USE_BEDROCK, CLAUDE_CODE_USE_VERTEX, or CLAUDE_CODE_USE_FOUNDRY.",
|
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
@@ -329,7 +204,10 @@ describe("validateEnvironmentVariables", () => {
|
|||||||
" - AWS_REGION is required when using AWS Bedrock.",
|
" - AWS_REGION is required when using AWS Bedrock.",
|
||||||
);
|
);
|
||||||
expect(error!.message).toContain(
|
expect(error!.message).toContain(
|
||||||
" - Either AWS_BEARER_TOKEN_BEDROCK or both AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY are required when using AWS Bedrock.",
|
" - AWS_ACCESS_KEY_ID is required when using AWS Bedrock.",
|
||||||
|
);
|
||||||
|
expect(error!.message).toContain(
|
||||||
|
" - AWS_SECRET_ACCESS_KEY is required when using AWS Bedrock.",
|
||||||
);
|
);
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
33
bun.lock
33
bun.lock
@@ -6,7 +6,6 @@
|
|||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": "^1.10.1",
|
"@actions/core": "^1.10.1",
|
||||||
"@actions/github": "^6.0.1",
|
"@actions/github": "^6.0.1",
|
||||||
"@anthropic-ai/claude-agent-sdk": "^0.1.52",
|
|
||||||
"@modelcontextprotocol/sdk": "^1.11.0",
|
"@modelcontextprotocol/sdk": "^1.11.0",
|
||||||
"@octokit/graphql": "^8.2.2",
|
"@octokit/graphql": "^8.2.2",
|
||||||
"@octokit/rest": "^21.1.1",
|
"@octokit/rest": "^21.1.1",
|
||||||
@@ -36,40 +35,8 @@
|
|||||||
|
|
||||||
"@actions/io": ["@actions/io@1.1.3", "", {}, "sha512-wi9JjgKLYS7U/z8PPbco+PvTb/nRWjeoFlJ1Qer83k/3C5PHQi28hiVdeE2kHXmIL99mQFawx8qt/JPjZilJ8Q=="],
|
"@actions/io": ["@actions/io@1.1.3", "", {}, "sha512-wi9JjgKLYS7U/z8PPbco+PvTb/nRWjeoFlJ1Qer83k/3C5PHQi28hiVdeE2kHXmIL99mQFawx8qt/JPjZilJ8Q=="],
|
||||||
|
|
||||||
"@anthropic-ai/claude-agent-sdk": ["@anthropic-ai/claude-agent-sdk@0.1.52", "", { "optionalDependencies": { "@img/sharp-darwin-arm64": "^0.33.5", "@img/sharp-darwin-x64": "^0.33.5", "@img/sharp-linux-arm": "^0.33.5", "@img/sharp-linux-arm64": "^0.33.5", "@img/sharp-linux-x64": "^0.33.5", "@img/sharp-linuxmusl-arm64": "^0.33.5", "@img/sharp-linuxmusl-x64": "^0.33.5", "@img/sharp-win32-x64": "^0.33.5" }, "peerDependencies": { "zod": "^3.24.1" } }, "sha512-yF8N05+9NRbqYA/h39jQ726HTQFrdXXp7pEfDNKIJ2c4FdWvEjxBA/8ciZIebN6/PyvGDcbEp3yq2Co4rNpg6A=="],
|
|
||||||
|
|
||||||
"@fastify/busboy": ["@fastify/busboy@2.1.1", "", {}, "sha512-vBZP4NlzfOlerQTnba4aqZoMhE/a9HY7HRqoOPaETQcSQuWEIyZMHGfVu6w9wGtGK5fED5qRs2DteVCjOH60sA=="],
|
"@fastify/busboy": ["@fastify/busboy@2.1.1", "", {}, "sha512-vBZP4NlzfOlerQTnba4aqZoMhE/a9HY7HRqoOPaETQcSQuWEIyZMHGfVu6w9wGtGK5fED5qRs2DteVCjOH60sA=="],
|
||||||
|
|
||||||
"@img/sharp-darwin-arm64": ["@img/sharp-darwin-arm64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-darwin-arm64": "1.0.4" }, "os": "darwin", "cpu": "arm64" }, "sha512-UT4p+iz/2H4twwAoLCqfA9UH5pI6DggwKEGuaPy7nCVQ8ZsiY5PIcrRvD1DzuY3qYL07NtIQcWnBSY/heikIFQ=="],
|
|
||||||
|
|
||||||
"@img/sharp-darwin-x64": ["@img/sharp-darwin-x64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-darwin-x64": "1.0.4" }, "os": "darwin", "cpu": "x64" }, "sha512-fyHac4jIc1ANYGRDxtiqelIbdWkIuQaI84Mv45KvGRRxSAa7o7d1ZKAOBaYbnepLC1WqxfpimdeWfvqqSGwR2Q=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-darwin-arm64": ["@img/sharp-libvips-darwin-arm64@1.0.4", "", { "os": "darwin", "cpu": "arm64" }, "sha512-XblONe153h0O2zuFfTAbQYAX2JhYmDHeWikp1LM9Hul9gVPjFY427k6dFEcOL72O01QxQsWi761svJ/ev9xEDg=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-darwin-x64": ["@img/sharp-libvips-darwin-x64@1.0.4", "", { "os": "darwin", "cpu": "x64" }, "sha512-xnGR8YuZYfJGmWPvmlunFaWJsb9T/AO2ykoP3Fz/0X5XV2aoYBPkX6xqCQvUTKKiLddarLaxpzNe+b1hjeWHAQ=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-linux-arm": ["@img/sharp-libvips-linux-arm@1.0.5", "", { "os": "linux", "cpu": "arm" }, "sha512-gvcC4ACAOPRNATg/ov8/MnbxFDJqf/pDePbBnuBDcjsI8PssmjoKMAz4LtLaVi+OnSb5FK/yIOamqDwGmXW32g=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-linux-arm64": ["@img/sharp-libvips-linux-arm64@1.0.4", "", { "os": "linux", "cpu": "arm64" }, "sha512-9B+taZ8DlyyqzZQnoeIvDVR/2F4EbMepXMc/NdVbkzsJbzkUjhXv/70GQJ7tdLA4YJgNP25zukcxpX2/SueNrA=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-linux-x64": ["@img/sharp-libvips-linux-x64@1.0.4", "", { "os": "linux", "cpu": "x64" }, "sha512-MmWmQ3iPFZr0Iev+BAgVMb3ZyC4KeFc3jFxnNbEPas60e1cIfevbtuyf9nDGIzOaW9PdnDciJm+wFFaTlj5xYw=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-linuxmusl-arm64": ["@img/sharp-libvips-linuxmusl-arm64@1.0.4", "", { "os": "linux", "cpu": "arm64" }, "sha512-9Ti+BbTYDcsbp4wfYib8Ctm1ilkugkA/uscUn6UXK1ldpC1JjiXbLfFZtRlBhjPZ5o1NCLiDbg8fhUPKStHoTA=="],
|
|
||||||
|
|
||||||
"@img/sharp-libvips-linuxmusl-x64": ["@img/sharp-libvips-linuxmusl-x64@1.0.4", "", { "os": "linux", "cpu": "x64" }, "sha512-viYN1KX9m+/hGkJtvYYp+CCLgnJXwiQB39damAO7WMdKWlIhmYTfHjwSbQeUK/20vY154mwezd9HflVFM1wVSw=="],
|
|
||||||
|
|
||||||
"@img/sharp-linux-arm": ["@img/sharp-linux-arm@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-linux-arm": "1.0.5" }, "os": "linux", "cpu": "arm" }, "sha512-JTS1eldqZbJxjvKaAkxhZmBqPRGmxgu+qFKSInv8moZ2AmT5Yib3EQ1c6gp493HvrvV8QgdOXdyaIBrhvFhBMQ=="],
|
|
||||||
|
|
||||||
"@img/sharp-linux-arm64": ["@img/sharp-linux-arm64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-linux-arm64": "1.0.4" }, "os": "linux", "cpu": "arm64" }, "sha512-JMVv+AMRyGOHtO1RFBiJy/MBsgz0x4AWrT6QoEVVTyh1E39TrCUpTRI7mx9VksGX4awWASxqCYLCV4wBZHAYxA=="],
|
|
||||||
|
|
||||||
"@img/sharp-linux-x64": ["@img/sharp-linux-x64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-linux-x64": "1.0.4" }, "os": "linux", "cpu": "x64" }, "sha512-opC+Ok5pRNAzuvq1AG0ar+1owsu842/Ab+4qvU879ippJBHvyY5n2mxF1izXqkPYlGuP/M556uh53jRLJmzTWA=="],
|
|
||||||
|
|
||||||
"@img/sharp-linuxmusl-arm64": ["@img/sharp-linuxmusl-arm64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-linuxmusl-arm64": "1.0.4" }, "os": "linux", "cpu": "arm64" }, "sha512-XrHMZwGQGvJg2V/oRSUfSAfjfPxO+4DkiRh6p2AFjLQztWUuY/o8Mq0eMQVIY7HJ1CDQUJlxGGZRw1a5bqmd1g=="],
|
|
||||||
|
|
||||||
"@img/sharp-linuxmusl-x64": ["@img/sharp-linuxmusl-x64@0.33.5", "", { "optionalDependencies": { "@img/sharp-libvips-linuxmusl-x64": "1.0.4" }, "os": "linux", "cpu": "x64" }, "sha512-WT+d/cgqKkkKySYmqoZ8y3pxx7lx9vVejxW/W4DOFMYVSkErR+w7mf2u8m/y4+xHe7yY9DAXQMWQhpnMuFfScw=="],
|
|
||||||
|
|
||||||
"@img/sharp-win32-x64": ["@img/sharp-win32-x64@0.33.5", "", { "os": "win32", "cpu": "x64" }, "sha512-MpY/o8/8kj+EcnxwvrP4aTJSWw/aZ7JIGR4aBeZkZw5B7/Jn+tY9/VNwtcoGmdT7GfggGIU4kygOMSbYnOrAbg=="],
