* Run workflows that call Claude on the egress-firewall runner in auto permission mode Move every workflow job that signs in to the Claude API from ubuntu-latest to GitHub's egress-firewall runner (ubuntu-24.04-firewall), and pass --permission-mode auto to the Claude Code action in each of them except claude.yml. In auto permission mode Claude Code reviews each tool call that needs permission and that the allowed tools do not cover, and runs it only if Claude Code's safety review passes it. Until now these runs, which have nobody to ask, refused every such call. The issue triage step, which anyone can start by opening an issue, also passes a --disallowedTools list for tools it never needs. claude.yml answers @claude mentions, and for those the action sets --permission-mode acceptEdits itself. Its permission mode is unchanged. Allowed tools, settings, models, triggers and permissions are unchanged. The network allow list for the firewall follows in the next change. * Add the network allow list, a security check and CLAUDE.md guidance - .github/egress-firewall.yaml: the hosts that jobs on the egress-firewall runner may reach, in enforce mode, each with what uses it. - .github/workflows/workflow-hardening.yml and .github/scripts/check_workflow_hardening.py: a check that fails when a job that calls Claude is not on the egress-firewall runner, does not pass --permission-mode auto, or when the allow list is missing, empty, not in enforce mode or names a host with '*'. claude.yml is listed as exempt from the permission mode rule, with the reason. - CLAUDE.md: a "Security hardening for GitHub Actions" section so that new and edited workflows keep these protections. * Pin the model for issue triage The step named no model, so it ran on Claude Code's default model. That default changed with Claude Code 2.1.280 to a model that is not available to this CI account. Pass --model claude-opus-5, the model this repository's test-*.yml workflows (ANTHROPIC_MODEL) and the Python SDK's example runs are pinned to for the same reason. This is independent of the security hardening in the two changes before it. * Check settings files and --settings for a permission mode The security check looked for defaultMode only in an inline 'settings' input. Also read the file a 'settings' input or a --settings flag in claude_args names, when it is inside the repository, and fail if it sets a permission mode. * Flag defaultMode anywhere in a job that calls Claude A settings file that an earlier step writes at run time can't be read by the step-level check, so also fail when the job's definition mentions defaultMode at all. * Fail the check when settings name a file outside the repository The check can't read such a file, so it can't tell whether it sets a permission mode. * Run @claude mentions in auto permission mode The action sets --permission-mode acceptEdits for @claude mentions and appends the workflow's claude_args after it, so the --permission-mode auto in claude.yml wins. Drop claude.yml from EXEMPT_FROM_AUTO_MODE. The check now also fails when a step in auto mode names a model older than claude-opus-4-6: Claude Code does not run auto mode on those and falls back to its default permission mode. --------- Co-authored-by: Claude <noreply@anthropic.com>
Claude Code Action
A general-purpose Claude Code action for GitHub PRs and issues that can answer questions and implement code changes. This action intelligently detects when to activate based on your workflow context—whether responding to @claude mentions, issue assignments, or executing automation tasks with explicit prompts. It supports multiple authentication methods including Anthropic direct API (API key or workload identity federation), Amazon Bedrock, Google Vertex AI, and Microsoft Foundry.
Features
- 🎯 Intelligent Mode Detection: Automatically selects the appropriate execution mode based on your workflow context—no configuration needed
- 🤖 Interactive Code Assistant: Claude can answer questions about code, architecture, and programming
- 🔍 Code Review: Analyzes PR changes and suggests improvements
- ✨ Code Implementation: Can implement simple fixes, refactoring, and even new features
- 💬 PR/Issue Integration: Works seamlessly with GitHub comments and PR reviews
- 🛠️ Flexible Tool Access: Access to GitHub APIs and file operations (additional tools can be enabled via configuration)
- 📋 Progress Tracking: Visual progress indicators with checkboxes that dynamically update as Claude completes tasks
- 📊 Structured Outputs: Get validated JSON results that automatically become GitHub Action outputs for complex automations
- 🏃 Runs on Your Infrastructure: The action executes entirely on your own GitHub runner (Anthropic API calls go to your chosen provider)
- ⚙️ Simplified Configuration: Unified
promptandclaude_argsinputs provide clean, powerful configuration aligned with Claude Code SDK
📦 Upgrading from v0.x?
See our Migration Guide for step-by-step instructions on updating your workflows to v1.0. The new version simplifies configuration while maintaining compatibility with most existing setups.
Quickstart
The easiest way to set up this action is through Claude Code in the terminal. Just open claude and run /install-github-app.
This command will guide you through setting up the GitHub app and required secrets.
Note:
- You must be a repository admin to install the GitHub app and add secrets
- This quickstart method is only available for direct Anthropic API users. For AWS Bedrock, Google Vertex AI, or Microsoft Foundry setup, see docs/cloud-providers.md.
📚 Solutions & Use Cases
Looking for specific automation patterns? Check our Solutions Guide for complete working examples including:
- 🔍 Automatic PR Code Review - Full review automation
- 📂 Path-Specific Reviews - Trigger on critical file changes
- 👥 External Contributor Reviews - Special handling for new contributors
- 📝 Custom Review Checklists - Enforce team standards
- 🔄 Scheduled Maintenance - Automated repository health checks
- 🏷️ Issue Triage & Labeling - Automatic categorization
- 📖 Documentation Sync - Keep docs updated with code changes
- 🔒 Security-Focused Reviews - OWASP-aligned security analysis
- 📊 DIY Progress Tracking - Create tracking comments in automation mode
Each solution includes complete working examples, configuration details, and expected outcomes.
Documentation
- Solutions Guide - 🎯 Ready-to-use automation patterns
- Migration Guide - ⭐ Upgrading from v0.x to v1.0
- Setup Guide - Manual setup, custom GitHub apps, and security best practices
- Usage Guide - Basic usage, workflow configuration, and input parameters
- Custom Automations - Examples of automated workflows and custom prompts
- Configuration - MCP servers, permissions, environment variables, and advanced settings
- Experimental Features - Execution modes and network restrictions
- Cloud Providers - AWS Bedrock, Google Vertex AI, and Microsoft Foundry setup
- Capabilities & Limitations - What Claude can and cannot do
- Security - Access control, permissions, and commit signing
- FAQ - Common questions and troubleshooting
📚 FAQ
Having issues or questions? Check out our Frequently Asked Questions for solutions to common problems and detailed explanations of Claude's capabilities and limitations.
License
This project is licensed under the MIT License—see the LICENSE file for details.