Skip to content

Add Claude Code GitHub Workflow - #7

Merged
gHashTag merged 2 commits into
mainfrom
add-claude-github-actions-1770555054844
Feb 8, 2026
Merged

gHashTag merged 2 commits into
mainfrom
add-claude-github-actions-1770555054844

Conversation

@gHashTag

@gHashTag gHashTag commented Feb 8, 2026

Copy link
Copy Markdown
Owner

🤖 Installing Claude Code GitHub App

This PR adds a GitHub Actions workflow that enables Claude Code integration in our repository.

What is Claude Code?

Claude Code is an AI coding agent that can help with:

  • Bug fixes and improvements
  • Documentation updates
  • Implementing new features
  • Code reviews and suggestions
  • Writing tests
  • And more!

How it works

Once this PR is merged, we'll be able to interact with Claude by mentioning @claude in a pull request or issue comment.
Once the workflow is triggered, Claude will analyze the comment and surrounding context, and execute on the request in a GitHub action.

Important Notes

  • This workflow won't take effect until this PR is merged
  • @claude mentions won't work until after the merge is complete
  • The workflow runs automatically whenever Claude is mentioned in PR or issue comments
  • Claude gets access to the entire PR or issue context including files, diffs, and previous comments

Security

  • Our Anthropic API key is securely stored as a GitHub Actions secret
  • Only users with write access to the repository can trigger the workflow
  • All Claude runs are stored in the GitHub Actions run history
  • Claude's default tools are limited to reading/writing files and interacting with our repo by creating comments, branches, and commits.
  • We can add more allowed tools by adding them to the workflow file like:
allowed_tools: Bash(npm install),Bash(npm run build),Bash(npm run lint),Bash(npm run test)

There's more information in the Claude Code action repo.

After merging this PR, let's try mentioning @claude in a comment on any PR to get started!

@vercel

vercel Bot commented Feb 8, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
trinity Building Building Preview, Comment Feb 8, 2026 0:51am
trinity-site Building Building Preview, Comment Feb 8, 2026 0:51am
trinity-web Building Building Preview, Comment Feb 8, 2026 0:51am
website Building Building Preview, Comment Feb 8, 2026 0:51am

@gHashTag
gHashTag merged commit 422dc85 into main Feb 8, 2026
5 of 9 checks passed
@vercel
vercel Bot temporarily deployed to Preview – trinity February 8, 2026 12:53 Inactive
@vercel
vercel Bot temporarily deployed to Preview – website February 8, 2026 12:53 Inactive
@vercel
vercel Bot temporarily deployed to Preview – trinity-site February 8, 2026 12:54 Inactive
@claude

claude Bot commented Feb 8, 2026

Copy link
Copy Markdown

Code Review: Claude Code GitHub Workflow Integration

Summary

This PR adds two GitHub Actions workflows to integrate Claude Code into the repository. Overall, the implementation follows GitHub Actions best practices and aligns with the project's security policies outlined in SECURITY.md.


✅ Strengths

1. Security Best Practices

  • Secrets Management: Properly uses GitHub Secrets (CLAUDE_CODE_OAUTH_TOKEN) instead of hardcoded credentials ✅
  • Minimal Permissions: Both workflows follow the principle of least privilege with explicit permissions blocks
  • Restricted Tool Access: claude-code-review.yml uses --allowed-tools to limit Claude to read-only gh commands and PR commenting
  • User Authentication: claude.yml requires explicit @claude mentions, preventing unauthorized executions

2. Code Quality

  • Clear Documentation: Excellent PR description explaining what Claude Code is and how it works
  • Sensible Triggers: claude.yml triggered only when @claude is mentioned; claude-code-review.yml runs on PR open/sync for automated reviews
  • Helpful Comments: Commented-out optional configurations provide guidance for future customization