|
|
||||||
|
|
||||||
"@modelcontextprotocol/sdk": ["@modelcontextprotocol/sdk@1.16.0", "", { "dependencies": { "ajv": "^6.12.6", "content-type": "^1.0.5", "cors": "^2.8.5", "cross-spawn": "^7.0.5", "eventsource": "^3.0.2", "eventsource-parser": "^3.0.0", "express": "^5.0.1", "express-rate-limit": "^7.5.0", "pkce-challenge": "^5.0.0", "raw-body": "^3.0.0", "zod": "^3.23.8", "zod-to-json-schema": "^3.24.1" } }, "sha512-8ofX7gkZcLj9H9rSd50mCgm3SSF8C7XoclxJuLoV0Cz3rEQ1tv9MZRYYvJtm9n1BiEQQMzSmE/w2AEkNacLYfg=="],
|
"@modelcontextprotocol/sdk": ["@modelcontextprotocol/sdk@1.16.0", "", { "dependencies": { "ajv": "^6.12.6", "content-type": "^1.0.5", "cors": "^2.8.5", "cross-spawn": "^7.0.5", "eventsource": "^3.0.2", "eventsource-parser": "^3.0.0", "express": "^5.0.1", "express-rate-limit": "^7.5.0", "pkce-challenge": "^5.0.0", "raw-body": "^3.0.0", "zod": "^3.23.8", "zod-to-json-schema": "^3.24.1" } }, "sha512-8ofX7gkZcLj9H9rSd50mCgm3SSF8C7XoclxJuLoV0Cz3rEQ1tv9MZRYYvJtm9n1BiEQQMzSmE/w2AEkNacLYfg=="],
|
||||||
|
|
||||||
"@octokit/auth-token": ["@octokit/auth-token@4.0.0", "", {}, "sha512-tY/msAuJo6ARbK6SPIxZrPBms3xPbfwBrulZe0Wtr/DIY9lje2HeV1uoebShn6mx7SjCHif6EjMvoREj+gZ+SA=="],
|
"@octokit/auth-token": ["@octokit/auth-token@4.0.0", "", {}, "sha512-tY/msAuJo6ARbK6SPIxZrPBms3xPbfwBrulZe0Wtr/DIY9lje2HeV1uoebShn6mx7SjCHif6EjMvoREj+gZ+SA=="],
|
||||||
|
|||||||
@@ -1,17 +1,16 @@
|
|||||||
# Cloud Providers
|
# Cloud Providers
|
||||||
|
|
||||||
You can authenticate with Claude using any of these four methods:
|
You can authenticate with Claude using any of these three methods:
|
||||||
|
|
||||||
1. Direct Anthropic API (default)
|
1. Direct Anthropic API (default)
|
||||||
2. Amazon Bedrock with OIDC authentication
|
2. Amazon Bedrock with OIDC authentication
|
||||||
3. Google Vertex AI with OIDC authentication
|
3. Google Vertex AI with OIDC authentication
|
||||||
4. Microsoft Foundry with OIDC authentication
|
|
||||||
|
|
||||||
For detailed setup instructions for AWS Bedrock and Google Vertex AI, see the [official documentation](https://docs.anthropic.com/en/docs/claude-code/github-actions#using-with-aws-bedrock-%26-google-vertex-ai).
|
For detailed setup instructions for AWS Bedrock and Google Vertex AI, see the [official documentation](https://docs.anthropic.com/en/docs/claude-code/github-actions#using-with-aws-bedrock-%26-google-vertex-ai).
|
||||||
|
|
||||||
**Note**:
|
**Note**:
|
||||||
|
|
||||||
- Bedrock, Vertex, and Microsoft Foundry use OIDC authentication exclusively
|
- Bedrock and Vertex use OIDC authentication exclusively
|
||||||
- AWS Bedrock automatically uses cross-region inference profiles for certain models
|
- AWS Bedrock automatically uses cross-region inference profiles for certain models
|
||||||
- For cross-region inference profile models, you need to request and be granted access to the Claude models in all regions that the inference profile uses
|
- For cross-region inference profile models, you need to request and be granted access to the Claude models in all regions that the inference profile uses
|
||||||
|
|
||||||
@@ -41,19 +40,11 @@ Use provider-specific model names based on your chosen provider:
|
|||||||
claude_args: |
|
claude_args: |
|
||||||
--model claude-4-0-sonnet@20250805
|
--model claude-4-0-sonnet@20250805
|
||||||
# ... other inputs
|
# ... other inputs
|
||||||
|
|
||||||
# For Microsoft Foundry with OIDC
|
|
||||||
- uses: anthropics/claude-code-action@v1
|
|
||||||
with:
|
|
||||||
use_foundry: "true"
|
|
||||||
claude_args: |
|
|
||||||
--model claude-sonnet-4-5
|
|
||||||
# ... other inputs
|
|
||||||
```
|
```
|
||||||
|
|
||||||
## OIDC Authentication for Cloud Providers
|
## OIDC Authentication for Bedrock and Vertex
|
||||||
|
|
||||||
AWS Bedrock, GCP Vertex AI, and Microsoft Foundry all support OIDC authentication.
|
Both AWS Bedrock and GCP Vertex AI require OIDC authentication.
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
# For AWS Bedrock with OIDC
|
# For AWS Bedrock with OIDC
|
||||||
@@ -106,36 +97,3 @@ AWS Bedrock, GCP Vertex AI, and Microsoft Foundry all support OIDC authenticatio
|
|||||||
permissions:
|
permissions:
|
||||||
id-token: write # Required for OIDC
|
id-token: write # Required for OIDC
|
||||||
```
|
```
|
||||||
|
|
||||||
```yaml
|
|
||||||
# For Microsoft Foundry with OIDC
|
|
||||||
- name: Authenticate to Azure
|
|
||||||
uses: azure/login@v2
|
|
||||||
with:
|
|
||||||
client-id: ${{ secrets.AZURE_CLIENT_ID }}
|
|
||||||
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
|
|
||||||
subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }}
|
|
||||||
|
|
||||||
- name: Generate GitHub App token
|
|
||||||
id: app-token
|
|
||||||
uses: actions/create-github-app-token@v2
|
|
||||||
with:
|
|
||||||
app-id: ${{ secrets.APP_ID }}
|
|
||||||
private-key: ${{ secrets.APP_PRIVATE_KEY }}
|
|
||||||
|
|
||||||
- uses: anthropics/claude-code-action@v1
|
|
||||||
with:
|
|
||||||
use_foundry: "true"
|
|
||||||
claude_args: |
|
|
||||||
--model claude-sonnet-4-5
|
|
||||||
# ... other inputs
|
|
||||||
env:
|
|
||||||
ANTHROPIC_FOUNDRY_BASE_URL: https://my-resource.services.ai.azure.com
|
|
||||||
|
|
||||||
permissions:
|
|
||||||
id-token: write # Required for OIDC
|
|
||||||
```
|
|
||||||
|
|
||||||
## Microsoft Foundry Setup
|
|
||||||
|
|
||||||
For detailed setup instructions for Microsoft Foundry, see the [official documentation](https://docs.anthropic.com/en/docs/claude-code/microsoft-foundry).
|
|
||||||
|
|||||||
@@ -61,3 +61,68 @@ For specialized use cases, you can fine-tune behavior using `claude_args`:
|
|||||||
--system-prompt "You are a code review specialist"
|
--system-prompt "You are a code review specialist"
|
||||||
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
```
|
```
|
||||||
|
|
||||||
|
## Network Restrictions
|
||||||
|
|
||||||
|
For enhanced security, you can restrict Claude's network access to specific domains only. This feature is particularly useful for:
|
||||||
|
|
||||||
|
- Enterprise environments with strict security policies
|
||||||
|
- Preventing access to external services
|
||||||
|
- Limiting Claude to only your internal APIs and services
|
||||||
|
|
||||||
|
When `experimental_allowed_domains` is set, Claude can only access the domains you explicitly list. You'll need to include the appropriate provider domains based on your authentication method.
