Files
claude-code/CLAUDE.md
Claude 7dbaea237f Run @claude mentions and dedupe in auto mode on a model that supports it
claude-sonnet-4-5 predates auto mode, so Claude Code fell back to its
default permission mode in the dedupe job. Move it and claude.yml to
claude-sonnet-4-6. The action sets --permission-mode acceptEdits for
@claude mentions and appends the workflow's claude_args after it, so the
--permission-mode auto in claude.yml wins. Drop claude.yml from
EXEMPT_FROM_AUTO_MODE.

The check now also fails when a step in auto mode names a model older than
claude-opus-4-6.
2026-09-29 08:21:19 +00:00

2.2 KiB

CLAUDE.md

Guidance for Claude Code and other coding agents working in this repository.

Security hardening for GitHub Actions

Workflow jobs in this repository that call Claude run with three protections. Keep them when you add or edit a workflow.

  1. Egress-firewall runner. The job has runs-on: ubuntu-24.04-firewall, a GitHub-hosted runner that filters the job's outbound network traffic. Do not move a job that calls Claude to another runner.
  2. Network allow list. .github/egress-firewall.yaml lists the hosts those jobs may reach, besides any that GitHub's firewall allows by default. Keep mode: enforce, which is what makes the firewall block the rest. Follow that file's header when you add a host.
  3. Auto permission mode. Every step that runs the Claude Code action (uses: anthropics/claude-code-action, or a local action with a claude_args input) passes --permission-mode auto in claude_args. A tool call that needs permission and that the allowed tools do not cover then runs only if Claude Code's safety review passes it. Allow only the tools the job needs, and keep any --disallowedTools list a step has. Use claude-opus-4-6 or a newer model: on an older one Claude Code falls back to its default permission mode.

claude.yml answers @claude mentions. The Claude Code action sets --permission-mode acceptEdits for those, and the --permission-mode auto in the workflow's claude_args, which comes after it, replaces it.

.github/workflows/workflow-hardening.yml fails when a job that runs the Claude Code action or mentions ANTHROPIC_FEDERATION_RULE_ID breaks protection 1 or 3, or when the allow list is missing, empty, not mode: enforce, or names a host with *. It cannot see a job that calls Claude another way, so check new workflows by hand too. If a job cannot meet protection 1 or 3, add it with the reason to the matching exemption table in .github/scripts/check_workflow_hardening.py. A job in EXEMPT_FROM_AUTO_MODE must set no permission mode at all. Do not skip or weaken the check.

Keep each workflow's permissions: block minimal, and never print tokens or environment variables in workflow logs.