claude-sonnet-4-5 predates auto mode, so Claude Code fell back to its default permission mode in the dedupe job. Move it and claude.yml to claude-sonnet-4-6. The action sets --permission-mode acceptEdits for @claude mentions and appends the workflow's claude_args after it, so the --permission-mode auto in claude.yml wins. Drop claude.yml from EXEMPT_FROM_AUTO_MODE. The check now also fails when a step in auto mode names a model older than claude-opus-4-6.
2.2 KiB
CLAUDE.md
Guidance for Claude Code and other coding agents working in this repository.
Security hardening for GitHub Actions
Workflow jobs in this repository that call Claude run with three protections. Keep them when you add or edit a workflow.
- Egress-firewall runner. The job has
runs-on: ubuntu-24.04-firewall, a GitHub-hosted runner that filters the job's outbound network traffic. Do not move a job that calls Claude to another runner. - Network allow list.
.github/egress-firewall.yamllists the hosts those jobs may reach, besides any that GitHub's firewall allows by default. Keepmode: enforce, which is what makes the firewall block the rest. Follow that file's header when you add a host. - Auto permission mode. Every step that runs the Claude Code action
(
uses: anthropics/claude-code-action, or a local action with aclaude_argsinput) passes--permission-mode autoinclaude_args. A tool call that needs permission and that the allowed tools do not cover then runs only if Claude Code's safety review passes it. Allow only the tools the job needs, and keep any--disallowedToolslist a step has. Useclaude-opus-4-6or a newer model: on an older one Claude Code falls back to its default permission mode.
claude.yml answers @claude mentions. The Claude Code action sets
--permission-mode acceptEdits for those, and the --permission-mode auto in
the workflow's claude_args, which comes after it, replaces it.
.github/workflows/workflow-hardening.yml fails when a job that runs the Claude
Code action or mentions ANTHROPIC_FEDERATION_RULE_ID breaks protection 1 or 3,
or when the allow list is missing, empty, not mode: enforce, or names a host
with *. It cannot see a job that calls Claude another way, so check new
workflows by hand too. If a job cannot meet protection 1 or 3, add it with the
reason to the matching exemption table in
.github/scripts/check_workflow_hardening.py. A job in EXEMPT_FROM_AUTO_MODE
must set no permission mode at all. Do not skip or weaken the check.
Keep each workflow's permissions: block minimal, and never print tokens or
environment variables in workflow logs.