3. Integration with Project

  • Follows Existing Patterns: Uses actions/checkout@v4 consistent with other workflows
  • References CLAUDE.md: Prompt instructs Claude to use repository conventions from CLAUDE.md
  • Aligns with Security Policy: No hardcoded secrets, follows SECURITY.md guidelines

@vercel
vercel Bot temporarily deployed to Preview – trinity-web February 8, 2026 12:54 Inactive
@claude

claude Bot commented Feb 8, 2026

Copy link
Copy Markdown

🔍 Potential Issues & Recommendations

1. Incomplete Allowed Tools in claude-code-review.yml

Issue: The workflow restricts Claude to only gh commands, but the prompt asks Claude to review code quality, bugs, performance, and test coverage. To do this effectively, Claude needs to read files (Read tool) and search code (Grep, Glob tools).

Current Restriction: Only gh commands are allowed

Recommendation: Add file reading tools to enable proper code review by adding Read, Grep, and Glob to the allowed-tools list.

2. Missing Build/Test Tools for Code Review

Issue: According to CLAUDE.md, the project uses Zig 0.15.x with specific build commands (zig build test, zig test src/vsa.zig). For Claude to verify test coverage and potential bugs, it should be able to run these commands.

Recommendation: Add Zig setup step and include zig test commands in allowed-tools.

3. Zig Version Inconsistency

Issue: CLAUDE.md specifies Requires Zig 0.15.x but ci.yml uses version 0.13.0.

Recommendation: Update ci.yml to Zig 0.15.x in a separate PR (not blocking this one).

4. Missing actions: read Permission in claude-code-review.yml

Issue: claude.yml includes actions: read permission to read CI results on PRs, but claude-code-review.yml does not have this permission despite reviewing PRs.

Recommendation: Add actions: read permission to claude-code-review.yml for consistency with claude.yml.

@claude

claude Bot commented Feb 8, 2026

Copy link
Copy Markdown

5. No Rate Limiting or Cost Controls

Issue: The claude-code-review.yml workflow runs on every PR open/sync, which could consume significant API credits if PRs are frequently updated, large PRs with many files are opened, or multiple PRs are opened simultaneously.

Recommendation: Consider adding safeguards:

  • Option A: Enable PR author/file filters (already commented in the workflow, but disabled)
  • Option B: Add PR size limits to skip review for PRs with more than 20 files
  • Option C: Add manual trigger via label (requires claude-review label to run)

6. Documentation Gaps

Issue: The PR does not document:

  1. How to set up the CLAUDE_CODE_OAUTH_TOKEN secret
  2. What permissions the token needs
  3. How to test the workflows before merging

Recommendation: Add setup instructions to PR description or create .github/docs/CLAUDE_CODE_SETUP.md with token generation and GitHub secrets configuration steps.


🔒 Security Assessment

Approved ✅

  • No hardcoded secrets
  • Follows SECURITY.md guidelines (Never commit API keys or secrets)
  • Uses GitHub secret management
  • Restricts workflow execution to repository collaborators
  • Limits tool access via --allowed-tools

Concerns (Minor)

  1. Broad id-token: write permission: Both workflows request id-token: write. This is typically used for OIDC federation. Verify this is required by the claude-code-action.
  2. No audit logging mentioned: Consider documenting that all Claude executions are logged in GitHub Actions history for security audits.

@claude

claude Bot commented Feb 8, 2026

Copy link
Copy Markdown

🧪 Test Coverage

Missing: No tests for the workflows themselves. Consider:

  1. Testing the workflow in a fork before merging
  2. Adding a comment with @claude on a test PR to verify claude.yml works
  3. Opening a test PR to verify claude-code-review.yml triggers correctly

Note: The PR description correctly states workflows will not work until merged. Consider creating a test repository first.