|
||||||
|
|
||||||
|
### Provider-Specific Examples
|
||||||
|
|
||||||
|
#### If using Anthropic API or subscription
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- uses: anthropics/claude-code-action@v1
|
||||||
|
with:
|
||||||
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
|
# Or: claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
|
||||||
|
experimental_allowed_domains: |
|
||||||
|
.anthropic.com
|
||||||
|
```
|
||||||
|
|
||||||
|
#### If using AWS Bedrock
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- uses: anthropics/claude-code-action@v1
|
||||||
|
with:
|
||||||
|
use_bedrock: "true"
|
||||||
|
experimental_allowed_domains: |
|
||||||
|
bedrock.*.amazonaws.com
|
||||||
|
bedrock-runtime.*.amazonaws.com
|
||||||
|
```
|
||||||
|
|
||||||
|
#### If using Google Vertex AI
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- uses: anthropics/claude-code-action@v1
|
||||||
|
with:
|
||||||
|
use_vertex: "true"
|
||||||
|
experimental_allowed_domains: |
|
||||||
|
*.googleapis.com
|
||||||
|
vertexai.googleapis.com
|
||||||
|
```
|
||||||
|
|
||||||
|
### Common GitHub Domains
|
||||||
|
|
||||||
|
In addition to your provider domains, you may need to include GitHub-related domains. For GitHub.com users, common domains include:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- uses: anthropics/claude-code-action@v1
|
||||||
|
with:
|
||||||
|
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
|
||||||
|
experimental_allowed_domains: |
|
||||||
|
.anthropic.com # For Anthropic API
|
||||||
|
.github.com
|
||||||
|
.githubusercontent.com
|
||||||
|
ghcr.io
|
||||||
|
.blob.core.windows.net
|
||||||
|
```
|
||||||
|
|
||||||
|
For GitHub Enterprise users, replace the GitHub.com domains above with your enterprise domains (e.g., `.github.company.com`, `packages.company.com`, etc.).
|
||||||
|
|
||||||
|
To determine which domains your workflow needs, you can temporarily run without restrictions and monitor the network requests, or check your GitHub Enterprise configuration for the specific services you use.
|
||||||
|
|||||||
@@ -38,7 +38,7 @@ The following permissions are requested but not yet actively used. These will en
|
|||||||
|
|
||||||
## Commit Signing
|
## Commit Signing
|
||||||
|
|
||||||
Commits made by Claude through this action are no longer automatically signed with commit signatures. To enable commit signing set `use_commit_signing: True` in the workflow(s). This ensures the authenticity and integrity of commits, providing a verifiable trail of changes made by the action.
|
All commits made by Claude through this action are automatically signed with commit signatures. This ensures the authenticity and integrity of commits, providing a verifiable trail of changes made by the action.
|
||||||
|
|
||||||
## ⚠️ Authentication Protection
|
## ⚠️ Authentication Protection
|
||||||
|
|
||||||
|
|||||||
@@ -70,6 +70,7 @@ jobs:
|
|||||||
| `branch_prefix` | The prefix to use for Claude branches (defaults to 'claude/', use 'claude-' for dash format) | No | `claude/` |
|
| `branch_prefix` | The prefix to use for Claude branches (defaults to 'claude/', use 'claude-' for dash format) | No | `claude/` |
|
||||||
| `settings` | Claude Code settings as JSON string or path to settings JSON file | No | "" |
|
| `settings` | Claude Code settings as JSON string or path to settings JSON file | No | "" |
|
||||||
| `additional_permissions` | Additional permissions to enable. Currently supports 'actions: read' for viewing workflow results | No | "" |
|
| `additional_permissions` | Additional permissions to enable. Currently supports 'actions: read' for viewing workflow results | No | "" |
|
||||||
|
| `experimental_allowed_domains` | Restrict network access to these domains only (newline-separated). | No | "" |
|
||||||
| `use_commit_signing` | Enable commit signing using GitHub's commit signature verification. When false, Claude uses standard git commands | No | `false` |
|
| `use_commit_signing` | Enable commit signing using GitHub's commit signature verification. When false, Claude uses standard git commands | No | `false` |
|
||||||
| `bot_id` | GitHub user ID to use for git operations (defaults to Claude's bot ID) | No | `41898282` |
|
| `bot_id` | GitHub user ID to use for git operations (defaults to Claude's bot ID) | No | `41898282` |
|
||||||
| `bot_name` | GitHub username to use for git operations (defaults to Claude's bot name) | No | `claude[bot]` |
|
| `bot_name` | GitHub username to use for git operations (defaults to Claude's bot name) | No | `claude[bot]` |
|
||||||
@@ -79,6 +80,7 @@ jobs:
|
|||||||
| `path_to_bun_executable` | Optional path to a custom Bun executable. Skips automatic Bun installation. Useful for Nix, custom containers, or specialized environments | No | "" |
|
| `path_to_bun_executable` | Optional path to a custom Bun executable. Skips automatic Bun installation. Useful for Nix, custom containers, or specialized environments | No | "" |
|
||||||
| `plugin_marketplaces` | Newline-separated list of Claude Code plugin marketplace Git URLs to install from (e.g., see example in workflow above). Marketplaces are added before plugin installation | No | "" |
|
| `plugin_marketplaces` | Newline-separated list of Claude Code plugin marketplace Git URLs to install from (e.g., see example in workflow above). Marketplaces are added before plugin installation | No | "" |
|
||||||
| `plugins` | Newline-separated list of Claude Code plugin names to install (e.g., see example in workflow above). Plugins are installed before Claude Code execution | No | "" |
|
| `plugins` | Newline-separated list of Claude Code plugin names to install (e.g., see example in workflow above). Plugins are installed before Claude Code execution | No | "" |
|
||||||
|
| `json_schema` | JSON schema for structured output validation. Automatically sets GitHub Action outputs for each field. See [Structured Outputs](#structured-outputs) section below | No | "" |
|
||||||
|
|
||||||
### Deprecated Inputs
|
### Deprecated Inputs
|
||||||
|
|
||||||
@@ -199,8 +201,16 @@ Get validated JSON results from Claude that automatically become GitHub Action o
|
|||||||
prompt: |
|
prompt: |
|
||||||
Check the CI logs and determine if this is a flaky test.
|
Check the CI logs and determine if this is a flaky test.
|
||||||
Return: is_flaky (boolean), confidence (0-1), summary (string)
|
Return: is_flaky (boolean), confidence (0-1), summary (string)
|
||||||
claude_args: |
|
json_schema: |
|
||||||
--json-schema '{"type":"object","properties":{"is_flaky":{"type":"boolean"},"confidence":{"type":"number"},"summary":{"type":"string"}},"required":["is_flaky"]}'
|
{
|
||||||
|
"type": "object",
|
||||||
|
"properties": {
|
||||||
|
"is_flaky": {"type": "boolean"},
|
||||||
|
"confidence": {"type": "number"},
|
||||||
|
"summary": {"type": "string"}
|
||||||
|
},
|
||||||
|
"required": ["is_flaky"]
|
||||||
|
}
|
||||||
|
|
||||||
- name: Retry if flaky
|
- name: Retry if flaky
|
||||||
if: fromJSON(steps.analyze.outputs.structured_output).is_flaky == true
|
if: fromJSON(steps.analyze.outputs.structured_output).is_flaky == true
|
||||||
@@ -209,7 +219,7 @@ Get validated JSON results from Claude that automatically become GitHub Action o
|
|||||||
|
|
||||||
### How It Works
|
### How It Works
|
||||||
|
|
||||||
1. **Define Schema**: Provide a JSON schema via `--json-schema` flag in `claude_args`
|
1. **Define Schema**: Provide a JSON schema in the `json_schema` input
|
||||||
2. **Claude Executes**: Claude uses tools to complete your task
|
2. **Claude Executes**: Claude uses tools to complete your task
|
||||||
3. **Validated Output**: Result is validated against your schema
|
3. **Validated Output**: Result is validated against your schema
|
||||||
4. **JSON Output**: All fields are returned in a single `structured_output` JSON string
|
4. **JSON Output**: All fields are returned in a single `structured_output` JSON string
|
||||||
|
|||||||
@@ -43,8 +43,27 @@ jobs:
|
|||||||
- is_flaky: true if likely flaky, false if real bug
|
- is_flaky: true if likely flaky, false if real bug
|
||||||
- confidence: number 0-1 indicating confidence level
|
- confidence: number 0-1 indicating confidence level
|
||||||
- summary: brief one-sentence explanation
|
- summary: brief one-sentence explanation
|
||||||
claude_args: |
|
json_schema: |
|
||||||
--json-schema '{"type":"object","properties":{"is_flaky":{"type":"boolean","description":"Whether this appears to be a flaky test failure"},"confidence":{"type":"number","minimum":0,"maximum":1,"description":"Confidence level in the determination"},"summary":{"type":"string","description":"One-sentence explanation of the failure"}},"required":["is_flaky","confidence","summary"]}'
|
{
|
||||||
|
"type": "object",
|
||||||
|
"properties": {
|
||||||
|
"is_flaky": {
|
||||||
|
"type": "boolean",
|
||||||
|
"description": "Whether this appears to be a flaky test failure"
|
||||||
|
},
|
||||||
|
"confidence": {
|
||||||
|
"type": "number",
|
||||||
|
"minimum": 0,
|
||||||
|
"maximum": 1,
|
||||||
|
"description": "Confidence level in the determination"
|
||||||
|
},
|
||||||
|
"summary": {
|
||||||
|
"type": "string",
|
||||||
|
"description": "One-sentence explanation of the failure"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"required": ["is_flaky", "confidence", "summary"]
|
||||||
|
}
|
||||||
|
|
||||||
# Auto-retry only if flaky AND high confidence (>= 0.7)
|
# Auto-retry only if flaky AND high confidence (>= 0.7)
|
||||||
- name: Retry flaky tests
|
- name: Retry flaky tests
|
||||||
|
|||||||
@@ -12,7 +12,6 @@
|
|||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@actions/core": "^1.10.1",