📊 Performance Considerations

Efficiency

  • fetch-depth: 1 minimizes checkout time ✅
  • Workflows run in parallel (separate jobs) ✅

Potential Bottlenecks


🎯 Final Recommendations

Must Fix (Before Merge)

  1. ✅ Add file reading tools to claude-code-review.yml (Read, Grep, Glob)
  2. ✅ Add actions: read permission to claude-code-review.yml
  3. ✅ Add setup documentation for CLAUDE_CODE_OAUTH_TOKEN

Should Fix (Before Merge)

  1. ⚠️ Add rate limiting (PR size check or manual label trigger)
  2. ⚠️ Add timeout to prevent excessive costs

Nice to Have (Future PR)

  1. 💡 Update Zig version in ci.yml to 0.15.x
  2. 💡 Add workflow testing instructions
  3. 💡 Create .github/docs/CLAUDE_CODE_SETUP.md

✅ Approval Status

Conditional Approval: This PR is well-structured and follows best practices, but needs fixes to items #1-3 above to be fully functional. The current claude-code-review.yml will not be able to read files, which defeats its purpose.

Once those are addressed, this is a valuable addition to the project developer workflow.


Review completed by Claude Code (Sonnet 4.5)
φ² + 1/φ² = 3 | PHOENIX = 999

gHashTag added a commit that referenced this pull request Mar 2, 2026
gHashTag added a commit that referenced this pull request Mar 18, 2026
@gHashTag
gHashTag deleted the add-claude-github-actions-1770555054844 branch April 3, 2026 10:57
gHashTag added a commit that referenced this pull request Sep 23, 2026
…ules that stopped being true (#1132)

* feat(queen): the leaderboard shows the GitHub people behind the lanes

The connection to GitHub is direct - the issues, the branches and the pull
requests a bee opens all live there - so a lane signed `@login` in
TRIOS_KEY_OWNERS now draws that person's avatar and links their profile. A
leaderboard of faces is an invitation; a leaderboard of `key #7` is a log.

The avatar is `github.com/<login>.png`, a public redirect: no API call, no
token, no rate limit, and a 404 leaves the row readable. The login is checked
AGAIN here rather than trusted from the wire, because it ends up in an href and
an img src, and a page that trusts a remote string to build a profile link can
be pointed at somebody else's account by whoever writes that string.

Also fixes the row on a phone: the three numbers now ride in one box, so
"Accepted" and "Bee hours" can no longer land on top of each other when the row
wraps (seen at 440 px on the live board).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* feat(queen): the roadmap asks people in, not just counts

The tab said how far the rewrite has to go and never said that anyone could
push it. A measurement is not a reason for a stranger to stay.

So the count of OPEN port issues is now a button that opens the real GitHub
search - not a page about the project, the issues themselves - and the text
says the two things a newcomer does not know: that the work is cut into one
file per issue, and that they need neither permission nor prior .t27 to take
one. Underneath, the other way in for someone with no time to write code:
lend the swarm a lane and its work earns XP.

The number costs no extra request. It is the same stage-progress search the
bars already make, read as `all - done`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(specs): the rules said there was no ranking, and now there is one

`onboarding.t27` is the rules of the game as a machine can read them - it
compiles, its test blocks are evaluated, and only then is it published at
t27.ai/llms.txt and t27.ai/agents.t27. One of its stated unknowns was:

    "what a contribution is worth: there is no reward, no token and no
     ranking, and inventing one would break the honesty law above"

That stopped being true on 2026-09-23, when lanes started earning XP and the
LEADERBOARD tab shipped. Under a law that says a claim which cannot be traced
to a source is removed, a claim contradicted by the thing we just built cannot
be left standing.

So the ranking is now stated where it can be checked: the two addresses, the
two numbers (100 per accepted issue, 10 per bee hour), how it is derived, and -
in the same breath - that it buys nothing and converts to nothing. The stated
unknown becomes the honest remainder: what a contribution is worth in anything
but the record of it.

A seventh way in joins the six: a person who would rather lend than write can
lend one provider key, which runs one bee. The pair that could quietly rot is
tested together - a ranking arrived, and the rule against asking a reader for a
credential did not move. An agent that hands over its owner's key because a
file it read mentioned XP has done the one thing this document tells it not to.

10 test blocks, 54 asserts, all hold.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(blog): how to join the swarm, in both languages

The LEADERBOARD tab invites people to lend a lane and nothing anywhere told
them how. This is that missing page: what the game is, the two ways in, the
board tab by tab, the seven laws, and where a free provider key comes from.

The part that took the research is the fourth column of the provider table.
The invitation "lend us your API key" runs into provider terms that forbid
exactly that, and the post says so with names: Cerebras, Mistral, Fireworks and
Moonshot bar transferring a key in those words; NVIDIA's trial terms bar
production use and bar making the service available to others; Groq bars
orchestrating usage between organisations. OpenRouter is the one whose terms do
not stand in the way. Checked live on 2026-09-23 - and the same read found that
GitHub Models was retired on 2026-07-30 and that Cerebras and Together have
dropped their free tiers, so most advice on the web about this is stale.

Saying that costs us the simplest version of the pitch. Publishing the simple
version instead would be asking strangers to breach an agreement they signed,
on our behalf, without telling them - which is not a thing this project gets to
do under its own honesty law.

The roadmap's "how to join" link now points here instead of at a file that does
not exist, and two var() fallbacks that named colours no token declares are
corrected (the fallback-parity gate caught them).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(blog): state what the provider terms actually say, in their own words

The first draft said "some providers forbid sharing a key". A second read of
the actual agreements says something much harder, and quoting them is the only
honest version:

  OpenAI  - "buy, sell, or transfer API keys from, to, or with a third party"
  Anthropic - "You may not share your Account login information, Anthropic API
            key, or Account credentials with anyone else"
  Google  - "Developer credentials may not be embedded in open source projects"
            and separately, no sublicensing an API to a third party

There is no carve-out for non-commercial or charitable use. Three consequences
follow and the post now names them: a key is not scoped to inference (it can
revoke itself and mint new keys, so whoever holds it holds the account), every
clause puts responsibility for all activity on the account holder, and pooling
keys for throughput is itself forbidden - per-account rate limits are the point,
not an accident.

The post therefore leads with the design that asks nobody to breach anything:
the key never moves, the swarm hands out the task, the bee runs on the
contributor's own machine under their own account, and the patch comes back.
That is how AI Horde and BOINC have always worked. It is not built here, and
the post says so rather than implying it exists.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
github-actions Bot added a commit that referenced this pull request Sep 23, 2026
feat(queen): faces on the leaderboard, a way in on the roadmap, and rules that stopped being true (#1132)

* feat(queen): the leaderboard shows the GitHub people behind the lanes

The connection to GitHub is direct - the issues, the branches and the pull
requests a bee opens all live there - so a lane signed `@login` in
TRIOS_KEY_OWNERS now draws that person's avatar and links their profile. A
leaderboard of faces is an invitation; a leaderboard of `key #7` is a log.

The avatar is `github.com/<login>.png`, a public redirect: no API call, no
token, no rate limit, and a 404 leaves the row readable. The login is checked
AGAIN here rather than trusted from the wire, because it ends up in an href and
an img src, and a page that trusts a remote string to build a profile link can
be pointed at somebody else's account by whoever writes that string.

Also fixes the row on a phone: the three numbers now ride in one box, so
"Accepted" and "Bee hours" can no longer land on top of each other when the row
wraps (seen at 440 px on the live board).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* feat(queen): the roadmap asks people in, not just counts

The tab said how far the rewrite has to go and never said that anyone could
push it. A measurement is not a reason for a stranger to stay.

So the count of OPEN port issues is now a button that opens the real GitHub
search - not a page about the project, the issues themselves - and the text
says the two things a newcomer does not know: that the work is cut into one
file per issue, and that they need neither permission nor prior .t27 to take
one. Underneath, the other way in for someone with no time to write code:
lend the swarm a lane and its work earns XP.