|
"@actions/core": "^1.10.1",
|
||||||
"@actions/github": "^6.0.1",
|
"@actions/github": "^6.0.1",
|
||||||
"@anthropic-ai/claude-agent-sdk": "^0.1.52",
|
|
||||||
"@modelcontextprotocol/sdk": "^1.11.0",
|
"@modelcontextprotocol/sdk": "^1.11.0",
|
||||||
"@octokit/graphql": "^8.2.2",
|
"@octokit/graphql": "^8.2.2",
|
||||||
"@octokit/rest": "^21.1.1",
|
"@octokit/rest": "^21.1.1",
|
||||||
|
|||||||
123
scripts/setup-network-restrictions.sh
Executable file
123
scripts/setup-network-restrictions.sh
Executable file
@@ -0,0 +1,123 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
# Setup Network Restrictions with Squid Proxy
|
||||||
|
# This script sets up a Squid proxy to restrict network access to whitelisted domains only.
|
||||||
|
|
||||||
|
set -e
|
||||||
|
|
||||||
|
# Check if experimental_allowed_domains is provided
|
||||||
|
if [ -z "$EXPERIMENTAL_ALLOWED_DOMAINS" ]; then
|
||||||
|
echo "ERROR: EXPERIMENTAL_ALLOWED_DOMAINS environment variable is required"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Check required environment variables
|
||||||
|
if [ -z "$RUNNER_TEMP" ]; then
|
||||||
|
echo "ERROR: RUNNER_TEMP environment variable is required"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ -z "$GITHUB_ENV" ]; then
|
||||||
|
echo "ERROR: GITHUB_ENV environment variable is required"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "Setting up network restrictions with Squid proxy..."
|
||||||
|
|
||||||
|
SQUID_START_TIME=$(date +%s.%N)
|
||||||
|
|
||||||
|
# Create whitelist file
|
||||||
|
echo "$EXPERIMENTAL_ALLOWED_DOMAINS" > $RUNNER_TEMP/whitelist.txt
|
||||||
|
|
||||||
|
# Ensure each domain has proper format
|
||||||
|
# If domain doesn't start with a dot and isn't an IP, add the dot for subdomain matching
|
||||||
|
mv $RUNNER_TEMP/whitelist.txt $RUNNER_TEMP/whitelist.txt.orig
|
||||||
|
while IFS= read -r domain; do
|
||||||
|
if [ -n "$domain" ]; then
|
||||||
|
# Trim whitespace
|
||||||
|
domain=$(echo "$domain" | xargs)
|
||||||
|
# If it's not empty and doesn't start with a dot, add one
|
||||||
|
if [[ "$domain" != .* ]] && [[ ! "$domain" =~ ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
|
||||||
|
echo ".$domain" >> $RUNNER_TEMP/whitelist.txt
|
||||||
|
else
|
||||||
|
echo "$domain" >> $RUNNER_TEMP/whitelist.txt
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
done < $RUNNER_TEMP/whitelist.txt.orig
|
||||||
|
|
||||||
|
# Create Squid config with whitelist
|
||||||
|
echo "http_port 3128" > $RUNNER_TEMP/squid.conf
|
||||||
|
echo "" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "# Define ACLs" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "acl whitelist dstdomain \"/etc/squid/whitelist.txt\"" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "acl localnet src 127.0.0.1/32" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "acl localnet src 172.17.0.0/16" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "acl SSL_ports port 443" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "acl Safe_ports port 80" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "acl Safe_ports port 443" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "acl CONNECT method CONNECT" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "# Deny requests to certain unsafe ports" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "http_access deny !Safe_ports" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "# Only allow CONNECT to SSL ports" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "http_access deny CONNECT !SSL_ports" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "# Allow localhost" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "http_access allow localhost" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "# Allow localnet access to whitelisted domains" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "http_access allow localnet whitelist" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "# Deny everything else" >> $RUNNER_TEMP/squid.conf
|
||||||
|
echo "http_access deny all" >> $RUNNER_TEMP/squid.conf
|
||||||
|
|
||||||
|
echo "Starting Squid proxy..."
|
||||||
|
# First, remove any existing container
|
||||||
|
sudo docker rm -f squid-proxy 2>/dev/null || true
|
||||||
|
|
||||||
|
# Ensure whitelist file is not empty (Squid fails with empty files)
|
||||||
|
if [ ! -s "$RUNNER_TEMP/whitelist.txt" ]; then
|
||||||
|
echo "WARNING: Whitelist file is empty, adding a dummy entry"
|
||||||
|
echo ".example.com" >> $RUNNER_TEMP/whitelist.txt
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Use sudo to prevent Claude from stopping the container
|
||||||
|
CONTAINER_ID=$(sudo docker run -d \
|
||||||
|
--name squid-proxy \
|
||||||
|
-p 127.0.0.1:3128:3128 \
|
||||||
|
-v $RUNNER_TEMP/squid.conf:/etc/squid/squid.conf:ro \
|
||||||
|
-v $RUNNER_TEMP/whitelist.txt:/etc/squid/whitelist.txt:ro \
|
||||||
|
ubuntu/squid:latest 2>&1) || {
|
||||||
|
echo "ERROR: Failed to start Squid container"
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# Wait for proxy to be ready (usually < 1 second)
|
||||||
|
READY=false
|
||||||
|
for i in {1..30}; do
|
||||||
|
if nc -z 127.0.0.1 3128 2>/dev/null; then
|
||||||
|
TOTAL_TIME=$(echo "scale=3; $(date +%s.%N) - $SQUID_START_TIME" | bc)
|
||||||
|
echo "Squid proxy ready in ${TOTAL_TIME}s"
|
||||||
|
READY=true
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
sleep 0.1
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "$READY" != "true" ]; then
|
||||||
|
echo "ERROR: Squid proxy failed to start within 3 seconds"
|
||||||
|
echo "Container logs:"
|
||||||
|
sudo docker logs squid-proxy 2>&1 || true
|
||||||
|
echo "Container status:"
|
||||||
|
sudo docker ps -a | grep squid-proxy || true
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Set proxy environment variables
|
||||||
|
echo "http_proxy=http://127.0.0.1:3128" >> $GITHUB_ENV
|
||||||
|
echo "https_proxy=http://127.0.0.1:3128" >> $GITHUB_ENV
|
||||||
|
echo "HTTP_PROXY=http://127.0.0.1:3128" >> $GITHUB_ENV
|
||||||
|
echo "HTTPS_PROXY=http://127.0.0.1:3128" >> $GITHUB_ENV
|
||||||
|
|
||||||
|
echo "Network restrictions setup completed successfully"
|
||||||
@@ -192,6 +192,11 @@ export function prepareContext(
|
|||||||
if (!isPR) {
|
if (!isPR) {
|
||||||
throw new Error("IS_PR must be true for pull_request_review event");
|
throw new Error("IS_PR must be true for pull_request_review event");
|
||||||
}
|
}
|
||||||
|
if (!commentBody) {
|
||||||
|
throw new Error(
|
||||||
|
"COMMENT_BODY is required for pull_request_review event",
|
||||||
|
);
|
||||||
|
}
|
||||||
eventData = {
|
eventData = {
|
||||||
eventName: "pull_request_review",
|
eventName: "pull_request_review",
|
||||||
isPR: true,
|
isPR: true,
|
||||||
@@ -459,123 +464,6 @@ export function generatePrompt(
|
|||||||
return mode.generatePrompt(context, githubData, useCommitSigning);
|
return mode.generatePrompt(context, githubData, useCommitSigning);
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Generates a simplified prompt for tag mode (opt-in via USE_SIMPLE_PROMPT env var)
|
|
||||||
* @internal
|
|
||||||
*/
|
|
||||||
function generateSimplePrompt(
|
|
||||||
context: PreparedContext,
|
|
||||||
githubData: FetchDataResult,
|
|
||||||
useCommitSigning: boolean = false,
|
|
||||||
): string {
|
|
||||||
const {
|
|
||||||
contextData,
|
|
||||||
comments,
|
|
||||||
changedFilesWithSHA,
|
|
||||||
reviewData,
|
|
||||||
imageUrlMap,
|
|
||||||
} = githubData;
|
|
||||||
const { eventData } = context;
|
|
||||||
|
|
||||||
const { triggerContext } = getEventTypeAndContext(context);
|
|
||||||
|
|
||||||
const formattedContext = formatContext(contextData, eventData.isPR);
|
|
||||||
const formattedComments = formatComments(comments, imageUrlMap);
|
|
||||||
const formattedReviewComments = eventData.isPR
|
|
||||||
? formatReviewComments(reviewData, imageUrlMap)
|
|
||||||
: "";
|
|
||||||
const formattedChangedFiles = eventData.isPR
|
|
||||||
? formatChangedFilesWithSHA(changedFilesWithSHA)
|
|
||||||
: "";
|
|
||||||
|
|
||||||
const hasImages = imageUrlMap && imageUrlMap.size > 0;
|
|
||||||
const imagesInfo = hasImages
|
|
||||||
? `\n\n<images_info>
|
|
||||||
Images from comments have been saved to disk. Paths are in the formatted content above. Use Read tool to view them.
|
|
||||||
</images_info>`
|
|
||||||
: "";
|
|
||||||
|
|
||||||
const formattedBody = contextData?.body
|
|
||||||
? formatBody(contextData.body, imageUrlMap)
|
|
||||||
: "No description provided";
|
|
||||||
|
|
||||||
const entityType = eventData.isPR ? "pull request" : "issue";
|
|
||||||
const jobUrl = `${GITHUB_SERVER_URL}/${context.repository}/actions/runs/${process.env.GITHUB_RUN_ID}`;
|
|
||||||
|
|
||||||
let promptContent = `You were tagged on a GitHub ${entityType} via "${context.triggerPhrase}". Read the request and decide how to help.
|
|
||||||
|
|
||||||
<context>
|
|
||||||
${formattedContext}
|
|
||||||
</context>
|
|
||||||
|
|
||||||
<${eventData.isPR ? "pr" : "issue"}_body>
|
|
||||||
${formattedBody}
|
|
||||||
</${eventData.isPR ? "pr" : "issue"}_body>
|
|
||||||
|
|
||||||
<comments>
|
|
||||||
${formattedComments || "No comments"}
|
|
||||||
</comments>
|
|
||||||
${
|
|
||||||
eventData.isPR
|
|
||||||
? `
|
|
||||||
<review_comments>
|
|
||||||
${formattedReviewComments || "No review comments"}
|
|
||||||
</review_comments>
|
|
||||||
|
|
||||||
<changed_files>
|
|
||||||
${formattedChangedFiles || "No files changed"}
|
|
||||||
</changed_files>`
|
|
||||||
: ""
|
|
||||||
}${imagesInfo}
|
|
||||||
|
|
||||||
<metadata>
|
|
||||||
repository: ${context.repository}
|
|
||||||
${eventData.isPR && eventData.prNumber ? `pr_number: ${eventData.prNumber}` : ""}
|
|
||||||
${!eventData.isPR && eventData.issueNumber ? `issue_number: ${eventData.issueNumber}` : ""}
|
|
||||||
trigger: ${triggerContext}
|
|
||||||
triggered_by: ${context.triggerUsername ?? "Unknown"}
|
|
||||||
claude_comment_id: ${context.claudeCommentId}
|
|
||||||
</metadata>
|
|
||||||
${
|
|
||||||
(eventData.eventName === "issue_comment" ||
|
|
||||||
eventData.eventName === "pull_request_review_comment" ||
|
|
||||||
eventData.eventName === "pull_request_review") &&
|
|
||||||
eventData.commentBody
|
|
||||||
? `
|
|
||||||
<trigger_comment>
|
|
||||||
${sanitizeContent(eventData.commentBody)}
|
|
||||||
</trigger_comment>`
|
|
||||||
: ""
|
|
||||||
}
|
|
||||||
|
|
||||||
Your request is in <trigger_comment> above${eventData.eventName === "issues" ? ` (or the ${entityType} body for assigned/labeled events)` : ""}.
|
|
||||||
|
|
||||||
Decide what's being asked:
|
|
||||||
1. **Question or code review** - Answer directly or provide feedback
|
|
||||||
2. **Code change** - Implement the change, commit, and push
|
|
||||||
|
|
||||||
Communication:
|
|
||||||
- Your ONLY visible output is your GitHub comment - update it with progress and results
|
|
||||||
- Use mcp__github_comment__update_claude_comment to update (only "body" param needed)
|
|
||||||
- Use checklist format for tasks: - [ ] incomplete, - [x] complete
|
|
||||||
- Use ### headers (not #)
|
|
||||||
${getCommitInstructions(eventData, githubData, context, useCommitSigning)}
|
|
||||||
${
|
|
||||||
eventData.claudeBranch
|
|
||||||
? `
|
|
||||||
When done with changes, provide a PR link:
|
|
||||||
[Create a PR](${GITHUB_SERVER_URL}/${context.repository}/compare/${eventData.baseBranch}...${eventData.claudeBranch}?quick_pull=1&title=<url-encoded-title>&body=<url-encoded-body>)
|
|
||||||
Use THREE dots (...) between branches. URL-encode all parameters.`
|
|
||||||
: ""
|
|
||||||
}
|
|
||||||
|
|
||||||
Always include at the bottom:
|
|
||||||
- Job link: [View job run](${jobUrl})
|
|
||||||
- Follow the repo's CLAUDE.md file for project-specific guidelines`;
|
|
||||||
|
|
||||||
return promptContent;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Generates the default prompt for tag mode
|
* Generates the default prompt for tag mode
|
||||||
* @internal
|
* @internal
|
||||||
@@ -585,10 +473,6 @@ export function generateDefaultPrompt(
|
|||||||
githubData: FetchDataResult,
|
githubData: FetchDataResult,
|
||||||
useCommitSigning: boolean = false,
|
useCommitSigning: boolean = false,
|
||||||
): string {
|
): string {
|
||||||
// Use simplified prompt if opted in
|
|
||||||
if (process.env.USE_SIMPLE_PROMPT === "true") {
|
|
||||||
return generateSimplePrompt(context, githubData, useCommitSigning);
|
|
||||||
}
|
|
||||||
const {
|
const {
|
||||||
contextData,
|
contextData,
|
||||||
comments,
|
comments,
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ type PullRequestReviewEvent = {
|
|||||||
eventName: "pull_request_review";
|
eventName: "pull_request_review";
|
||||||
isPR: true;
|
isPR: true;
|
||||||
prNumber: string;
|
prNumber: string;
|
||||||
commentBody?: string; // May be absent for approvals without comments
|
commentBody: string;
|
||||||
claudeBranch?: string;
|
claudeBranch?: string;
|
||||||
baseBranch?: string;
|
baseBranch?: string;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -26,6 +26,7 @@ export function collectActionInputsPresence(): void {
|
|||||||
max_turns: "",
|
max_turns: "",
|
||||||
use_sticky_comment: "false",
|
use_sticky_comment: "false",
|
||||||
use_commit_signing: "false",
|
use_commit_signing: "false",
|
||||||
|
experimental_allowed_domains: "",
|
||||||
};
|
};
|
||||||
|
|
||||||
const allInputsJson = process.env.ALL_INPUTS;
|
const allInputsJson = process.env.ALL_INPUTS;
|
||||||
|
|||||||
@@ -152,7 +152,7 @@ async function run() {
|
|||||||
|
|
||||||
// Check if action failed and read output file for execution details
|
// Check if action failed and read output file for execution details
|
||||||
let executionDetails: {
|
let executionDetails: {
|
||||||
total_cost_usd?: number;
|
cost_usd?: number;
|
||||||
duration_ms?: number;
|
duration_ms?: number;
|
||||||
duration_api_ms?: number;
|
duration_api_ms?: number;
|
||||||
} | null = null;
|
} | null = null;
|
||||||
@@ -179,11 +179,11 @@ async function run() {
|
|||||||
const lastElement = outputData[outputData.length - 1];
|
const lastElement = outputData[outputData.length - 1];
|
||||||
if (
|
if (
|
||||||
lastElement.type === "result" &&
|
lastElement.type === "result" &&
|
||||||
"total_cost_usd" in lastElement &&
|
"cost_usd" in lastElement &&
|
||||||
"duration_ms" in lastElement
|
"duration_ms" in lastElement
|
||||||
) {
|
) {
|
||||||
executionDetails = {
|
executionDetails = {
|
||||||
total_cost_usd: lastElement.total_cost_usd,
|
cost_usd: lastElement.cost_usd,
|
||||||
duration_ms: lastElement.duration_ms,
|
duration_ms: lastElement.duration_ms,
|
||||||
duration_api_ms: lastElement.duration_api_ms,
|
duration_api_ms: lastElement.duration_api_ms,
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -13,8 +13,6 @@ export const PR_QUERY = `
|
|||||||
headRefName
|
headRefName
|
||||||
headRefOid
|
headRefOid
|
||||||
createdAt
|
createdAt
|
||||||
updatedAt
|
|
||||||
lastEditedAt
|
|
||||||
additions
|
additions
|
||||||
deletions
|
deletions
|
||||||
state
|
state
|
||||||
@@ -98,8 +96,6 @@ export const ISSUE_QUERY = `
|
|||||||
login
|
login
|
||||||
}
|
}
|
||||||
createdAt
|
createdAt
|
||||||
updatedAt
|
|
||||||
lastEditedAt
|
|
||||||
state
|
state
|
||||||
comments(first: 100) {
|
comments(first: 100) {
|
||||||
nodes {
|
nodes {
|
||||||
|
|||||||
@@ -107,38 +107,6 @@ export function filterReviewsToTriggerTime<
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Checks if the issue/PR body was edited after the trigger time.
|
|
||||||
* This prevents a race condition where an attacker could edit the issue/PR body
|
|
||||||
* between when an authorized user triggered Claude and when Claude processes the request.
|
|
||||||
*
|
|
||||||
* @param contextData - The PR or issue data containing body and edit timestamps
|
|
||||||
* @param triggerTime - ISO timestamp of when the trigger event occurred
|
|
||||||
* @returns true if the body is safe to use, false if it was edited after trigger
|
|
||||||
*/
|
|
||||||
export function isBodySafeToUse(
|
|
||||||
contextData: { createdAt: string; updatedAt?: string; lastEditedAt?: string },
|
|
||||||
triggerTime: string | undefined,
|
|
||||||
): boolean {
|
|
||||||
// If no trigger time is available, we can't validate - allow the body
|
|
||||||
// This maintains backwards compatibility for triggers that don't have timestamps
|
|
||||||
if (!triggerTime) return true;
|
|
||||||
|
|
||||||
const triggerTimestamp = new Date(triggerTime).getTime();
|
|
||||||
|
|
||||||
// Check if the body was edited after the trigger
|
|
||||||
// Use lastEditedAt if available (more accurate for body edits), otherwise fall back to updatedAt
|
|
||||||
const lastEditTime = contextData.lastEditedAt || contextData.updatedAt;
|
|
||||||
if (lastEditTime) {
|
|
||||||
const lastEditTimestamp = new Date(lastEditTime).getTime();
|
|
||||||
if (lastEditTimestamp >= triggerTimestamp) {
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
|
|
||||||
type FetchDataParams = {
|
type FetchDataParams = {
|
||||||
octokits: Octokits;
|
octokits: Octokits;
|
||||||
repository: string;
|
repository: string;
|
||||||
@@ -305,13 +273,9 @@ export async function fetchGitHubData({
|
|||||||
body: c.body,
|
body: c.body,
|
||||||
}));
|
}));
|
||||||
|
|
||||||
// Add the main issue/PR body if it has content and wasn't edited after trigger
|
// Add the main issue/PR body if it has content
|
||||||
// This prevents a TOCTOU race condition where an attacker could edit the body
|
const mainBody: CommentWithImages[] = contextData.body
|
||||||
// between when an authorized user triggered Claude and when Claude processes the request
|
? [
|
||||||
let mainBody: CommentWithImages[] = [];
|
|
||||||
if (contextData.body) {
|
|
||||||
if (isBodySafeToUse(contextData, triggerTime)) {
|
|
||||||
mainBody = [
|
|
||||||
{
|
{
|
||||||
...(isPR
|
...(isPR
|
||||||
? {
|
? {
|
||||||
@@ -325,14 +289,8 @@ export async function fetchGitHubData({
|
|||||||
body: contextData.body,
|
body: contextData.body,
|
||||||
}),
|
}),
|
||||||
},
|
},
|
||||||
];
|
]
|
||||||
} else {
|
: [];
|
||||||
console.warn(
|
|
||||||
`Security: ${isPR ? "PR" : "Issue"} #${prNumber} body was edited after the trigger event. ` +
|
|
||||||
`Excluding body content to prevent potential injection attacks.`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
const allComments = [
|
const allComments = [
|
||||||
...mainBody,
|
...mainBody,
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
import { GITHUB_SERVER_URL } from "../api/config";
|
import { GITHUB_SERVER_URL } from "../api/config";
|
||||||
|
|
||||||
export type ExecutionDetails = {
|
export type ExecutionDetails = {
|
||||||
total_cost_usd?: number;
|
cost_usd?: number;
|
||||||
duration_ms?: number;
|
duration_ms?: number;
|
||||||
duration_api_ms?: number;
|
duration_api_ms?: number;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -58,8 +58,6 @@ export type GitHubPullRequest = {
|
|||||||
headRefName: string;
|
headRefName: string;
|
||||||
headRefOid: string;
|
headRefOid: string;
|
||||||
createdAt: string;
|
createdAt: string;
|
||||||
updatedAt?: string;
|
|
||||||
lastEditedAt?: string;
|
|
||||||
additions: number;
|
additions: number;
|
||||||
deletions: number;
|
deletions: number;
|
||||||
state: string;
|
state: string;
|
||||||
@@ -85,8 +83,6 @@ export type GitHubIssue = {
|
|||||||
body: string;
|
body: string;
|
||||||
author: GitHubAuthor;
|
author: GitHubAuthor;
|
||||||
createdAt: string;
|
createdAt: string;
|
||||||
updatedAt?: string;
|
|
||||||
lastEditedAt?: string;
|
|
||||||
state: string;
|
state: string;
|
||||||
comments: {
|
comments: {
|
||||||
nodes: GitHubComment[];
|
nodes: GitHubComment[];
|
||||||
|
|||||||
@@ -7,6 +7,7 @@ import { parseAllowedTools } from "./parse-tools";
|
|||||||
import { configureGitAuth } from "../../github/operations/git-config";
|
import { configureGitAuth } from "../../github/operations/git-config";
|
||||||
import type { GitHubContext } from "../../github/context";
|
import type { GitHubContext } from "../../github/context";
|
||||||
import { isEntityContext } from "../../github/context";
|
import { isEntityContext } from "../../github/context";
|
||||||
|
import { appendJsonSchemaArg } from "../../utils/json-schema";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Extract GitHub context as environment variables for agent mode
|
* Extract GitHub context as environment variables for agent mode
|
||||||
@@ -149,6 +150,9 @@ export const agentMode: Mode = {
|
|||||||
claudeArgs = `--mcp-config '${escapedOurConfig}'`;
|
claudeArgs = `--mcp-config '${escapedOurConfig}'`;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Add JSON schema if provided
|
||||||
|
claudeArgs = appendJsonSchemaArg(claudeArgs);
|
||||||
|
|
||||||
// Append user's claude_args (which may have more --mcp-config flags)
|
// Append user's claude_args (which may have more --mcp-config flags)
|
||||||
claudeArgs = `${claudeArgs} ${userClaudeArgs}`.trim();
|
claudeArgs = `${claudeArgs} ${userClaudeArgs}`.trim();
|
||||||
|
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ import { isEntityContext } from "../../github/context";
|
|||||||
import type { PreparedContext } from "../../create-prompt/types";
|
import type { PreparedContext } from "../../create-prompt/types";
|
||||||
import type { FetchDataResult } from "../../github/data/fetcher";
|
import type { FetchDataResult } from "../../github/data/fetcher";
|
||||||
import { parseAllowedTools } from "../agent/parse-tools";
|
import { parseAllowedTools } from "../agent/parse-tools";
|
||||||
|
import { appendJsonSchemaArg } from "../../utils/json-schema";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Tag mode implementation.
|
* Tag mode implementation.
|
||||||
@@ -177,6 +178,9 @@ export const tagMode: Mode = {
|
|||||||
// Add required tools for tag mode
|
// Add required tools for tag mode
|
||||||
claudeArgs += ` --allowedTools "${tagModeTools.join(",")}"`;
|
claudeArgs += ` --allowedTools "${tagModeTools.join(",")}"`;
|
||||||
|
|
||||||
|
// Add JSON schema if provided
|
||||||
|
claudeArgs = appendJsonSchemaArg(claudeArgs);
|
||||||
|
|
||||||
// Append user's claude_args (which may have more --mcp-config flags)
|
// Append user's claude_args (which may have more --mcp-config flags)
|
||||||
if (userClaudeArgs) {
|
if (userClaudeArgs) {
|
||||||
claudeArgs += ` ${userClaudeArgs}`;
|
claudeArgs += ` ${userClaudeArgs}`;
|
||||||
|
|||||||
17
src/utils/json-schema.ts
Normal file
17
src/utils/json-schema.ts
Normal file
@@ -0,0 +1,17 @@
|
|||||||
|
/**
|
||||||
|
* Appends JSON schema CLI argument if json_schema is provided
|
||||||
|
* Escapes schema for safe shell passing
|
||||||
|
*/
|
||||||
|
export function appendJsonSchemaArg(
|
||||||
|
claudeArgs: string,
|
||||||
|
jsonSchemaStr?: string,
|
||||||
|
): string {
|
||||||
|
const schema = jsonSchemaStr || process.env.JSON_SCHEMA || "";
|
||||||
|
if (!schema) {
|
||||||
|
return claudeArgs;
|
||||||
|
}
|
||||||
|
|
||||||
|
// CLI validates schema - just escape for safe shell passing
|
||||||
|
const escapedSchema = schema.replace(/'/g, "'\\''");
|
||||||
|
return `${claudeArgs} --json-schema '${escapedSchema}'`;
|
||||||
|
}
|
||||||
@@ -258,7 +258,7 @@ describe("updateCommentBody", () => {
|
|||||||
const input = {
|
const input = {
|
||||||
...baseInput,
|
...baseInput,
|
||||||
executionDetails: {
|
executionDetails: {
|
||||||
total_cost_usd: 0.13382595,
|
cost_usd: 0.13382595,
|
||||||
duration_ms: 31033,
|
duration_ms: 31033,
|
||||||
duration_api_ms: 31034,
|
duration_api_ms: 31034,
|
||||||
},
|
},
|
||||||
@@ -301,7 +301,7 @@ describe("updateCommentBody", () => {
|
|||||||
const input = {
|
const input = {
|
||||||
...baseInput,
|
...baseInput,
|
||||||
executionDetails: {
|
executionDetails: {
|
||||||
total_cost_usd: 0.25,
|
cost_usd: 0.25,
|
||||||
},
|
},
|
||||||
triggerUsername: "testuser",
|
triggerUsername: "testuser",
|
||||||
};
|
};
|
||||||
@@ -322,7 +322,7 @@ describe("updateCommentBody", () => {
|
|||||||
branchName: "claude-branch-123",
|
branchName: "claude-branch-123",
|
||||||
prLink: "\n[Create a PR](https://github.com/owner/repo/pr-url)",
|
prLink: "\n[Create a PR](https://github.com/owner/repo/pr-url)",
|
||||||
executionDetails: {
|
executionDetails: {
|
||||||
total_cost_usd: 0.01,
|
cost_usd: 0.01,
|
||||||
duration_ms: 65000, // 1 minute 5 seconds
|
duration_ms: 65000, // 1 minute 5 seconds
|
||||||
},
|
},
|
||||||
triggerUsername: "trigger-user",
|
triggerUsername: "trigger-user",
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ import {
|
|||||||
fetchGitHubData,
|
fetchGitHubData,
|
||||||
filterCommentsToTriggerTime,
|
filterCommentsToTriggerTime,
|
||||||
filterReviewsToTriggerTime,
|
filterReviewsToTriggerTime,
|
||||||
isBodySafeToUse,
|
|
||||||
} from "../src/github/data/fetcher";
|
} from "../src/github/data/fetcher";
|
||||||
import {
|
import {
|
||||||
createMockContext,
|
createMockContext,
|
||||||
@@ -372,139 +371,6 @@ describe("filterReviewsToTriggerTime", () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
describe("isBodySafeToUse", () => {
|
|
||||||
const triggerTime = "2024-01-15T12:00:00Z";
|
|
||||||
|
|
||||||
const createMockContextData = (
|
|
||||||
createdAt: string,
|
|
||||||
updatedAt?: string,
|
|
||||||
lastEditedAt?: string,
|
|
||||||
) => ({
|
|
||||||
createdAt,
|
|
||||||
updatedAt,
|
|
||||||
lastEditedAt,
|
|
||||||
});
|
|
||||||
|
|
||||||
describe("body edit time validation", () => {
|
|
||||||
it("should return true when body was never edited", () => {
|
|
||||||
const contextData = createMockContextData("2024-01-15T10:00:00Z");
|
|
||||||
expect(isBodySafeToUse(contextData, triggerTime)).toBe(true);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("should return true when body was edited before trigger time", () => {
|
|
||||||
const contextData = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00Z",
|
|
||||||
"2024-01-15T11:00:00Z",
|
|
||||||
"2024-01-15T11:30:00Z",
|
|
||||||
);
|
|
||||||
expect(isBodySafeToUse(contextData, triggerTime)).toBe(true);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("should return false when body was edited after trigger time (using updatedAt)", () => {
|
|
||||||
const contextData = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00Z",
|
|
||||||
"2024-01-15T13:00:00Z",
|
|
||||||
);
|
|
||||||
expect(isBodySafeToUse(contextData, triggerTime)).toBe(false);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("should return false when body was edited after trigger time (using lastEditedAt)", () => {
|
|
||||||
const contextData = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00Z",
|
|
||||||
undefined,
|
|
||||||
"2024-01-15T13:00:00Z",
|
|
||||||
);
|
|
||||||
expect(isBodySafeToUse(contextData, triggerTime)).toBe(false);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("should return false when body was edited exactly at trigger time", () => {
|
|
||||||
const contextData = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00Z",
|
|
||||||
"2024-01-15T12:00:00Z",
|
|
||||||
);
|
|
||||||
expect(isBodySafeToUse(contextData, triggerTime)).toBe(false);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("should prioritize lastEditedAt over updatedAt", () => {
|
|
||||||
// updatedAt is after trigger, but lastEditedAt is before - should be safe
|
|
||||||
const contextData = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00Z",
|
|
||||||
"2024-01-15T13:00:00Z", // updatedAt after trigger
|
|
||||||
"2024-01-15T11:00:00Z", // lastEditedAt before trigger
|
|
||||||
);
|
|
||||||
expect(isBodySafeToUse(contextData, triggerTime)).toBe(true);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe("edge cases", () => {
|
|
||||||
it("should return true when no trigger time is provided (backward compatibility)", () => {
|
|
||||||
const contextData = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00Z",
|
|
||||||
"2024-01-15T13:00:00Z", // Would normally fail
|
|
||||||
"2024-01-15T14:00:00Z", // Would normally fail
|
|
||||||
);
|
|
||||||
expect(isBodySafeToUse(contextData, undefined)).toBe(true);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("should handle millisecond precision correctly", () => {
|
|
||||||
// Edit 1ms after trigger - should be unsafe
|
|
||||||
const contextData = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00Z",
|
|
||||||
"2024-01-15T12:00:00.001Z",
|
|
||||||
);
|
|
||||||
expect(isBodySafeToUse(contextData, triggerTime)).toBe(false);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("should handle edit 1ms before trigger - should be safe", () => {
|
|
||||||
const contextData = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00Z",
|
|
||||||
"2024-01-15T11:59:59.999Z",
|
|
||||||
);
|
|
||||||
expect(isBodySafeToUse(contextData, triggerTime)).toBe(true);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("should handle various ISO timestamp formats", () => {
|
|
||||||
const contextData1 = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00Z",
|
|
||||||
"2024-01-15T11:00:00Z",
|
|
||||||
);
|
|
||||||
const contextData2 = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00+00:00",
|
|
||||||
"2024-01-15T11:00:00+00:00",
|
|
||||||
);
|
|
||||||
const contextData3 = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00.000Z",
|
|
||||||
"2024-01-15T11:00:00.000Z",
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(isBodySafeToUse(contextData1, triggerTime)).toBe(true);
|
|
||||||
expect(isBodySafeToUse(contextData2, triggerTime)).toBe(true);
|
|
||||||
expect(isBodySafeToUse(contextData3, triggerTime)).toBe(true);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe("security scenarios", () => {
|
|
||||||
it("should detect race condition attack - body edited between trigger and processing", () => {
|
|
||||||
// Simulates: Owner triggers @claude at 12:00, attacker edits body at 12:00:30
|
|
||||||
const contextData = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00Z", // Issue created
|
|
||||||
"2024-01-15T12:00:30Z", // Body edited after trigger
|
|
||||||
);
|
|
||||||
expect(isBodySafeToUse(contextData, "2024-01-15T12:00:00Z")).toBe(false);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("should allow body that was stable at trigger time", () => {
|
|
||||||
// Body was last edited well before the trigger
|
|
||||||
const contextData = createMockContextData(
|
|
||||||
"2024-01-15T10:00:00Z",
|
|
||||||
"2024-01-15T10:30:00Z",
|
|
||||||
"2024-01-15T10:30:00Z",
|
|
||||||
);
|
|
||||||
expect(isBodySafeToUse(contextData, "2024-01-15T12:00:00Z")).toBe(true);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe("fetchGitHubData integration with time filtering", () => {
|
describe("fetchGitHubData integration with time filtering", () => {
|
||||||
it("should filter comments based on trigger time when provided", async () => {
|
it("should filter comments based on trigger time when provided", async () => {
|
||||||
const mockOctokits = {
|
const mockOctokits = {
|
||||||
@@ -830,119 +696,4 @@ describe("fetchGitHubData integration with time filtering", () => {
|
|||||||
// All three comments should be included as they're all before trigger time
|
// All three comments should be included as they're all before trigger time
|
||||||
expect(result.comments.length).toBe(3);
|
expect(result.comments.length).toBe(3);
|
||||||
});
|
});
|
||||||
|
|
||||||
it("should exclude issue body when edited after trigger time (TOCTOU protection)", async () => {
|
|
||||||
const mockOctokits = {
|
|
||||||
graphql: jest.fn().mockResolvedValue({
|
|
||||||
repository: {
|
|
||||||
issue: {
|
|
||||||
number: 555,
|
|
||||||
title: "Test Issue",
|
|
||||||
body: "Malicious body edited after trigger",
|
|
||||||
author: { login: "attacker" },
|
|
||||||
createdAt: "2024-01-15T10:00:00Z",
|
|
||||||
updatedAt: "2024-01-15T12:30:00Z", // Edited after trigger
|
|
||||||
lastEditedAt: "2024-01-15T12:30:00Z", // Edited after trigger
|
|
||||||
comments: { nodes: [] },
|
|
||||||
},
|
|
||||||
},
|
|
||||||
user: { login: "trigger-user" },
|
|
||||||
}),
|
|
||||||
rest: jest.fn() as any,
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await fetchGitHubData({
|
|
||||||
octokits: mockOctokits as any,
|
|
||||||
repository: "test-owner/test-repo",
|
|
||||||
prNumber: "555",
|
|
||||||
isPR: false,
|
|
||||||
triggerUsername: "trigger-user",
|
|
||||||
triggerTime: "2024-01-15T12:00:00Z",
|
|
||||||
});
|
|
||||||
|
|
||||||
// The body should be excluded from image processing due to TOCTOU protection
|
|
||||||
// We can verify this by checking that issue_body is NOT in the imageUrlMap keys
|
|
||||||
const hasIssueBodyInMap = Array.from(result.imageUrlMap.keys()).some(
|
|
||||||
(key) => key.includes("issue_body"),
|
|
||||||
);
|
|
||||||
expect(hasIssueBodyInMap).toBe(false);
|
|
||||||
});
|
|
||||||
|
|
||||||
it("should include issue body when not edited after trigger time", async () => {
|
|
||||||
const mockOctokits = {
|
|
||||||
graphql: jest.fn().mockResolvedValue({
|
|
||||||
repository: {
|
|
||||||
issue: {
|
|
||||||
number: 666,
|
|
||||||
title: "Test Issue",
|
|
||||||
body: "Safe body not edited after trigger",
|
|
||||||
author: { login: "author" },
|
|
||||||
createdAt: "2024-01-15T10:00:00Z",
|
|
||||||
updatedAt: "2024-01-15T11:00:00Z", // Edited before trigger
|
|
||||||
lastEditedAt: "2024-01-15T11:00:00Z", // Edited before trigger
|
|
||||||
comments: { nodes: [] },
|
|
||||||
},
|
|
||||||
},
|
|
||||||
user: { login: "trigger-user" },
|
|
||||||
}),
|
|
||||||
rest: jest.fn() as any,
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await fetchGitHubData({
|
|
||||||
octokits: mockOctokits as any,
|
|
||||||
repository: "test-owner/test-repo",
|
|
||||||
prNumber: "666",
|
|
||||||
isPR: false,
|
|
||||||
triggerUsername: "trigger-user",
|
|
||||||
triggerTime: "2024-01-15T12:00:00Z",
|
|
||||||
});
|
|
||||||
|
|
||||||
// The contextData should still contain the body
|
|
||||||
expect(result.contextData.body).toBe("Safe body not edited after trigger");
|
|
||||||
});
|
|
||||||
|
|
||||||
it("should exclude PR body when edited after trigger time (TOCTOU protection)", async () => {
|
|
||||||
const mockOctokits = {
|
|
||||||
graphql: jest.fn().mockResolvedValue({
|
|
||||||
repository: {
|
|
||||||
pullRequest: {
|
|
||||||
number: 777,
|
|
||||||
title: "Test PR",
|
|
||||||
body: "Malicious PR body edited after trigger",
|
|
||||||
author: { login: "attacker" },
|
|
||||||
baseRefName: "main",
|
|
||||||
headRefName: "feature",
|
|
||||||
headRefOid: "abc123",
|
|
||||||
createdAt: "2024-01-15T10:00:00Z",
|
|
||||||
updatedAt: "2024-01-15T12:30:00Z", // Edited after trigger
|
|
||||||
lastEditedAt: "2024-01-15T12:30:00Z", // Edited after trigger
|
|
||||||
additions: 10,
|
|
||||||
deletions: 5,
|
|
||||||
state: "OPEN",
|
|
||||||
commits: { totalCount: 1, nodes: [] },
|
|
||||||
files: { nodes: [] },
|
|
||||||
comments: { nodes: [] },
|
|
||||||
reviews: { nodes: [] },
|
|
||||||
},
|
|
||||||
},
|
|
||||||
user: { login: "trigger-user" },
|
|
||||||
}),
|
|
||||||
rest: jest.fn() as any,
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await fetchGitHubData({
|
|
||||||
octokits: mockOctokits as any,
|
|
||||||
repository: "test-owner/test-repo",
|
|
||||||
prNumber: "777",
|
|
||||||
isPR: true,
|
|
||||||
triggerUsername: "trigger-user",
|
|
||||||
triggerTime: "2024-01-15T12:00:00Z",
|
|
||||||
});
|
|
||||||
|
|
||||||
// The body should be excluded from image processing due to TOCTOU protection
|
|
||||||
const hasPrBodyInMap = Array.from(result.imageUrlMap.keys()).some((key) =>
|
|
||||||
key.includes("pr_body"),
|
|
||||||
);
|
|
||||||
expect(hasPrBodyInMap).toBe(false);
|
|
||||||
});
|
|
||||||
});
|
});
|
||||||
|
|||||||
2
test/fixtures/sample-turns.json
vendored
2
test/fixtures/sample-turns.json
vendored
@@ -189,7 +189,7 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"type": "result",
|
"type": "result",
|
||||||
"total_cost_usd": 0.0347,
|
"cost_usd": 0.0347,
|
||||||
"duration_ms": 18750,
|
"duration_ms": 18750,
|
||||||
"result": "Successfully removed debug print statement from file and added review comment to document the change."
|
"result": "Successfully removed debug print statement from file and added review comment to document the change."
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -401,53 +401,6 @@ export const mockPullRequestReviewContext: ParsedGitHubContext = {
|
|||||||
inputs: { ...defaultInputs, triggerPhrase: "@claude" },
|
inputs: { ...defaultInputs, triggerPhrase: "@claude" },
|
||||||
};
|
};
|
||||||
|
|
||||||
export const mockPullRequestReviewWithoutCommentContext: ParsedGitHubContext = {
|
|
||||||
runId: "1234567890",
|
|
||||||
eventName: "pull_request_review",
|
|
||||||
eventAction: "dismissed",
|
|
||||||
repository: defaultRepository,
|
|
||||||
actor: "senior-developer",
|
|
||||||
payload: {
|
|
||||||
action: "submitted",
|
|
||||||
review: {
|
|
||||||
id: 11122233,
|
|
||||||
body: null, // Simulating approval without comment
|
|
||||||
user: {
|
|
||||||
login: "senior-developer",
|
|
||||||
id: 44444,
|
|
||||||
avatar_url: "https://avatars.githubusercontent.com/u/44444",
|
|
||||||
html_url: "https://github.com/senior-developer",
|
|
||||||
},
|
|
||||||
state: "approved",
|
|
||||||
html_url:
|
|
||||||
"https://github.com/test-owner/test-repo/pull/321#pullrequestreview-11122233",
|
|
||||||
submitted_at: "2024-01-15T15:30:00Z",
|
|
||||||
},
|
|
||||||
pull_request: {
|
|
||||||
number: 321,
|
|
||||||
title: "Refactor: Improve error handling in API layer",
|
|
||||||
body: "This PR improves error handling across all API endpoints",
|
|
||||||
user: {
|
|
||||||
login: "backend-developer",
|
|
||||||
id: 33333,
|
|
||||||
avatar_url: "https://avatars.githubusercontent.com/u/33333",
|
|
||||||
html_url: "https://github.com/backend-developer",
|
|
||||||
},
|
|
||||||
},
|
|
||||||
repository: {
|
|
||||||
name: "test-repo",
|
|
||||||
full_name: "test-owner/test-repo",
|
|
||||||
private: false,
|
|
||||||
owner: {
|
|
||||||
login: "test-owner",
|
|
||||||
},
|
|
||||||
},
|
|
||||||
} as PullRequestReviewEvent,
|
|
||||||
entityNumber: 321,
|
|
||||||
isPR: true,
|
|
||||||
inputs: { ...defaultInputs, triggerPhrase: "@claude" },
|
|
||||||
};
|
|
||||||
|
|
||||||
export const mockPullRequestReviewCommentContext: ParsedGitHubContext = {
|
export const mockPullRequestReviewCommentContext: ParsedGitHubContext = {
|
||||||
runId: "1234567890",
|
runId: "1234567890",
|
||||||
eventName: "pull_request_review_comment",
|
eventName: "pull_request_review_comment",
|
||||||
|
|||||||
@@ -10,7 +10,6 @@ import {
|
|||||||
mockPullRequestCommentContext,
|
mockPullRequestCommentContext,
|
||||||
mockPullRequestReviewContext,
|
mockPullRequestReviewContext,
|
||||||
mockPullRequestReviewCommentContext,
|
mockPullRequestReviewCommentContext,
|
||||||
mockPullRequestReviewWithoutCommentContext,
|
|
||||||
} from "./mockContext";
|
} from "./mockContext";
|
||||||
|
|
||||||
const BASE_ENV = {
|
const BASE_ENV = {
|
||||||
@@ -127,24 +126,6 @@ describe("parseEnvVarsWithContext", () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
describe("pull_request_review event without comment", () => {
|
|
||||||
test("should parse pull_request_review event correctly", () => {
|
|
||||||
process.env = BASE_ENV;
|
|
||||||
const result = prepareContext(
|
|
||||||
mockPullRequestReviewWithoutCommentContext,
|
|
||||||
"12345",
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.eventData.eventName).toBe("pull_request_review");
|
|
||||||
expect(result.eventData.isPR).toBe(true);
|
|
||||||
expect(result.triggerUsername).toBe("senior-developer");
|
|
||||||
if (result.eventData.eventName === "pull_request_review") {
|
|
||||||
expect(result.eventData.prNumber).toBe("321");
|
|
||||||
expect(result.eventData.commentBody).toBe("");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe("pull_request_review_comment event", () => {
|
describe("pull_request_review_comment event", () => {
|
||||||
test("should parse pull_request_review_comment event correctly", () => {
|
test("should parse pull_request_review_comment event correctly", () => {
|
||||||
process.env = BASE_ENV;
|
process.env = BASE_ENV;
|
||||||
|
|||||||
Reference in New Issue
Block a user