The number costs no extra request. It is the same stage-progress search the
bars already make, read as `all - done`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(specs): the rules said there was no ranking, and now there is one

`onboarding.t27` is the rules of the game as a machine can read them - it
compiles, its test blocks are evaluated, and only then is it published at
t27.ai/llms.txt and t27.ai/agents.t27. One of its stated unknowns was:

    "what a contribution is worth: there is no reward, no token and no
     ranking, and inventing one would break the honesty law above"

That stopped being true on 2026-09-23, when lanes started earning XP and the
LEADERBOARD tab shipped. Under a law that says a claim which cannot be traced
to a source is removed, a claim contradicted by the thing we just built cannot
be left standing.

So the ranking is now stated where it can be checked: the two addresses, the
two numbers (100 per accepted issue, 10 per bee hour), how it is derived, and -
in the same breath - that it buys nothing and converts to nothing. The stated
unknown becomes the honest remainder: what a contribution is worth in anything
but the record of it.

A seventh way in joins the six: a person who would rather lend than write can
lend one provider key, which runs one bee. The pair that could quietly rot is
tested together - a ranking arrived, and the rule against asking a reader for a
credential did not move. An agent that hands over its owner's key because a
file it read mentioned XP has done the one thing this document tells it not to.

10 test blocks, 54 asserts, all hold.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(blog): how to join the swarm, in both languages

The LEADERBOARD tab invites people to lend a lane and nothing anywhere told
them how. This is that missing page: what the game is, the two ways in, the
board tab by tab, the seven laws, and where a free provider key comes from.

The part that took the research is the fourth column of the provider table.
The invitation "lend us your API key" runs into provider terms that forbid
exactly that, and the post says so with names: Cerebras, Mistral, Fireworks and
Moonshot bar transferring a key in those words; NVIDIA's trial terms bar
production use and bar making the service available to others; Groq bars
orchestrating usage between organisations. OpenRouter is the one whose terms do
not stand in the way. Checked live on 2026-09-23 - and the same read found that
GitHub Models was retired on 2026-07-30 and that Cerebras and Together have
dropped their free tiers, so most advice on the web about this is stale.

Saying that costs us the simplest version of the pitch. Publishing the simple
version instead would be asking strangers to breach an agreement they signed,
on our behalf, without telling them - which is not a thing this project gets to
do under its own honesty law.

The roadmap's "how to join" link now points here instead of at a file that does
not exist, and two var() fallbacks that named colours no token declares are
corrected (the fallback-parity gate caught them).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(blog): state what the provider terms actually say, in their own words

The first draft said "some providers forbid sharing a key". A second read of
the actual agreements says something much harder, and quoting them is the only
honest version:

  OpenAI  - "buy, sell, or transfer API keys from, to, or with a third party"
  Anthropic - "You may not share your Account login information, Anthropic API
            key, or Account credentials with anyone else"
  Google  - "Developer credentials may not be embedded in open source projects"
            and separately, no sublicensing an API to a third party

There is no carve-out for non-commercial or charitable use. Three consequences
follow and the post now names them: a key is not scoped to inference (it can
revoke itself and mint new keys, so whoever holds it holds the account), every
clause puts responsibility for all activity on the account holder, and pooling
keys for throughput is itself forbidden - per-account rate limits are the point,
not an accident.

The post therefore leads with the design that asks nobody to breach anything:
the key never moves, the swarm hands out the task, the bee runs on the
contributor's own machine under their own account, and the patch comes back.
That is how AI Horde and BOINC have always worked. It is not built here, and
the post says so rather than implying it exists.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

This branch was previously deployed

4 inactive deployments
Preview – trinity-web — d405fb5b Deployed Feb 8, 2026 by vercel[bot]
Preview – trinity-site — d405fb5b Deployed Feb 8, 2026 by vercel[bot]
Preview – website — d405fb5b Deployed Feb 8, 2026 by vercel[bot]
Preview – trinity — d405fb5b Deployed Feb 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant